SMM – x86 BIOS Security

Here is my Security update blog post… of this year, or decade, or ever 🙂

Most of us know viruses and even computer viruses, malwares, spywares, and use anti-virus software. Some of us even know rootkits, that run hidden from us (userspace) and sometimes from even the OS.

Do you know what your computer actually does when it boots up, and what is SMM or what the SMI Handler does? (I didn’t.)

The latest and greatest rootkits now run in System Management Mode (developed and supplied by hackers, NSA …) started straight from the BIOS. (Before your OS even has a chance to load.)

So don’t even trust your trusty Live CDs (pendrives…) to run clean.

So this is the research paper I found:
Are You Giving Firmware Attackers a Free Pass? from legbacore
Stealing encryption keys after booting into Tails Live OS Video

Other Info:
The Boot up process explained in detail [part 2]
System Management Mode
NSA implants

Tools & SW:
Copernicus (License Request)
chipsec
biosbits
hwlatdetect
Coreboot

Your Phones are not better either…
Using NAND Flash Bad Block Table to Hide stuff

Grab & Drag Window anywhere

I found this article while I was wondering if there is a functionality on Windows like the Alt+Mouse window resizing on Linux:

Get the Linux Alt+Window Drag Functionality in Windows

There is an updated script here: Easy Window Dragging, that uses Caps Lock or Middle button of Mouse instead of Alt.

Then I also modified a little bit… now it can also resize the window 🙂

CapsLockDragWindow.ahk