19 ms·
X86 rootkit
- vardump 11y agoRead through it all. Seems legit so far. This is bad. Exploiting non-vulnerable SMM code through a remap flaw in x86 architecture. Ouch. Not only can this arbitrarily exploit the running OS. It might actually be able to physically destroy the computer it's running on, for example by abusing thermal controls. Doesn't affect Sandy bridge or newer.
- jsprogrammer 11y agoYep. I didn't read most of the last 1/2-1/3 of the slides, but it looks like the magic number may be different for each machine (ie. there is no one binary to rule them all[all though you could probably trivially generate all possibilities])? And that there is at least some process involved in determining the number what the number is? The author is legit. Here's a somewhat recent talk he gave: https://www.youtube.com/watch?v=C8--cXwuuFQ https://www.youtube.com/watch?v=C8--cXwuuFQ
- TazeTSchnitzel 11y agoThe "magic number" is just a signal to the rootkit. It's not a rootkit itself.
- rasz_pl 11y agosemi legit, cantor.dust is still vaporware
- jsprogrammer 11y agoYes, true. No beta invite yet.
- rasz_pl 11y agoinvites to what? CIA front for reverse engineering? Guy works for a non profit that happens to be the biggest employee for RE coders, nobody heard of it _and_ its only client is DoD, all of this is dodgy as F edit: quick google shows Battelle Memorial is a 'known' CIA front company. /tinfoilhat mode Now Im starting to suspect this SMM escalation was in their arsenal and he overheard some details in the cafeteria?
- jsprogrammer 11y agoInvite to candor.dust? What is the relevance of a CIA front? The software was demo'd, explained, and makes sense. More likely, the software is quite powerful and was developed into a larger, more automated version that Domas/Battelle/CIA/whoever doesn't want to give away.
- caprinja 11y agosenseye seems to match the featureset from cantor dust pretty well but other than 'pretty pictures' its hard to see how its useful
- jsprogrammer 11y agoThe "intuitive" feeling that he claims to develop after using it for awhile seems like it would be useful of you do a lot of reverse engineering or forensics work.
- caprinja 11y agoyeah perhaps I just havn't gotten the feel for it - think I've spent some 8-10 hours total playing around (more comfortable with regular hex+disasm+debug+scripts), I liked the https://github.com/letoram/senseye/wiki/Sense_MFile https://github.com/letoram/senseye/wiki/Sense_MFile thing though
- jsprogrammer 11y agoThis looks pretty cool. cantor.dust seemed more usable than senseye (I haven't used either).
- userbinator 11y agoThe severity of this depends on whether you consider SMM the same privilege level as ring 0, or higher. From my understanding, SMM seems like it was never really designed to be a higher privilege level with strong isolation guarantees.
- bonzini 11y agoIt was not designed as one, but it was mutated into one. SMRR were added for that reason, and various fixes were made to the chipsets in order to isolate SMM better. Remember that SMM is _the_ trusted base for UEFI secure boot.
- mjn 11y agoLooks like this was a talk at the Black Hat conference today. In addition to the slides PDF in the Github repository, the Black Hat site also has a short paper: https://www.blackhat.com/us-15/briefings.html#the-memory-sinkhole-unleashing-an-x86-design-flaw-allowing-universal-privilege-escalation https://www.blackhat.com/us-15/briefings.html#the-memory-sin...
- jsprogrammer 11y ago2-page description from the author: https://www.blackhat.com/docs/us-15/materials/us-15-Domas-The-Memory-Sinkhole-Unleashing-An-x86-Design-Flaw-Allowing-Universal-Privilege-Escalation-wp.pdf https://www.blackhat.com/docs/us-15/materials/us-15-Domas-Th...
- Rantenki 11y agoIt's going to be interesting to see what the ramifications are this for trusted execution environments, where people are validating the hardware they are running on via tboot. It's fortunate that newer platforms seem to be immune (see https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00045&languageid=en-fr https://security-center.intel.com/advisory.aspx?intelid=INTE... ), but remediation after exploit via total hardware replacement would _suck_ for anybody with servers just a couple of years old.
- strstr 11y agoTXT's interactions with SMM are pretty broken [1]. For example, TXT doesn't (can't) validate SMRAM. This exploit still requires ring 0, which, hopefully, the code running in TXT doesn't give access too willy nilly. [1] http://invisiblethingslab.com/resources/bh09dc/Attacking%20Intel%20TXT%20-%20paper.pdf http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...
- cft 11y agoDoes this apply to all server boards or only some?
- x0 11y agoOh man... when I read the title, I was thinking "sure, x86, whatever, but what OS is this rootkit for?" Scary.
