Live data from Hacker News

ThinkPwn: System Management Mode arbitrary code execution

github.com

21–30 of 154 posts

Re: ThinkPwn: System Management Mode arbitrary code execution

#21
post #14
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

Clear as mud. Lenovo has previously sacrificed user security and privacy for money (superfish), so it does not surprise me that they have done it again, and these kinds of weasel words aren't going to get me to buy another Lenovo product again. Here's an idea: How about not putting backdoors in our products? How about making it easier for consumers to replace software on systems they own?

Lenovo has always maintained a higher standard for their Think products, Superfish was only an issue on the Idea line. Doesn't excuse the debacle, but ThinkPad's are their professional line of notebooks and they make every effort to keep a positive image.

Re: ThinkPwn: System Management Mode arbitrary code execution

#22
post #19
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

Maybe author did not want to deal with Lenovo. > Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose.

True. The part of the statement that stands out to me is the word "collaborate", which seems to imply that they made some sort of contact (since they didn't say "unsuccessful attempts to contact") so your theory may be accurate.

Although based on the author's original blog post and title for the GitHub repo, it seems that he originally thought it was Lenovo specific...

Re: ThinkPwn: System Management Mode arbitrary code execution

#23

T450S user here. What exactly does this mean for me? I get it's a security issue, but that's about all I understood...

The attack against you would be interdiction, where the NSA (or whomever) would MITM shipping and receiving.

What shipping and receiving? Somewhere between where you will receive the package -- be it your home, PO Box, postal office, etc -- and the originating storage facility (ie: warehouse), there is a long list of hands exchanging your product. One of these hands would be an NSA agent's hands.

https://en.wikipedia.org/wiki/Interdiction

Who is targeted? In all likelihood, businesses, but I'm sure individuals are targeted as well.

The attack requires physical access to the hardware.

And just to be clear -- it's not just Lenovo products. The net seems to have been cast much wider and other devices seem to be affected (HP laptops, desktop motherboards).

Re: ThinkPwn: System Management Mode arbitrary code execution

#24

> Vulnerable code of SystemSmmRuntimeRt UEFI driver was copy-pasted by Lenovo from Intel reference code for 8-series chipsets. > Alex James found vulnerable code on motherboards from GIGABYTE (Z68-UD3H, Z77X-UD5H, Z87MX-D3H, Z97-D3H and many others): This is beyond the scope of just Lenovo machines.

Could a mod please retitle to "ThinkPwn: Intel 8-series firmware exploit affects multiple vendors" ? It's a bit of a mouthful but reflects that this is more widespread than just ThinkPads.

Re: ThinkPwn: System Management Mode arbitrary code execution

#25
I've always liked the build quality of the ThinkPad series though it's been a few years since I've put my hands on one. That said, it looks like they need to spend similar attention on the software. On the flip side, though, I wonder if this solves the issue with the Yoga laptops I read about recently where the user could not disable SecureBoot in order to install the operating system of their choice.

It's a little sad to be excited about a vulnerability because it might provide an opportunity for a consumer open up the products they rightfully purchased.

Re: ThinkPwn: System Management Mode arbitrary code execution

#26
post #6

Earlier quoted context omitted.

I think this exploit requires local administrative access. If an attacker already has this, you're pretty screwed to begin with. In other words, while this could definitely make an attack more damaging and harder to remove, it doesn't seem like a reason to stop using a computer that has decent software and physical security.

This exploit just requires physical, not administrative, access to the machine. You build an EFI "app", put it on a flash drive, and execute it from the UEFI shell.

Oh come on, how practical is this attack? I don't think Lenovo will default boot off a usb drive without user intervention.

If you can get someone to run a USB that'll boot you open the user up to a bazillion exploits already and already own the machine.

Re: ThinkPwn: System Management Mode arbitrary code execution

#27
post #19
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

Maybe author did not want to deal with Lenovo. > Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose.

The author (Dmytro Oleksiuk) tweeted [0]: 'Dear vendors, “give us your 0day vulnerability for free and don’t publish anything” — it’s not a cooperation request'.

[0] https://twitter.com/d_olex/status/748806692754714625

Re: ThinkPwn: System Management Mode arbitrary code execution

#29
post #2

Really hope Lenovo respond soon. Feel like I should leave my ThinkPads hibernated for now.

Similar situation here... I just purchased a refurbished L420 which arrives today. Hopefully they re-flash the firmware as a matter of course.

Re: ThinkPwn: System Management Mode arbitrary code execution

#30
post #20
post #9

What are we up to now? Three preloaded spyware scandals, possible remote execution via the Intel stack and now this vulnerability. That's just what we know about, who knows what else exists. I don't think I can buy another one, which is sad as I think it was a timeless and great design.

I plan on using my quad core T520 for probably another 5+ years. All of their laptops after the T520 series have the full size keyboard with numberpad which off-sets the center of the keyboard, so now your typing is mostly happing on the left side of the keyboard and that causes wrist strain. Having a numberpad is really lame on a laptop. I won't buy one and I know of no one else that likes the numberpad either.. sad…

Wow this was actually going to be a major buying factor in my next Laptop, was really considering a gaming laptop for the numpad but I guess it wouldn't be too difficult to buy a bluetooth numpad for the right side of the keyboard/get used to the numbers above the keyboard. Thanks for this angle. Never considered wrist strain.
Post reply on HN