Moving from Common-Sense Knowledge About UEFI to Dumping UEFI Firmware
labs.sentinelone.com
labs.sentinelone.com
> You go to firmware conferences sponsored by Intel, ARM, IBM, Microsoft, Apple, among others and it's the same few hundred people just switching companies.
Can't speak specifically to UEFI firware stuffm, but my experience with similar domains (that have a small number of really smart, but primarily professional members) is that they don't tend to be very "welcoming" to beginners.
Yah, lots of communities have established rules and even as a relative newcomer myself, getting something into EDK2 is a long and somewhat arduous process. They don't accept PRs, it's all over mailing lists.
https://microsoft.github.io/mu if you're curious about
Why are we still using UEFI?
From an end-user perspective, Coreboot+$PAYLOAD >> UEFI.
If you want direct access to the hardware, you'll typically attach IC hooks to the SPI chip itself, and read/write with flashrom. It's almost always a chunky soic-8 package.
https://libreboot.org/docs/install/c201.html#installing-libr...
[...]
>"Because of the low-level nature of the infection, LoJax had a rather unique degree of persistence: it could survive OS reinstallation, hard-drive replacement, and most other techniques IT personnel typically use to clean infected machines.
To be able to perform the infection, LoJax first had to dump the contents of the UEFI firmware, patch it with its malicious payload, and then flash it back. Based on this description, it is quite clear that
we can acquire our own firmware simply by following the path LoJax delineated for us.
(PDS: And clean it, if it is present...)
Below is the relevant excerpt from section 4 of the whitepaper, outlining the process:
“The tool’s … task is to retrieve the BIOS region base address on the SPI flash memory as well as its size. This information is contained in the SPI Host Interface register “BIOS Flash Primary Region”. All SPI Host Interface registers are memory-mapped in the Root Complex Register Block (RCRB) whose base address can be retrieved by reading the correct PCI Configuration Register. ReWriter_read obtains this address by using RwDrv IOCTL 0x22840 and reading the correct offset (0xF0 in our case). Once the BIOS region base address and size are known, the dump tool reads the relevant content of the SPI flash memory and writes it to a file on disk.”"