7 ms·
Inception - Root any machine over FireWire, Thunderbolt, others
- vezzy-fnord 13y agoThis is relatively old. I first recall seeing it a few years ago.
- jseliger 13y agoIf so, why haven't Microsoft and Apple patched it?
- SomeoneWeird 13y agoIt's part of the FireWire spec, they can't.
- AaronFriel 13y agoIt isn't a software issue - it's a hardware issue. FireWire and these other specifications require direct memory access. If you plug in a device and it emulates something that requests DMA from the hardware, your machine can be owned. The solution is an IO memory management unit with virtualized access to physical memory. I am not sure how you can actually enforce this to devices on the bus though.
- nine_k 13y agoIf it requires a driver (and it does), it is a software issue. Just having a FireWire port, without a driver, is not enough. So a sane OS should just not allow to initialize a DMA transfer from a newly attached device until a user with enough privilege allows it.
- __david__ 13y agoThe solution is easier than that: only open up the appropriate buffers to DMA. It doesn't need to be virtualized, it just needs to be bounds checked. Maybe I'm spoiled by good hardware, but when I wrote FireWire drivers for embedded systems, we didn't just open up DMA access to RAM willy-nilly. I honestly don't know enough about OHCI to know what the hardware setup is like, but I suspect it's just laziness.
- amichal 13y agoOSX 10.7.2+ apparently disables DMA when using FileVault and a screen lock. See the article 'Attack mitigation - OSX'. Seems like a decent compromise.
- MichaelGG 13y agoSee for instance: http://support.microsoft.com/kb/2516445 http://support.microsoft.com/kb/2516445 It's a well known limitation/tradeoff. Newer machines might ditch DisplayPort for Thunderbolt, which will really suck. "The drawback of this mitigation is that external storage devices can no longer connect by using the 1394 port, and all PCI Express devices that are connected to the Thunderbolt port will not work. Because USB and eSATA are so prevalent, and because DisplayPort often works even when Thunderbolt is disabled, the adverse effect caused by these mitigations should be limited. "
- haberman 13y agoFrom the article: > Attack Mitigation : OSX : Don’t panic – if you are using FileVault2 and OS X Lion (10.7.2) and higher, the OS will automatically turn off DMA when locked – you’re still vulnerable to attacks when unlocked, though So it sounds like Apple has patched it. You just have to make sure your machine is locked.
- c0nsumer 13y agoOn Windows there's no patching to do, since this is by design. If you want to close this potential hole you simply stop the Firewire DMA driver from loading, which is pretty easy to do via Group or Local Policy. Microsoft has an article on it here: http://support.microsoft.com/kb/2516445 http://support.microsoft.com/kb/2516445
- almosnow 13y agoAwesome work, loved thr name
- teddyh 13y agoThis part was especially interesting: Q: Isn’t FireWire a dying horse? Few laptops ship with FireWire ports these days, which makes Inception a useless tool. A: You can use any interface that expands the PCIe bus, for example PCMCIA, ExpressCards, the new Thunderbolt interface and perhaps SD/IO to hotplug a FireWire interface into the victim machine. The OS will install the necessary drivers on the fly, even when the machine is locked.
- userbinator 13y agoBut this also has a positive side: Ensure that FireWire drivers are present and not removed from the system In other words, if you don't have FireWire drivers installed, then this won't do anything; another plus for not installing the drivers for those who have a system with FireWire ports but never need to use them. My laptop has both FireWire and USB controllers disabled, the former because I never use it and the latter because I almost never use it - and when I do, I find it's not too much hassle to go into the Device Manager and enable the one for the one port I intend to use. Another positive side-effect is that the USB drivers seem to take a rather long time to initialise, so booting is much faster without them.
- wmf 13y agoI don't think this kind of attack is limited to FireWire; that was just the easiest version to build. Thunderbolt can attach arbitrary PCI devices, like an FPGA that pretends to be an AHCI controller...
- Fasebook 13y agoThese interfaces have DMA, they don't need drivers to interface with the hardware.
- Sanddancer 13y agoThey do need a driver to set up which DMA channel to use, etc. While these devices can go nuts once things are up and running, just plugging it in won't do anything until the computer actually acknowledges it.
- userbinator 13y agoNothing exciting here... if you have physical access, it's game over.
- harshreality 13y agoIsn't there a practical distinction though between having your computer compromised when you turn your back on someone for 5 seconds and when you leave them alone with your computer for a few minutes?
