A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about kernel-mode development.
 #21175  by AaLl86
 Mon Oct 14, 2013 1:01 pm
Hi All!
As usual I am here to bother KernelMode.info community with a new technical analysis on Windows 8 UEFI Boot manager and Loader. :-) ;-)
Here is the link: http://news.saferbytes.it/analisi/2013/ ... -overview/

The analysis is nothing extraordinary. It's aim is to deeply describe the algorithm shared by UEFI Boot Manager and Windows loader, used to precisely identify System boot disk and to do actual low level I/O on a NTFS volume exploiting UEFI services.

Please, as usual, let me know what do you all think about it.

Regards, and enjoy!
Andrea

ps. Stay tuned for a new Sirefef analysis.... XD :-)