3 ms·
Chip Red Pill Repos : https://github.com/chip-red-pill https://github.com/chip-red-pill Tool : https://github.com/chip-red-pill/udbgInstr https://github.com/c
by blopeur 5y ago
Chip Red Pill Repos : https://github.com/chip-red-pill https://github.com/chip-red-pill
Tool : https://github.com/chip-red-pill/udbgInstr https://github.com/chip-red-pill/udbgInstr
Undocumented x86 insts for uarch control : https://github.com/chip-red-pill/udbgInstr/blob/main/paper/undocumented_x86_insts_for_uarch_control.pdf https://github.com/chip-red-pill/udbgInstr/blob/main/paper/u...
- shoo 5y agothanks for linking to the paper, that contains considerably more information
- mleonhard 5y agoSummary: An Intel CPU in "Red Unlock" mode allows any user-mode code to read and write its microcode. The paper teaches security researchers how to do it. They can use it to discover undocumented Intel CPU internals and functionality. I don't know if these instructions will be useful in exploits. They require the CPU to be in Red Unlock mode. One known way to enable Red Unlock requires connecting a special cable to the motherboard's USB port and exploiting the Intel Trusted Execution Engine core [0]. There are probably remote exploits via ethernet and the Intel Management Engine. Could there be some motherboards that shipped with Red Unlock mode permanently enabled? User-mode code running on such machines could trivially root the machine and even escape a hypervisor. [0] https://github.com/ptresearch/IntelTXE-PoC https://github.com/ptresearch/IntelTXE-PoC