7 ms·
Intel AMT Checker for Linux
- Artlav 9y agoSo, if it says "Error: IOCTL_MEI_CONNECT_CLIENT receive message. err=-1", what does it mean? Tried it on i5-6260U, should be new enough to have the thing.
- guipsp 9y agoUpgrade your kernel, or build the kernel with the AMT module
- yorwba 9y ago> Requires that the mei_me driver (part of the upstream kernel) be loaded. Maybe the driver isn't loaded?
- Artlav 9y agoIt is.
- buovjaga 9y agoHere is an issue for it: https://github.com/mjg59/mei-amt-check/issues/1 https://github.com/mjg59/mei-amt-check/issues/1
- knappa 9y agoThe issues page has a report of the same error (as does my i5-6600) and the author says: >Ok, I'm /inclined/ to believe that this indicates that the system doesn't implement AMT at all, but I'll try to do some more research.
- rst 9y agoI got this message on a system which has a Core i7-4510 CPU; this is not on the list of systems with "vPro" technology. I've seen referenced as another name for the vulnerable component --- but given the marketing-spawned confusion around Intel CPU nomenclature, I can easily imagine someone (perhaps me!) getting confused on the point. Search for "vPro" systems here: https://ark.intel.com/Search/FeatureFilter?productType=processors&VProTechnology=true https://ark.intel.com/Search/FeatureFilter?productType=proce...
- wmf 9y agoThis isn't that helpful because you need a vPro-capable CPU and the proper chipset and AMT firmware to be vulnerable.
- d33 9y ago"Intel AMT: ENABLED, AMT is unprovisioned". Does that mean AMT is still potentially vulnerable to attacks from user/kernelspace?
- lclarkmichalek 9y agoFrom the readme: In this state, AMT is not vulnerable to CVE-2017-5689.
- d33 9y agoThanks! Missed this part. Also, do you think it's a good idea to keep it in this state as opposed to updating in case Intel's new patches lock AMT down even further? This is the pattern I saw with Sony once - groups of users not updating their consoles because via exploiting it they could get more control over it.
- lclarkmichalek 9y agoYou should be able to disable it in the BIOS. If you're not going to use it, I'd suggest disabling it. You could always reenable it later, should you find a need for it.
- kuschku 9y agoI have no BIOS option at all for this, yet it’s enabled and provisioned. What do I do?
- lclarkmichalek 9y agoWell, firstly, don't connect your machine to networks you don't trust the members of :) If your machine's manufacturer still supports the device, check if they have any firmware updates available. Hopefully they will have recent updates that include a fix for the AMT authn issue. If you want to disable it, Intel has provided a mitigation guide which has instructions on disabling LMS (which AMT is part of): https://downloadmirror.intel.com/26754/eng/Intel-SA-00075%20Mitigation%20Guide-Rev%201.2.pdf https://downloadmirror.intel.com/26754/eng/Intel-SA-00075%20.... I've not had to follow it myself, good luck if you do :) I'm just repeating stuff I've read from MJG, take a look at his FAQ around this issue: https://mjg59.dreamwidth.org/48429.html https://mjg59.dreamwidth.org/48429.html
- neves 9y agoIt looks like I’m out the news cycle. What is AMT? Why would I need to check for it? Why just in Linux?
- rnhmjoj 9y agoThis explains what it is and why everyone is (or should be) upset about it: http://www.intel.com/content/www/us/en/architecture-and-technology/intel-amt-vulnerability-announcement.html#faq http://www.intel.com/content/www/us/en/architecture-and-tech...
- 0x0 9y agoIt turns out all(?) Intel CPUs in the last decade has a co-CPU that is always running as long as there is electricity available - even when shut down - that is continuously executing a "management engine" bios program, which your main CPU or OS cannot prevent (in fact, if the ME fails to "check in", the main CPU will automatically shutdown in 30 minutes). And, of course, it turns out there is a remote exploit for it. (The co-CPU intercepts network packets on its own, too, apparently)
- lclarkmichalek 9y agoNot all Intel CPUs have AMT. Most consumer machines won't have it enabled, it's an enterprise targeted feature. > Does this mean every Intel system built since 2008 can be taken over by hackers? No. Most Intel systems don't ship with AMT. Most Intel systems with AMT don't have it turned on. From an FAQ by MJG, the author of the tool we are discussing: https://mjg59.dreamwidth.org/48429.html https://mjg59.dreamwidth.org/48429.html
- pritambaral 9y agoYour parent is correct. They aren't talking about AMT. They're talking about ME, which IS present in every Intel chip (since 2008-ish)
- lclarkmichalek 9y ago
- FrozenVoid 9y agoIf anyone get compiling errors with 'timeval tv' being undefined add this to headers #include <sys/time.h>
- mjg59 9y agoThanks, I added that.
