• Email
  • Like
  • Save
  • Private Content
  • Embed
 

[Defcon] Hardware backdooring is practical

by on Jul 29, 2012

  • 81,623 views

This presentation will demonstrate that permanent backdooring of hardware is practical. We have built a generic proof of concept malware for the intel architecture, Rakshasa, capable of infecting more ...

This presentation will demonstrate that permanent backdooring of hardware is practical. We have built a generic proof of concept malware for the intel architecture, Rakshasa, capable of infecting more than a hundred of different motherboards. The first net effect of Rakshasa is to disable NX permanently and remove SMM related fixes from the BIOS, resulting in permanent lowering of the security of the backdoored computer, even after complete earasing of hard disks and reinstallation of a new operating system. We shall also demonstrate that preexisting work on MBR subvertions such as bootkiting and preboot authentication software bruteforce can be embedded in Rakshasa with little effort. More over, Rakshasa is built on top of free software, including the Coreboot project, meaning that most of its source code is already public. This presentation will take a deep dive into Coreboot and hardware components such as the BIOS, CMOS and PIC embedded on the motherboard, before detailing the inner workings of Rakshasa and demo its capabilities. It is hoped to raise awareness of the security community regarding the dangers associated with non open source firmwares shipped with any computer and question their integrity. This shall also result in upgrading the best practices for forensics and post intrusion analysis by including the afore mentioned firmwares as part of their scope of work.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as OpenOffice

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

28 Embeds 68,233

http://gigazine.net 56153
http://www.theverge.com 8492
http://mobile.theverge.com 1547
http://www.google.com 1223
http://www.cnbeta.com 483
https://twitter.com 84
http://cnbeta.com 82
http://vz10.tumblr.com 47
http://news.livedoor.com 28
https://si0.twimg.com 25
http://webcache.googleusercontent.com 13
https://twimg0-a.akamaihd.net 9
http://sapient.jp 9
http://www.gigazine.net 8
http://translate.googleusercontent.com 7
http://us-w1.rockmelt.com 6
http://m.cnbeta.com 3
http://tweetedtimes.com 2
http://twitter.com 2
http://www.google.co.jp 2
http://storify.com 1
http://www.uuzo.net 1
http://blog.livedoor.jp 1
http://58.188.103.33 1
http://www.naivix.com 1
http://www.cnbeta.com.sixxs.org 1
http://www.marchintosh.net 1
https://yorkcollege.blackboard.com 1

More...

Statistics

Likes
5
Downloads
219
Comments
0
Embed Views
68,233
Views on SlideShare
13,390
Total Views
81,623
Post Comment
Edit your comment

[Defcon] Hardware backdooring is practical [Defcon] Hardware backdooring is practical Presentation Transcript