home.social

#firmware_rootkit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #firmware_rootkit, aggregated by home.social.

fetched live
  1. I want some feedback/ideas!

    Recap:
    I am planning to make a hdd firmware rootkit, that is 'extreme persistence'.

    Link to post: infosec.exchange/@loneicewolf/

    :wow_miku:

    Just to make a small update : I have been digging around in the Circuitry, (Covers unscrewed, searching for manuals, etc)
    (so basically "the practical part of this project has begun")

    I need some ideas; What should the rootkit be capable off, instead of only being persistent?

    I want some ideas from all of you here in infosec (this is the major reason why I actually made a account here, it's to ask this single question) <- ofc I love this site in all other ways! anyway, some "ideas" for "ideas" to the bootkit capabilities **might be** :

    - Kleptography (Capability to detect & alter Cryptographic Operations) Example: Detect AES Operations, hook it and export the master keys in a hidden sector on the drive (not accessible to the OS because of a hidden sector, firmware-hidden that is)

    - C&C (Command n Control) Example: Attach raspberry pi or arduino, make a wifi access point, and connect to it, and control it via a gui/menu(local http site) and upload and download firmware/programs/commands. Commands can be: Shutdown drive forcefully, make hidden sector, get hidden sectors, write data to a hidden sector, perform self-test, etc.

    Anything that's missing? If we pretend it's done, what do *you* want this to be capable of?

    NOTE ⚠️ I can't promise I will implement all things (that's simply not possible) but I need some "outside ideas", which is why I turn to you people! :)

    Thanks! And Big Wishes From A Swede!

    Over n out!
    Will.

    #reverseengineering
    #theory #theories #theoretical #project
    #feedback #ideas #creativity #thoughts
    #bootkit #rootkit #infosec #malware #firmware #firmware_rootkit
    #hdd #ssd

  2. I want some feedback/ideas!

    Recap:
    I am planning to make a hdd firmware rootkit, that is 'extreme persistence'.

    Link to post: infosec.exchange/@loneicewolf/

    :wow_miku:

    Just to make a small update : I have been digging around in the Circuitry, (Covers unscrewed, searching for manuals, etc)
    (so basically "the practical part of this project has begun")

    I need some ideas; What should the rootkit be capable off, instead of only being persistent?

    I want some ideas from all of you here in infosec (this is the major reason why I actually made a account here, it's to ask this single question) <- ofc I love this site in all other ways! anyway, some "ideas" for "ideas" to the bootkit capabilities **might be** :

    - Kleptography (Capability to detect & alter Cryptographic Operations) Example: Detect AES Operations, hook it and export the master keys in a hidden sector on the drive (not accessible to the OS because of a hidden sector, firmware-hidden that is)

    - C&C (Command n Control) Example: Attach raspberry pi or arduino, make a wifi access point, and connect to it, and control it via a gui/menu(local http site) and upload and download firmware/programs/commands. Commands can be: Shutdown drive forcefully, make hidden sector, get hidden sectors, write data to a hidden sector, perform self-test, etc.

    Anything that's missing? If we pretend it's done, what do *you* want this to be capable of?

    NOTE ⚠️ I can't promise I will implement all things (that's simply not possible) but I need some "outside ideas", which is why I turn to you people! :)

    Thanks! And Big Wishes From A Swede!

    Over n out!
    Will.

    #reverseengineering
    #loneicewolf
    #theory #theories #theoretical #project #ssd
    #feedback #ideas #creativity #thoughts
    #bootkit #rootkit #infosec #malware #firmware #firmware_rootkit