[Secure-testing-team] how to handle SMM attacks?

Florian Weimer fw at deneb.enyo.de
Mon Aug 10 05:25:40 UTC 2009


* Michael S. Gilbert:

> any thoughts on how to address SMM (System Management Mode) attacks?
> this code resides in the vulnerable motherboard's bioses, and hence
> outside of the os.

It's really not much different than flashable components of any other
kind (NIC or disk firmware).  The aproach may be new, but the dangers
aren't.



More information about the Secure-testing-team mailing list