
By Lucian Constantin
Excerpt:
Alfredo Ortega and Anibal Sacco, two Argentinian security researchers from Core Security Technologies, have shocked the people at CanSecWest when they have presented how persistent code can be injected and executed from the BIOS environment. According to their own account, the implications are huge.
The malicious BIOS code is executed using the VGA ROM signature as ready-signal. "We can patch a driver to drop a fully working rootkit. We even have a little code that can remove or disable anti-virus," Mr. Ortega exemplifies the possibilities.
Source: Softpedia











