Nytro Posted November 15, 2014 Report Posted November 15, 2014 BIOS and Secure Boot Attacks UncoveredAndrew Furtak, Yuriy Bulygin, Oleksandr Bazhaniuk, John Loucaides, Alexander Matrosov, Mikhail GorobetsSigned BIOS Updates Are RareMebromimalware includes BIOS infector & MBR bootkitcomponents•Patches BIOS ROM binary injecting malicious ISA Option ROM with legitimate BIOS image mod utility•Triggers SW SMI 0x29/0x2F to erase SPI flash then write patched BIOS binaryNo Signature Checks of OS boot loaders (MBR)•No concept of Secure or Verified Boot•Wonder why TDL4 and likes flourished?Slides: http://www.c7zero.info/stuff/BIOSandSecureBootAttacksUncovered_eko10.pdf Quote