Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Posted Aug 29, 2017 21:32 UTC (Tue) by SEJeff (guest, #51588)Parent article: Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Posted Aug 30, 2017 1:03 UTC (Wed)
by jhoblitt (subscriber, #77733)
[Link] (4 responses)
Posted Aug 30, 2017 2:02 UTC (Wed)
by mjg59 (subscriber, #23239)
[Link] (3 responses)
Posted Aug 30, 2017 10:20 UTC (Wed)
by nix (subscriber, #2304)
[Link] (2 responses)
Really this is such a complicated tangle I'm amazed modern servers manage to boot at all. No wonder they take so damn long to do it. I guess it helps that both the ME and the BMC have watchdog timers so if the other one messes up too badly and the boot hangs an immediate reboot-and-try-again can be triggered.
Posted Aug 30, 2017 16:01 UTC (Wed)
by mjg59 (subscriber, #23239)
[Link] (1 responses)
Posted Aug 30, 2017 19:04 UTC (Wed)
by rahvin (guest, #16953)
[Link]
Which is part of the reason it's such a major security vulnerability. It's unknown and untested code running on a CPU the user has no control over that has DMA access and can override the main CPU. It can copy any data off the system and send it wherever it wants and the only way to block it would be to firewall it externally because the host OS would never see the communication. I understand the Enterprise idea behind these things but the code should be open source and updateable because there is as big of a security vulnerability here than there is in the awful IPMI BMC linux stacks that are out there. One of these days the Blackhats are going to start probing these things and I have no doubt there is going to be vulnerability after vulnerability that's going to allow blackhats to take completely control of connected computers. It will make the Mirari botnet look like childs play.
Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Disabling Intel ME 11 via undocumented mode (Positive Technologies)
Disabling Intel ME 11 via undocumented mode (Positive Technologies)