Readit News logoReadit News
rinkhals commented on Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface   breaknenter.org/2012/02/a... · Posted by u/fourk
enneff · 14 years ago
I thought this was a hardware-based attack. Does it matter whether the OS supports firewire or not?
rinkhals · 14 years ago
http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...

"We have successfully tested that after unloading AppleFWOHCI.kext the current tools won't work anymore."

If that's true then an option for those who need to use FW/TB devices is to remove the drivers from the system folder to prevent loading at startup and kextload/kextunload on demand.

The following named drivers are present in "/System/Library/Extensions/" :

IOFireWireAVC.kext IOFireWireFamily.kext //(The AppleFWOHCI.kext mentioned above is included here) IOFireWireIP.kext IOFireWireSBP2.kext IOFireWireSerialBusProtocolTransport.kext

IOThunderboltFamily.kext AppleThunderboltDPAdapters.kext AppleThunderboltEDMService.kext AppleThunderboltNHI.kext AppleThunderboltPCIAdapters.kext AppleThunderboltUTDM.kext

u/rinkhals

KarmaCake day7February 12, 2012View Original