Hiding a root kit in the NIC

Presentation at Hack.lu: Reversing the Broacom NetExtreme's firmware - Sogeti ESEC Lab

Quite interesting idea, that. No trace in the OS, undetectable by any AV or Spyware scanner, and perfectly hidden communication.

If used a sniffer, for a given data to be written to the network wire; it could be easily detected.

So a new requirment for integrity check would be to device such kind of sniffer based automated test in addition to the chacksum maintainance, to gurentee integrity, using appropriate hash algorithm (SHA1 or above).