3 ms·
Couldn't they just hardware mitm the CPU and Ram, not to be prisoner of AES. This way they can dump stages as well.
by shdshdshd 5y ago
Couldn't they just hardware mitm the CPU and Ram, not to be prisoner of AES. This way they can dump stages as well.
- ajross 5y agoSure, but that requires having a fully instrumented host get attacked. If all you have is a few reports of compromised machines, it's much harder to work backwards to the exploit. The attacker will switch things around before phishing again, etc... Honeypots are harder than they look, basically.
- deleted 5y ago[deleted]