Twitter | Pretraživanje | |
Alex Matrosov
Everybody cares about signed BIOS updates. When other firmwares like Intel Embedded Controller (EC) can get FW updates without any authorization on some recent hardware. EC have RW access to SPI flash storage and other interesting stuff for rootkits.
Reply Retweet Označi sa "sviđa mi se" More
Bjørn A. Jørgensen 20. velj 2018.
Odgovor korisniku/ci @matrosov @offensive_con i 2 ostali
I am trying to hammer this home with and . All FW updates should be signed and auditable. New iLO/iDRAC security features are not complete.
Reply Retweet Označi sa "sviđa mi se"
Mathias Krause 21. velj 2018.
Odgovor korisniku/ci @matrosov @offensive_con
Shouldn’t PFAT make it require some kind of nonce for the update? 🤔 Anyways, the EC SPI flash access is still subject to Flash Descriptor constraints. So it shouldn’t be able to mess with the ME or BIOS region, for example — assuming a sane Flash Descriptor setup 😉
Reply Retweet Označi sa "sviđa mi se"