On 9/22/2011 3:59 PM, ved...@nym.hush.com wrote: > Can these rootkits work when there is no mbr access?
Yes. In fact, EFI/UEFI is more or less a replacement for MBRs. EFI/UEFI is almost the first thing through the CPU's brain upon booting. There's probably some on-chip microcode that executes first, but EFI/UEFI is, IIRC, the first off-CPU stuff that gets loaded and executed. The EFI/UEFI designers went to some lengths to harden the system against malware -- unfortunately they could only harden it, not immunize it. _______________________________________________ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users