Your flash chip is protected? You're dealing with hideous SMM? Maybe this will help: http://blog.cr4.sh/2015/02/exploiting-uefi-boot-script-table.html
Based on a 31c3 talk. I thought I'd post it here as long as it's useful.
Torsten
--
coreboot mailing list: [email protected]
http://www.coreboot.org/mailman/listinfo/coreboot

