
by Yuriy Bulygin & Alexander Matrosov & Mikhail Gorobets & Oleksandr Bazhaniuk
In this presentation, we explore the attack surface of modern hypervisors from the perspective of vulnerabilities in system firmware, such as BIOS and in hardware emulation. We will demonstrate a number of new attacks on hypervisors based on system firmware vulnerabilities with impacts ranging from VMM DoS to hypervisor privilege escalation to SMM privilege escalation from within the virtual machines.
We will also show how a firmware rootkit based on these vulnerabilities could expose secrets within virtual machines and explain how firmware issues can be used for analysis of hypervisor-protected content such as VMCS structures, EPT tables, host physical addresses (HPA) map, IOMMU page tables etc. To enable further hypervisor security testing, we will also be releasing new modules in the open source CHIPSEC framework to test issues in hypervisors when virtualizing hardware.
Attacking Hypervisors Using Firmware And Hardware blackhat 2015 |
| 20 Likes | 20 Dislikes |
| 1,575 views views | 117K followers |
| People & Blogs | Upload TimePublished on 29 Dec 2015 |
Related keywords
- infosec news
- information security manager
- blackhat asia 2019
- blackhat 2019
- infosec twitter
- blackhat 2018
- black hat seo technique
- blackhat europe
- blackhat badger sekiro
- black hat x reader
- black hat cartoon
- black hat x dr flug
- cyber securityとは
- blackhat conference 2019
- cyber security cloud
- black hat full movie
- blackhat badger
- blackhat forum
- information security foundation 勉強
- infosec rotkreuz
- cyber security framework
- information security policy template
- infosecurity utrecht
- infosec ups system
- cyber security news
- cyber security act
- infosecurity
- blackhat full movie
- infosec blog
- black hat badger
- information security foundation 参考書
- information security management system
- cyber security conference
- black hat seo
- cyber security pro
- black hat movie
- blackhat imdb
- infosec podcast
- black hat cast
- cyber security pro 新しいネットワークが検出されました
- cyber security cloud managed rules
- cyber security measures
- information security governance
- infosec global
- infosecurity europe 2020
- infosec health
- infosec magazine
- information security 日本語
- infosec 19
- black hat anime
- information security foundation
- infosecurity magazine
- cyber security tokyo
- black hat meaning
- black hatch
- information security definition
- information security pdf
- infosec europe 2019
- cyber security market
- infosec institute
- infosec 2019 london
- information security foundation 難易度
- black hatch gamefowl
- cyber security management system
- information security certifications
- blackhat film
- cyber security pro アンインストール
- information security specialist
- cyber security 意味
- cyber security analyst
- information security policy
- black hat usa 2019
- information security forum
- information security news
- infosec conferences
- information security officer
- infosekta
- cyber security japan
- blackhat trailer
- information security analyst
- cyber security university
- black hat hacker
- black hat forum
- cyber security company
- black hat hacking
- black hat villainous
- blackhat conference
- information security foundation based on iso/iec 27001
- blackhat usa
- cyber security report
- blackhatworld
- black hat x demencia
- information security management
- blackhat cast
- black hat 2019
- infosec reactions
Không có nhận xét nào:
Đăng nhận xét