UEFI firmware images must be digitally signed, period. This will make this attack impossible. I'd say all downloadable/flashable firmware must be digitally signed. Click to expand... Aside from that ...
i have dhcp, tftp and www services setup to run PXE boots and use it for all my fedora builds and VMs. works great. i am now trying to setup PXE boot for Kali linux ...