SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Running Unsigned Code In Intel Management Engine
Date    Saturday December 30 2017, @09:32AM
Author    janrinok
Topic   
from the told-you-so dept.
https://soylentnews.org/article.pl?sid=17/12/29/1853255

janrinok has found the following PDF:

There has been quite a bit of discussion recently regarding the use of a Management Engine (ME), or the code that exists within a CPU but is inaccessible to the user of the computer using that CPU. To quote from the introduction of this PDF:

Intel Management Engine (Intel ME) is a proprietary technology that consists of a microcontroller integrated into the Platform Controller Hub (PCH) chip and a set of built-in peripherals. The PCH carries almost all communication between the processor and external devices. Therefore, Intel ME has access to almost all data on the computer. The ability to execute third-party code on Intel ME would allow for a complete compromise of the platform.

Several people, including some from within our own community, have expressed concern that any weaknesses in the ME code would provide another attack surface and, guess what? It has been done! This PDF explains just how some people have managed to achieve the hackers dream and our worst nightmare, and details some research on this subject. It even goes so far as to explain how to run unsigned code in the ME, albeit under a limited set of circumstances - thus giving a hacker total control over the system. However, as this is only the beginning of such research in relative terms it does not bode well for the future. Finding the flaw is the first step, learning how to exploit is the next.

The PDF is, by necessity, quite technical but will be understandable by a significant proportion of our community. The report claims that the following CPUs are susceptible to the attacks detailed in it:


Original Submission

Links

  1. "janrinok" - mailto:janrinok@soylentnews.org
  2. "following PDF" - https://www.blackhat.com/docs/eu-17/materials/eu-17-Goryachy-How-To-Hack-A-Turned-Off-Computer-Or-Running-Unsigned-Code-In-Intel-Management-Engine-wp.pdf
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=24041

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, Running Unsigned Code In Intel Management Engine on 2023-07-08 19:18:20