📺Our REsearch: "A Dark Side of UEFI: Cross-Silicon Exploitation" recording is available!
🎙️@matrosov and @flothrone at #OffensiveCon23 stage talking about the new ARM and TrustZone attacks exposed from recent UEFI adoption.
https://t.co/Ti7DOhYkUH
⛓️The widespread use of UEFI on ARM devices notably expands the attack surfaces within TrustZone and beyond, raising security concerns
💥REsearch: "A Dark Side of UEFI: Cross-Silicon Exploitation" presented the new ARM attacks at @offensive_con
🔬Slides: https://t.co/c7MR1YmSSa
Supply Chain security is not only about detecting known threats. It's about eliminating the blind spots and gaining more transparency and explainability. Some companies attempt to adapt their traditional methods to fit into newer paradigms, which proves ineffective in practice.
🔥At @offensive_con, we showcased three different attack scenarios on ARM UEFI and beyond:
1️⃣CWE-125: OOB (memory leak) with GetVariable/SetVariable pattern.
2️⃣BRLY-2022-033: GetVariable Stack overflow (UsbConfigDxe).
3️⃣LPE to SMM from DXE by design.
https://t.co/9F0P3uPhN3
During @offensive_con our @marver presented his research on security aspects of embedded SIM cards.
We are releasing SMShell, an SMS based implant proof of concept for Red Teaming that can evade out of band.
Blogpost: https://t.co/3i4SieWUEm
GitHub: https://t.co/71QbSKwxYZ
UEFI ARM code contains a lot of blindspots with mitigation coverage. Not all functions are covered by canary checking (only functions with potentially unsafe calls to MemLib/PrintLib are protected).
But even partial coverage bumps FW security to the next level compared to x86.
⛓️Design issues are the worst!
🔥Given the current revocation architecture, we are facing the serious challenges of accommodating over 2300+ bootmgr binaries within DBX Revocation List (limited space left in EFI Variable storage).
Heading to the Qualcomm Product Security Summit and @Offensive_con this week
🔥A Dark Side of UEFI: Cross-Silicon Exploitation
@Binarly_io REsearch going to present new ways of exploiting Qualcomm Snapdragon 8 devices with UEFI-specific flavor. Stay tuned!
@flothrone@yeggorv
Damn! That was one of the doomsday scenarios we always thought of at Intel. How did this happen?
haven't dived into the detail yet but will soon. I trust @matrosov
🎙️Join us tomorrow for the #BHASIA talk: "The Various Shades of Supply Chain: SBOM, N-Days, and Zero Trust." /cc @hughsient @immune_gmbh
⛓️We have some fascinating data insights regarding firmware supply chain security.
https://t.co/TRRAR8xFNh
🔥New finding! We have confirmed that previously leaked Intel BootGuard private keys from Lenovo/LCFC in September 2022 are still relevant for numerous devices in the field (Lenovo, Supermicro, Intel ...).
⛓️https://t.co/WfyIYgLBmD
🔬FwHunt: https://t.co/PHvxAdXzOL