- reirob 11y agoBy reading the 2 page paper from the author [0] - it's linked to somewhere in this thread: "[...] SMM code is installed during the boot process by system firmware, the diversity of which typically precludes a widespread attack. However select components of system firmware are derived from a set of Unified Extensible Firmware Interface (UEFI) template code provided by Intel. Such is the case for the initial SMM entry point, which is almost universally deployed on modern systems. An attack directed against this specific code sequence achieves the widest possible coverage. [...]" So theoretically it's exploitable on all Operating Systems. The exploit is using the combination of a hardware bug and UEFI code. The hardware bug consists in allowing to relocate the APIC (Advanced Programmable Interrupt Controller) memory range to the memory range used by the SMM (System Management Mode) and so influencing the data in some of SMMs memory. [0] https://www.blackhat.com/docs/us-15/materials/us-15-Domas-The-Memory-Sinkhole-Unleashing-An-x86-Design-Flaw-Allowing-Universal-Privilege-Escalation-wp.pdf https://www.blackhat.com/docs/us-15/materials/us-15-Domas-Th...
- x0 11y agoOh, I was aware, but that was just my immediate thought, because I'd never really conceived of something like it. Thanks, though! I'm sure someone reading this thread found your comment very helpful.
- im3w1l 11y agoIs it a coincidence that newer CPU's aren't vulnerable, or was it fixed because of discussions with Intel?
- jsprogrammer 11y agoI believe the author previously disclosed to Intel.
- x0ra 11y agoStill, it was fixed with Sandy Bridge 2 years ago.
- Sanddancer 11y agoIt's coincidence. The change that causes a GPF when the APIC space overlaps with SMM space was an undocumented change when Sandy Bridge was rolled out. So some engineers at Intel may have had an inkling that something could happen there, but at the same time, Sandy Bridge was the first chip with an on-die memory controller, so the engineer assigned to the new implementation could have just been more diligent in thinking through failure scenarios.
- omgmypztxqma 11y agoAre AMD's (or other non-Intel shops') CPUs vulnerable to this remap gimmick as well - or, is it specific to Intel's circuitry? (Sorry, I can't read the slides at present.)
- Sanddancer 11y agoFrom the slides, it looks like AMD chips are vulnerable as well. They didn't mention any other X86 vendors.
- deleted 11y ago[deleted]
- wtallis 11y ago
- MrBra 11y agoWhat does this imply?
- deleted 11y ago[deleted]
- mappu 11y agoThe PDF indicates this requires ring 0 to work, right? So you can't go from user to root. However it does mention ring -2 is under the hypervisor, so.. that allows guest->host escape under VT-x?
- strstr 11y agoThe whole "ring-2" thing is misleading. Root to SMM doesn't imply a VM escape. Most hypervisors don't even implement APIC relocation properly (I believe KVM fixes it to 0xfee00000). Even if APIC were relocatable in a guest, Host SMM runs outside of the hypervisor, and wouldn't be influenced by the guest (the guest's APIC MMIO accesses are all virtualized: either converted into VMEXITs on sandybridge and earlier, or potentially passed through to the APIC access page.)
- strstr 11y agoThe APIC's registers are an unusual form of per core black magic. As far as I know, no other memory addresses behave in the same way -- visible and reacting only to that specific core. It's unsurprising that Intel initially didn't catch this case. Fortunately, it's `just` a root => SMM escalation, which are already more common than anyone would really like to admit.
- eximius 11y agoDid I misread? I thought it only requires userland?
- 3JPLW 11y agoThe presentation certainly makes it seem that way. The dramatic "POC" with the magic number only works with the rootkit already installed. The proceedings paper has much more detail[1]. Installing the rootkit requires some very careful crafting and requires ring 0 to request memory remapping and set up far pointer descriptors. 1. (pdf) https://www.blackhat.com/docs/us-15/materials/us-15-Domas-The-Memory-Sinkhole-Unleashing-An-x86-Design-Flaw-Allowing-Universal-Privilege-Escalation-wp.pdf https://www.blackhat.com/docs/us-15/materials/us-15-Domas-Th...
- TazeTSchnitzel 11y agoYou didn't read past the first page. The only userland thing is activating the rootkit.
- flashman 11y agoPrevious discussion: https://news.ycombinator.com/item?id=9663249 https://news.ycombinator.com/item?id=9663249
- vardump 11y agoMore like previous guessing and hypothesizing. The details weren't known at that time.
- hmottestad 11y agoShould we call it "halt and catch fire 2015"?
- pmalynin 11y agoEh, ring-2 is pretty lame. Most code either runs in ring-3 or ring-0. I'm not even sure how one would even get to ring-2.
- mappu 11y agoRing negative-2, not ring 2. It represents SMM (-2) under the hypervisor (-1) under root (0). Although OS/2 and eComstation use ring 2 a lot which made them hard to emulate for a while.
- recentdarkness 11y agoring (-2) not ring (2)
- rootlocus 11y agoRead us-15-Domas-TheMemorySinkhole.pdf for an in depth explanation.
- thomasrossi 11y agoHm, what is really interesting would be to understand how this can impact a shared machine, say an EC2. Is there any more reasearch on this?
- cnvogel 11y agoThe hypervisor on EC2 will (or rather: it can, and I assume it will) block your virtualized Kernel (running on Ring-0) from messing with the APIC. This (running a hypervisor) is one of the possible mitigations for the sinkhole-exploit.
- anonbanker 11y agoDoes this affect AMD processors as well? if so, this would be a huge step toward rooting a PS4/XboxOne.
- zachberger 11y agoThe slides state they're investigating if its exploitable on AMD