12.07.2015 Views

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PERSISTENC<strong>EFI</strong>RMWARE FLASH‣ Apple’s firmware updates‣ Firmware updates are copied to ESP‣ Written to flash on reboot‣ Older machines use <strong>EFI</strong> Firmware Volumes (.fd files)‣ Volume is blessed with EfiUpdaterApp.efi‣ Writes to flash via SPI from <strong>EFI</strong> environment‣ Newer machines use <strong>EFI</strong> Capsules (.scap files)‣ <strong>EFI</strong> capsule mailbox stuff? (see the spec)De Mysteriis Dom Jobsivs - Black Hat USA2012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!