I saw this on slashdot today
http://it.slashdot.org/article.pl?sid=09/03/19/179228
Here's the paper which was released today
http://invisiblethingslab.com/itl/Resources.html
Scary times
Security researchers Joanna Rutkowska (the bluepill hypervisor woman) and Loic Duflotfound found a new way to basically install a rooktkit into the SMM memory space of the BIOS making it completely hidden from the OS, bootCDs etc and almost impossible to remove.
the good news is I think they need physical access to the machine, and it's a new exploit which will hopefull be patched before it allow any damage
http://it.slashdot.org/article.pl?sid=09/03/19/179228
Here's the paper which was released today
http://invisiblethingslab.com/itl/Resources.html
Scary times
the good news is I think they need physical access to the machine, and it's a new exploit which will hopefull be patched before it allow any damage
The attack presented in the paper has been fixed on some systems according to Intel. We have however found out that even the relatively new boards, like e.g. Intel DQ35 are still vulnerable (the very recent Intel DQ45 doesn't seem to be vulnerable though). The exploit attached is for DQ35 board the offsets would have to be changed to work on other boards (please do not ask how to do this).
http://theinvisiblethings.blogspot.com/2009/03/attacking-smm-memory-via-intel-cpu.html