Full Disclosure mailing list archives

Re: [inbox] Breaking LoJack for Laptops


From: Michael Holstein <michael.holstein () csuohio edu>
Date: Tue, 27 Dec 2005 16:21:02 -0500

> in another life, I played witht eh computrace software.  If I remember
> correctly it transmits it's data before the OS fully boots, and it is
> supposed to survive a Ghost re-image or an OS re-install.

I could envision doing this with BIOS participation and taking advantage of the HPA area on an ATA drive .. since Ghost (et.al.) won't 'see' the HPA area as a valid address on the drive.

But to send out a "phone home" packet, you'd have to put a lot of logic in the bios (enough to do tcp/ip, dhcp, dns, plus hardware drivers for ethernet, etc).

~Mike.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: