3 ms·
> Bloomberg says it is in line with memory to CPUs to intercept some password validation code I think that's a misreading of their article. They were not claim
by rphlx 8y ago
> Bloomberg says it is in line with memory to CPUs to intercept some password validation code
I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wires could be enough to compromise it and gain God Mode over the early x86 SW environment.
- dboreham 8y agoI thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.
- rphlx 8y agoIt's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.
- etcet 8y agoYou can update the BIOS via SuperMicro's IPMI. It's actually a feature you have to pay extra for: https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/SMBU.png https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S...
- dboreham 8y agoGetting them to take your money in exchange for that utility turns out to be hard. I seem to recall figuring out a way to work around the lack of it, but details have been paved out. I think it involved building the OS-based BIOS flashing tool from source.
- dboreham 8y agoYou can flash the BIOS from BMC on some SuperMicro motherboards. But wait..you can flash the bios from the OS on many machines so why is this a new more dangerous attack vector? Because SM can sign their own BIOS image?