Hard disk firmware offers persistent root access
Summary
Sprite_tm examines a hard disk controller and shows how modified firmware can manipulate data traffic and survive reinstallations. The experiment used an ordinary SATA hard drive. The controller contained an ARM processor.
Ideas
- Hard disk controllers run complex firmware of their own.
- Debug interfaces allow access to memory and processor state.
- Manipulated firmware changes the sectors read without anyone noticing.
- Changing the operating system does not overwrite the controller firmware.
Insights
- Peripheral devices form trust domains of their own.
- Reinstalling only removes malware within the storage layers that are written.
- Closed firmware makes independent integrity checks harder.
Facts
- The demonstration survived formatting and reinstallation.
Recommendations
- Include device firmware in threat models.
- Dispose of compromised storage media instead of just reformatting them.
References
Links to the original source and the Web Archive open in a new tab.