-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/695/windows-remote-memory-access-though-firewire/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
On the other hand, if you can write into an instruction stream, you can set breakpoints, so consing up a debug stub from it CAN'T be THAT HARD. ;)
I think one of the small-but-cool things that came out of my work on firewire memory access was the ability to recover plain text real-mode-disk-crypto passwords (like PGP Wholedisk or similar) from the real mode bios keyboard buffer. Of course, this is just one of the many treasures that lies around in memory, but it's not the first thing you think of. You boot your laptop, enter your disk crypto (or bios disk locker, or whatever) password out in realmode, and it stays there, forever, because it's never used again now you're in protected mode.
I thought it was neat, anyway.
I'm sure I read an article by Simson Garfinkel where he has hinted that acquiring memory using DMA may also be possible using USB.
http://www.csoonline.com/read/050106/ipods.html