12.07.2015 Views

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

DE MYSTERIIS DOM JOBSIVS Mac EFI Rootkits - Reverse ...

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>DE</strong>MO‣ Evil maid using USB‣ Boot from USB flash drive‣ Shim.efi loads malicious driver‣ Driver registers for ExitBootServices()‣ Shim.efi finds real bootloader via NVRAM‣ Executes bootloader‣ Driver gets called back by ExitBootServices() and patchesthe kernelDe Mysteriis Dom Jobsivs - Black Hat USA2012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!