trmm.net
Thunderstrike2 details - Trammell Hudson's Projects
https://trmm.net/Thunderstrike2_details
Mdash; Trammell Hudson's Projects. From Trammell Hudson's Projects. Thunderstrike 2: Mac firmware worm details. This is the annotated transcript of our DefCon 23. Talk, which presented the full details of Thunderstrike 2. The first firmware worm for Apple's Macs that can spread via both software or Thunderbolt hardware accessories and writes itself to the boot flash on the system's motherboard. The original slides. Are available. This page is still being edited and updated with additional links. Our coll...
trmm.net
Thunderstrike 2 - Trammell Hudson's Projects
https://trmm.net/Thunderstrike_2
Mdash; Trammell Hudson's Projects. From Trammell Hudson's Projects. Thunderstrike 2 was presented at DefCon 23 / BlackHat 2015 and the annotated presentation. Is available with significantly more details, as well as a demo video. Of the proof-of-concept in action. Thunderstrike 2 is a continuation of my security research on Thunderstrike. In collaboration with Xeno Kovah and Corey Kallenberg of LegbaCore. I've also collected Thunderstrike 2 news coverage. In June 2015 ( VU#577140. BIOS CNTL.SMM SWP.
reverse.put.as
Reversing Prince Harming's kiss of death | Reverse Engineering Mac OS X
https://reverse.put.as/2015/07/01/reversing-prince-harmings-kiss-of-death
Reverse Engineering Mac OS X. Reverse Engineering and Security for fun and pleasure! Reversing Prince Harming’s kiss of death. July 1, 2015. As I wrote in the original post. The bug is definitely not related to a hardware failure and can be fixed with a (simple) firmware update. The initial assumptions pointing to some kind of S3 boot script failure were correct. This also allows finding which Mac models are vulnerable to this bug. 0 – The ACPI S3 sleep feature. System Management Bus (SMBus). Instead of ...
itcafe.hu
Csúnyán megbuktatták a Mac számítógépeket is - IT café Biztonság hír
https://itcafe.hu/hir/apple_mac_firmware_sebezhetoseg.html
2016 augusztus 27., szombat. Csúnyán megbuktatták a Mac számítógépeket is. Biztonsági szakemberek a rendszer alapprogramjában találtak olyan sebezhetőséget, mely lehetővé teszi a gépek megfertőzését. A napokban zajló hackertalálkozó, a Black Hat. Hasonló sérülékenységet nem is oly rég feltártak már a Maceknél. A kutatók, Xeno Kovah és Trammell Hudson, a LegbaCore. Biztonsági cég, illetve a Two Sigma Investments. A hibát az Apple a tudósítás szerint már javította. Egy hónap ingyen az Apple-től a görögöknek.
sentinelone.com
Reverse Engineering Mac OS X | Sentinelone.com
https://sentinelone.com/blog/reverse-engineering-mac-os-x
Critical Server Protection Platform. SentinelOne for Financial Institution. SentinelOne EPP for the Energy Sector. Find out more about our new Ransomware Cyber Guarantee. Call 855 868 3733. Critical Server Protection Platform. SentinelOne for Financial Services. SentinelOne for Oil & Gas. Reversing Prince Harming’s kiss of death. As I wrote in the original post. Now let’s jump to the technical part and understand why the bug occurs. I am also going to show you how to build a temporary fix. Instead of rei...
privesfeer.arnoschrauwers.nl
Firmware ook van Apples kwetsbaar - Niks te verbergenNiks te verbergen
http://privesfeer.arnoschrauwers.nl/03/08/2015/firmware-ook-van-apples-kwetsbaar
We worden steeds beter in de gaten gehouden. Spring naar de primaire inhoud. Firmware ook van Apples kwetsbaar. Het tweetal – Xeno Kovah, eigenaar van LegbaCore. En Trammell Hudson, een beveiligingstechnicus bij Two Sigma Investments. Dat is allemaal alleen te verhelpen door de firmwarechip te herprogrammeren.Kovah: “Voor de meeste gebruikers is dat een geval van gooi maar weg. De meeste mensen en organisaties zullen de computer niet open maken en de chip elektrisch herprogrammeren.R...De kwalijke pro...
certnazionale.it
Thunderstrike 2: nuova minaccia per i Mac - CERT Nazionale Italia
https://www.certnazionale.it/news/2015/08/06/thunderstrike-2-nuova-minaccia-per-i-mac
Ministero dello Sviluppo Economico. CERT Nazionale Italia - Computer Emergency Response Team. Thunderstrike 2: nuova minaccia per i Mac. Thunderstrike 2: nuova minaccia per i Mac. Giovedì, 6 agosto 2015. Ricercatori della società di sicurezza LegbaCore. Hanno scoperto che OS X è affetto da una vulnerabilità potenzialmente grave. I ricercatori hanno sviluppato un. Che può anche essere installato da remoto nel. Del chip che contiene il firmware, un’operazione non alla portata di tutti. O attraverso un sito...
smokinggun.de
Hacker Archive - // smoking gun - tipps und security weblog
http://www.smokinggun.de/tag/hacker
Smoking gun - tipps und security weblog. Wie und warum Facebook-Accounts gehackt werden. Facebook ist eigentlich überhaupt nicht mein Ding. Erst in diesem Jahr habe ich aus beruflichen Gründen einen Account angelegt. Der aber bis auf zwei oder drei anfangs hochgeladene Fotos keinerlei private Informationen über mich und mein Leben enthält. Komische Facebook-Beitrittsbestätigung: Aber ich kenne keinen Yee Man Mok. Read More …. Fragwürdige Sicherheit: Admin-Zugang für WordPress löschen. Einer der gängigste...
smokinggun.de
Viren und Trojaner Archive - // smoking gun - tipps und security weblog
http://www.smokinggun.de/category/viren-und-trojaner
Smoking gun - tipps und security weblog. Octopus City Blues: Scammer versteckten Malware in Steam-Seite. Scammer haben die Greenlight-Seite von Octopus City Blues kopiert, bei Steam Greenlight hochgeladen und Malware eingeschleust. Einige Steam-User scheinen auf den Scam hereingefallen zu sein. Malware gibt sich als Voice-Chat aus, verbreitet sich per Steam Chat. Die Hintertür zu jedem PC: Das BIOS. Nur Updates versprechen einen wirksamen Schutz für das BIOS. Halten die beiden einen Vortrag mit dem Thema...