#firmware_rootkit — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #firmware_rootkit, aggregated by home.social.
-
I want some feedback/ideas!
Recap:
I am planning to make a hdd firmware rootkit, that is 'extreme persistence'.Link to post: https://infosec.exchange/@loneicewolf/112265018494526585
:wow_miku:
Just to make a small update : I have been digging around in the Circuitry, (Covers unscrewed, searching for manuals, etc)
(so basically "the practical part of this project has begun")I need some ideas; What should the rootkit be capable off, instead of only being persistent?
I want some ideas from all of you here in infosec (this is the major reason why I actually made a account here, it's to ask this single question) <- ofc I love this site in all other ways! anyway, some "ideas" for "ideas" to the bootkit capabilities **might be** :
- Kleptography (Capability to detect & alter Cryptographic Operations) Example: Detect AES Operations, hook it and export the master keys in a hidden sector on the drive (not accessible to the OS because of a hidden sector, firmware-hidden that is)
- C&C (Command n Control) Example: Attach raspberry pi or arduino, make a wifi access point, and connect to it, and control it via a gui/menu(local http site) and upload and download firmware/programs/commands. Commands can be: Shutdown drive forcefully, make hidden sector, get hidden sectors, write data to a hidden sector, perform self-test, etc.
Anything that's missing? If we pretend it's done, what do *you* want this to be capable of?
NOTE ⚠️ I can't promise I will implement all things (that's simply not possible) but I need some "outside ideas", which is why I turn to you people! :)
Thanks! And Big Wishes From A Swede!
Over n out!
Will.#reverseengineering
#theory #theories #theoretical #project
#feedback #ideas #creativity #thoughts
#bootkit #rootkit #infosec #malware #firmware #firmware_rootkit
#hdd #ssd -
I want some feedback/ideas!
Recap:
I am planning to make a hdd firmware rootkit, that is 'extreme persistence'.Link to post: https://infosec.exchange/@loneicewolf/112265018494526585
:wow_miku:
Just to make a small update : I have been digging around in the Circuitry, (Covers unscrewed, searching for manuals, etc)
(so basically "the practical part of this project has begun")I need some ideas; What should the rootkit be capable off, instead of only being persistent?
I want some ideas from all of you here in infosec (this is the major reason why I actually made a account here, it's to ask this single question) <- ofc I love this site in all other ways! anyway, some "ideas" for "ideas" to the bootkit capabilities **might be** :
- Kleptography (Capability to detect & alter Cryptographic Operations) Example: Detect AES Operations, hook it and export the master keys in a hidden sector on the drive (not accessible to the OS because of a hidden sector, firmware-hidden that is)
- C&C (Command n Control) Example: Attach raspberry pi or arduino, make a wifi access point, and connect to it, and control it via a gui/menu(local http site) and upload and download firmware/programs/commands. Commands can be: Shutdown drive forcefully, make hidden sector, get hidden sectors, write data to a hidden sector, perform self-test, etc.
Anything that's missing? If we pretend it's done, what do *you* want this to be capable of?
NOTE ⚠️ I can't promise I will implement all things (that's simply not possible) but I need some "outside ideas", which is why I turn to you people! :)
Thanks! And Big Wishes From A Swede!
Over n out!
Will.#reverseengineering
#loneicewolf
#theory #theories #theoretical #project #ssd
#feedback #ideas #creativity #thoughts
#bootkit #rootkit #infosec #malware #firmware #firmware_rootkit