3 ms·
I used it to look into Gigabytes response to Intel SA 00075 described in https://embedi.com/files/presentations/BH-Las-Vegas-2017-Intel-AMT-Stealth-Breakthrough
by hilmipilmi 9y ago
I used it to look into Gigabytes response to Intel SA 00075
described in https://embedi.com/files/presentations/BH-Las-Vegas-2017-Intel-AMT-Stealth-Breakthrough-presentation.pdf https://embedi.com/files/presentations/BH-Las-Vegas-2017-Int....
before: http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a)-6300_f3.zip http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a...
after: http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a)-6300_f4.zip http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a...
You can see that there is an extra function call added that tests for response.length.
Given the easy availability of the assembler dump you can expect progress towards demystifying IME.
I'm not a professional in the security field, but I sense that there is lots of possibilities by just doing a
"strings image/00275000.NFTP/amt.mod". Gigabyte might be special, but they have left their assert prints in the code
and you can get a sense what the thing is doing...