- deleted 9y ago[deleted]
- tumdum_ 9y agoDid anyone read that code before using it? :)
- mkl 9y agoI looked through it first. Not thoroughly enough to spot anything really underhanded, but it seems to be well written code that does stuff like what it claims.
- uzoodoo 9y agoThe author is pretty well-known https://en.wikipedia.org/wiki/Matthew_Garrett https://en.wikipedia.org/wiki/Matthew_Garrett
- mkl 9y agoThat alone is not enough, though it helps. Being well-known means a more desirable account to steal, and this is code that must be run as root.
- tumdum_ 9y agoMoreover there is no trivial way to verify that https://github.com/mjg59 https://github.com/mjg59 is github accout of Matthew Garrett. So all one needs to do is to create account that looks good and most people assume that it's safe. Obviously I'm not saying that this is the case here. But it might not be the best idea to run whichever github project someone links to under root.
- virtualwhys 9y ago> Intel AMT: ENABLED > AMT is unprovisioned Think I'd be alright even if it were provisioned as the ethernet port on this Dell Precision laptop got fried during a lightning storm last year (i.e. from reports I've read a wired connection is needed for the exploit to work). Then again, better to know AMT isn't provisioned than to rely on third party reporting.
- jaimex2 9y agoGod #$%@ing damn it, this is why we can't have nice things. You can do only so much to not get pwned software wise, now you need to be paranoid about the hardware too?! Going through all Xeon servers is going to be fun tomorrow.
- nom 9y agoUnfortunately, there are too few hardware developers and not enough hardware-awareness, thanks to the good abstraction nowadays. In the modern age, only few software devs cares about the underlying hardware, because it just works. The thing is, software _runs_ on hardware and any bug/backdoor etc in it undermines everything above. Did you know that the baseband chip in your smartphone runs it's own linux? Or that every SIM card comes with java applications that can communicate with it? I guess not. Considering how much hardware is required on a modern PC main board, it's really not that surprising that there are backdoors, bugs, or other mechanisms that can be exploited.
- throwaypestban 9y ago> the baseband chip in your smartphone runs it's own ... Microkernel In many if not most cases this kernel would be an L4 implementation. > OKL4 has been deployed on over 2 billion mobile phones (https://en.wikipedia.org/wiki/Open_Kernel_Labs https://en.wikipedia.org/wiki/Open_Kernel_Labs)
- monocasa 9y agoModern hexagons run a full Linux under L4 also. It seems like the microkernel separation isn't really architected towards security AFAICT, but for running hard real time tasks on the same cores as the rest of the system.
- Kali909 9y agoIt's comical at this stage.
- criddell 9y agoIf your servers have multiple network ports and you aren't using them all, don't use the first one. Apparently the ME interface is only exposed on the main network interface.
- criddell 9y agoWhy would Intel insist on being so secretive about their management engine? Is it some kind of competitive advantage for them? Supposedly, it's useful for management tasks in enterprise environments, but if I were CIO, I think I would ban VPro chips. Who wants ring -3 processes running on their network for which they have no information about?
- vectorEQ 9y agoSo secretive because its so vulnerable as any of their shitty low level nonsense features. Would be nice if they just focsed on ipc and efficient throughput instead of making it swiss cheese!
- pcwalton 9y ago> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.
- criddell 9y agoDocumenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.
