Excerpt:
The researchers - Anibal Sacco and Alfredo Ortega of Core Security Technologies - presented two attacks at the CanSecWest Security Conference, injecting code into a virtual machine running the Windows operating system and, on another virtual machine, replacing critical files in OpenBSD. Because BIOS is stored on a chip on the motherboard and is used to initially run software on a computer, a program inserted into the instructions will be run whenever the system starts.
Source: Security Focus











