12.07.2015 Views

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ATTACKING THE KERNELPATCHING THE KERNELkernel trampoline - stage 1 payload - stage 2restore patchedinstructioncall payload initinstall rootkit hookspayload initialisationalloc memoryand relocatepayloadcontinueOS bootfind stage 2 payloadin <strong>EFI</strong> variablesload_init_program()trampoline initkernel initialisationDe Mysteriis Dom Jobsivs - Black Hat USA2012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!