Risky Business #67 -- Firmware pwnage
Mon, 06/23/2008 - 17:38
Topic Source:
On this week's Risky Business we're taking a look at firmware root kits with John Heasman from the US arm of NGS Software. Some time ago, John figured out how to plonk a root kit on to a PCI device [pdf]. As you can imagine, those sorts of root kits can be very difficult to detect and remove.
But it gets worse.
Newer research, due to be presented at BlackHat in Las Vegas, will show how the CPU on some PCI devices (like the chip on network devices designed to do TCP checksum calculations) can actually be used to run the root kits. That means they never gets loaded into main memory.
Post new comment
User login
Recent podcasts
-
Symantec and McAfee kick off the year of the Dragon with some decent lulzā¦
-
Russians owned our pumps. Persians pwned our drones.
-
How to turn your Kindle into a free, global SSH and IRC modem...
-
Does the hype match the reality?
-
Rootkitting OS X, fun with EFI bootloaders and more...




Recent comments
7 hours 59 min ago
2 days 22 hours ago
5 days 14 hours ago
6 days 14 hours ago
2 weeks 2 days ago
2 weeks 3 days ago
2 weeks 3 days ago
4 weeks 1 day ago
4 weeks 1 day ago
5 weeks 6 days ago