Live data from Hacker News

ThinkPwn: System Management Mode arbitrary code execution

github.com

121–130 of 154 posts

Re: ThinkPwn: System Management Mode arbitrary code execution

#121
post #109
post #87

Earlier quoted context omitted.

Name calling? Come on. I'm not really a fan of the trend of "branding" vulnerabilities, but it is just harmless silliness, and substantially less inflammatory than security industry smack-talking norms from not too long ago. Or put another way, I suggest adjusting your sensitivity before cracking open an issue of Phrack. And a serious question: in your view what would be a "responsible" way to release a multivendor e…

Give the vendor a timeframe to investigate and resolve. Even sometimes ignores reports like this, at least give them the courtesy instead of expose this as an 0day.

My mistake - I had developed the impression that Lenovo was informed ahead of time. I had only skimmed at first.

I had thought the complaint was about not waiting until what sounds like most of the PC OEMs stopped sitting on their thumbs. Please disregard that part of my response.

Re: ThinkPwn: System Management Mode arbitrary code execution

#122
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

It appears that the only security being broken is that of manufacturers against owners of machines . Why should a security researcher feel the least bit obligated to collaborate?

Because when a company sells millions of things to people, those people are potentially affected. Giving the company -- even one you have no particular love for -- a chance to figure out how to mitigate risk for their customers is a nice thing you do for their customers.

Re: ThinkPwn: System Management Mode arbitrary code execution

#123
post #14
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

Clear as mud. Lenovo has previously sacrificed user security and privacy for money (superfish), so it does not surprise me that they have done it again, and these kinds of weasel words aren't going to get me to buy another Lenovo product again. Here's an idea: How about not putting backdoors in our products? How about making it easier for consumers to replace software on systems they own?

Lenovo is not one team. People who write and test superfish are not the same who deal with firmware. They may not even know each other.

Re: ThinkPwn: System Management Mode arbitrary code execution

#124
post #122

Earlier quoted context omitted.

It appears that the only security being broken is that of manufacturers against owners of machines . Why should a security researcher feel the least bit obligated to collaborate?

Because when a company sells millions of things to people, those people are potentially affected. Giving the company -- even one you have no particular love for -- a chance to figure out how to mitigate risk for their customers is a nice thing you do for their customers.

In this case, there is no customer risk to be mitigated! The only thing that could be "mitigated" is the owners' newfound access to their own hardware!

The tiny sliver of end-user threat - a customer's machine gets pwned with a rootkit that a reinstall cannot wipe - can and always could have been eliminated by manufacturers simply shipping proper documentation!

Re: ThinkPwn: System Management Mode arbitrary code execution

#126
Joanna Rutkowska has written about Intel based products that are possibly vulnerable to the Intel management engine code. Even if you run an open source operating system such as Linux or FreeBSD, there is still proprietary code in the management engine that you cannot look or verify that its secure.

Here is the paper http://blog.invisiblethings.org/papers/2015/x86_harmful.pdf

UEFI is another gigantic hide point for malware.

I think one could possibly run more simple platforms such as Raspberry PI, Odroid which may not have embedded management engines. That should be more secure than x86 platforms.

Re: ThinkPwn: System Management Mode arbitrary code execution

#127

Earlier quoted context omitted.

its not longer fair to call game over with physical access; indeed countermeasure like full disk encryption, computrace and Mac firmware passwords are all examples of things we do to raise the difficulty for a physical attacker.

And the vast majority of them is trivially defeated by a bug inline with your USB keyboard.

You can reconstruct a lot of information with a keylogger but nowhere near all of it.

Re: ThinkPwn: System Management Mode arbitrary code execution

#128

Starting with the X230 series of ThinkPads, Lenovo has used flash write protection to prevent "unauthorized" BIOS modifications. Owners of X220 laptops and below are able to reflash the BIOS to remove Lenovo's whitelist of WLAN/WWAN cards; the X230 models are currently stuck with Wi-Fi N and Gobi 3000 3G-only cards due to Lenovo's whitelist. Would this exploit allow ThinkPad owners to reflash their BIOS chip without…

My coworker replaced his BIOS/UEFI with an open source version (thinkpads enable this). It allowed him bypass Lenovo’s whitelisting of “approved” hardware, so he could install his own 3g modem. He repurposed an old Arduino into an SPI flasher and a chip clip to sit on the bios flash chip. https://twitter.com/thomas_cannon/status/703633676102471680

Is the open source version you speak of Libreboot? That's the only open source BIOS replacement I know for any thinkpads. That Thinkpad looks a bit new for full-fledged librebooting! Did he have to reflash the ME firmware back on?

Re: ThinkPwn: System Management Mode arbitrary code execution

#129
post #87
post #62

Earlier quoted context omitted.

Perhaps financial compensation was indeed not Cr4sh's motivation for this zero day, but I felt it's a stretch to call this disclosure responsible. Also his name-calling (ThinkPwn) campaign was inappropriate and premature when the root cause was later discovered in Intel's reference code and propagated to IBVs's products.

Name calling? Come on. I'm not really a fan of the trend of "branding" vulnerabilities, but it is just harmless silliness, and substantially less inflammatory than security industry smack-talking norms from not too long ago. Or put another way, I suggest adjusting your sensitivity before cracking open an issue of Phrack. And a serious question: in your view what would be a "responsible" way to release a multivendor e…

> I'm not really a fan of the trend of "branding" vulnerabilities, but it is just harmless silliness

It's probably harmless but I'm not so sure it's silly. It's much more distinguishing than monikers like "CVE-2016-0093". It can sometimes convey the seriousness of the relevant exploit (not sure if that's the case this time though). These branded-vulnerabilities are also probably much more valuable on a CV as such.

Re: ThinkPwn: System Management Mode arbitrary code execution

#130

Earlier quoted context omitted.

The author (Dmytro Oleksiuk) tweeted [0]: 'Dear vendors, “give us your 0day vulnerability for free and don’t publish anything” — it’s not a cooperation request'. [0] https://twitter.com/d_olex/status/748806692754714625

His Twitter tagline is: "... aka Cr4sh, unethical hacker". He put "unethical" in his own damn profile, I don't think he deserves the benefit of doubt.

If he was that unethical we wouldn't be discussing public disclosure here.
Post reply on HN