- pcwalton 9y agoI agree with you. But Intel would have to convince skeptical Hollywood executives of that, who are more inclined to just not let PCs have new content at all, since relatively few people consume TV and movies on PCs to begin with. Personally, I think the right solution is to not have DRM for music, TV, and movies on PCs, purely for business reasons. What's happening today is that Intel is effectively shipping everyone who buys an x86 CPU a content decryption module, burning goodwill among free software advocates even though fewer than 1% of consumers will ever use the functionality (actually, does anyone use it?) It makes more business sense for consumers to just buy set-top boxes to consume content. It's not like anyone who buys a $450 Core i7 is going to balk at paying $35 for a Chromecast.
- ingenium 9y agoHmm, I ensured the mei driver was loaded (lsmod confirms it), but I get: "Cannot open /dev/mei: No such file or directory" dmesg shows: "[ 18.233688] mei_me 0000:00:16.0: Device doesn't have valid ME Interface [ 18.233700] mei_me 0000:00:16.1: Device doesn't have valid ME Interface" So I'm guessing I'm not vulnerable. I suppose Supermicro replaced it with their own IPMI interface.
- subway 9y agoIPMI does not replace MEI. It sits off to the side. Odds are, MEI/AMT is off in your firmware.
- pflanze 9y agoSimilarly, on an Intel NUC with i5-6260U: # git rev-parse HEAD 9aa755885093fc8ca8c822797a30ed98ffe2e166 # make gcc mei-amt-check.c -o mei-amt-check # modprobe mei-me # ./mei-amt-check -v Cannot open /dev/mei: No such file or directory # l /dev/*mei* /bin/ls: cannot access /dev/*mei*: No such file or directory # dmesg |grep -i mei # A little confusing as the program is supposed to show "Intel AMT: DISABLED" 'If run on a system with no AMT'.
- pflanze 9y agoOK, with commit a4d8fca4d18e1ae896b0305a53e152b568596bc1 (still after running modprobe mei_me) it is saying: Unable to find a Management Engine interface - run sudo modprobe mei_me and retry. If you receive the same error, this system does not have AMT (Sounds good)
- HeadlessChild 9y agoFixed in this commit: https://github.com/mjg59/mei-amt-check/pull/4/commits/4f2fef320261dd0362698280e4e82e3d88e5c08d https://github.com/mjg59/mei-amt-check/pull/4/commits/4f2fef...
- newman314 9y agoI'm running VMware on a whitebox with a H87 chipset and vPro capable processor. MEI shows up in dmesg. Has anyone else checked their VMware box accordingly?
- deleted 9y ago[deleted]
- sigmar 9y agoI remember early word during this AMT debacle was that there were certain conditions in which AMT could be remotely provisioned. Were those statements false? Is Enabled/unprovisioned completely safe?
- INTPenis 9y agoI'm shocked to say that the Thinkpad x260 does not have AMT at all. Shocked not because I think it's a huge conspiracy to control your computer but because I honestly do believe AMT was made with the best intentions of providing a level of theft mitigation for devices. Just like "Find my Mac" from Apple that seems to get very little flack. I'd be surprised if this meant that my pretty expensive Lenovo Thinkpad X-series lacks theft protection.
- Angostura 9y agoWhen you first set up your Mac, you are asked explicitly whether you want Find My Mac turned on and the Preference to turn it off is then in plain sight in the iCloud preferences. In what way are the two comparable?
- Saavedro 9y agoi don't think anyone has found a machine yet where AMT is enabled out of the box either
- wfn 9y agoAMT is enabled by default (but not provisioned) on an X220, for example.
- Saavedro 9y agosorry, I meant provisioned. As far as I know (could be wrong) it doesn't even listen to any network ports until its provisioned
- wfn 9y agoAh, then yes, it seems, and you should be right (at least in principle - I'm not sure, either) with regards to network ports. (I've done some light scanning out of curiosity, but that's only anecdotal...)
- 9y ago
- acd 9y agoI want to be able to bios disable Intel AMT and AMDs variant of it. This is another bad attack vector. Further i want a simpler boot loader UEFI is bloatware and bad for security as its easy to hide things in those huge prorietary binary blobs.
- deleted 9y ago[deleted]
- besogne 9y ago"Error: Management Engine refused connection. This probably means you don't have AMT" $ ls /dev/mei0 -lh crw------- 1 root root 246, 0 May 15 21:02 /dev/mei0 Is there a way to completely remove AMT ?