Live data from Hacker News

Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

bleepingcomputer.com

21–30 of 84 posts

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#21
post #4

Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(

Are there any open hardware computers of comparable computing power?

How can the consumer stop someone from exploiting this hack?

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#22

Earlier quoted context omitted.

Yes, AMD chips have almost exactly the same features as Intel ME. The cynic in me thinks that some execs got FISA orders.

https://en.wikipedia.org/wiki/Communications_Assistance_for_...

Applies to telecom companies, not CPU manufacturers.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#23
post #17
post #11

Aaaand I think this is the first public disclosure of malware using the Intel Management Engine / AMT's network connection (that uses SMBus, i talked about it here https://news.ycombinator.com/item?id=14309557 and gave links to appropriate datasheets). Welp. AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of complete…

is why Intel needed to give an irreversible and verifiable way of completely disabling it. The article said it comes disabled by default. Isn't this a verifiable way, or is the article incorrect?

If it isn't verifiable, how can you check if the article's statement is true for your particular machine?

And moreover, the article continues with Microsoft can't say if these state-sponsored hackers found a secret way to enable this feature on infected hosts

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#24

This site denies access to the article from a German proxy. What a weird reason can be for this?

Is it a free proxy? Some asshole may have been using the proxy to scrape or ddos the website perhaps? Or perhaps someone did various other nefarious things such as spam comments or harass people.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#27
post #4

Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(

Are there any open hardware computers of comparable computing power? How can the consumer stop someone from exploiting this hack?

1) No, not even close.

2) Disconnect from the network. This, of course, won't stop local attacks on the AMT or ME.

This is why I've been complaining about the ME forever. Forcing a privileged black-box that can't be disabled in to every CPU is... not suspicious all.

Even worse are some implementations. I have a Supermicro all-in-one MB that I used in building a home storage server. It has two gig-ethernet ports. About two months ago, I was rearranging around the machine, and when I plugged it back in, apparently I switched the ethernet port plugged in to the switch to the "primary" interface.

And one of the monitors goes off a few minutes later - there's a new network device on my private network. Turns out a web interface to the ME comes up automatically when using the primary NIC - it got a DHCP lease and was happily waiting to be managed - with the default creds ADMIN/ADMIN.

I thought that we had that one figured out, but apparently not. Yes, I should have read the manual for the motherboard, but that's beyond absurd. And, I guess, a good reminder to trust nothing.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#28
post #5
post #2

Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).

Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…

> People have been begging Intel for a very long time to make business-tier chips without remote access capabilities.

Yes. But somehow, any time anyone brings up wanting a device without one, people start poo-pooing the idea. "Just don't use it." "That's paranoid." "Just another CVE, yawn."

In a ton of discussions over the years, I have yet to hear a single plausible, benign reason for why the ME's 30 minute timer must be impossible to disable by the owner of the chip.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#29
post #5

Earlier quoted context omitted.

Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…

Who knows if the feature is not still present in silicon but just software-disabled? It's not really new that Intel and AMD do binning to get more yield.

It isn't present AFAIK, because Intel cuts corners on enthusiast chips they do not expect to be used in a networked environment in order to save money, and still charge you more than the non-enthusiast counterparts.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#30
post #20
post #3

Issues with that doesn't seem to have scratched Intel's reputation as much as I expected.

Maybe because everyone, who had any clue, knew since the begging what was ME intended for. The only news here is that "wrong" guys used this backdoor (again, nothing unexpected).

Cynicism is consent
Post reply on HN