- jedbrown 13y agoI asked about this just the other day because I use full-disk encryption, but rarely shut the machine down (just sleep with screen lock). The responder was fairly confident that this was not a concern, but Inception does not require an implausible level of expertise to use, yet it would render my encryption useless (assuming the driver is present). https://news.ycombinator.com/item?id=7113788 https://news.ycombinator.com/item?id=7113788 A couple years ago, I chased down and tackled a guy who snatched my laptop on the Blue Line in Chicago. The threat of laptop theft is real and I'd like to mitigate the damage that would result without compromising my ability to work.
- MichaelGG 13y agoOn OSX, IIRC, FireWire DMA was disabled if full disk encryption is turned on. Windows similarly has some sort of security advisory or capability wrt FireWire. If other ports are exposed that offer DMA capabilities, then they need to be disabled. Don't load the drivers/epoxy the physical ports. I was not aware that a new connector would reopen such a massive vulnerability. (Docking ports may also have some issue, but since they're proprietary it wouldn't matter.) That said, I think my assessment is still accurate. If you're just worried about a theft, it seems very unlikely they'd run these kinds of tools before restarting. And even then, why bother? Why not just reformat the machine, if it's just a theft? If you have actual enemies "then keep your laptop physically secured and powered off. And don't use it after breaking chain of custody." The really shitty thing is that some new laptops (W540) apparently don't ship DisplayPort or other digital video, but just Thunderbolt.
- 13y ago
- seldo 13y agoIt seems like the root problem here, as in lots of security problems, is an assumption made early on is no longer valid (e.g. "this application only runs on our LAN, so no need to protect against malicious actors"). In this case, PCI was originally an internal technology -- adding a new PCI device involved opening the case and plugging in a new card. Pluggable PCIe devices changed that assumption, so things that were previously pretty safe (trusting a new piece of hardware physically installed into the box) became unsafe (trusting a random device plugged into the box).
- AaronFriel 13y agoIt's not even that - well, maybe a little bit that, but all pieces of hardware with independent processors could theoretically own your machine. (Even, theoretically, pieces of hardware that attach to your machine that only emulate simple state machines could hijack your CPU and make a "weird machine".) The problem here is fundamentally one of performance - PCIe and other devices cannot function efficiently without direct memory access. The only reason FireWire was capable of the speeds it originally was, was because of DMA. USB didn't have DMA (and still doesn't? I think..) and so for shuttling large amounts of uncompressed data into the address space of a consuming application, it was incredibly inefficient to involve the CPU. PCI-Express and other buses followed a similar route - DMA is vastly superior to every other way of transferring data. Theoretically an I/O memory management unit with virtualization support could protect your machine, but I don't know if any OSes and hardware combinations actually use that to protect the machine.
- nine_k 13y agoThe problem is not in DMA. The problem is that DMA is allowed across memory protection, without authorization and without user consent. I suppose it made sense when Macs and PCs ran single-user OSes on hardware that lacked memory protection. Keeping the default behavior from that day is not wise for, well, last decade or so. (Fresh OSX seems to have changed accordingly, as the tool's page mentions.)
- yuliyp 13y ago
- runn1ng 13y ago(2011) should be added to the title; see the date of the comments below the article.
- Sanddancer 13y agoWhile this attack is a bit old, the proofs of concept remain, except you can do more fun things with certain hardware released in the interim. For example, Apple's firewire display uses a broadcom networking chip that is susceptable to people writing malicious firmware for -- http://esec-lab.sogeti.com/post/2010/11/21/Presentation-at-Hack.lu-%3A-Reversing-the-Broacom-NetExtreme-s-firmware http://esec-lab.sogeti.com/post/2010/11/21/Presentation-at-H... . Fitting a malicious payload into the given space may be a bit tough, but I imagine the intrepid hacker can do it with style and flare.
- comex 13y agoNote that on newer processors, VT-d is supposed to entirely prevent this attack on CPUs that support it (damn Intel), and OSes do use it [1]. I'm curious whether anyone has tried to search for bugs in those implementations. [1] https://developer.apple.com/library/mac/documentation/HardwareDrivers/Conceptual/ThunderboltDevGuide/DebuggingThunderboltDrivers/DebuggingThunderboltDrivers.html https://developer.apple.com/library/mac/documentation/Hardwa...
- etc 13y agoIt's worse than that. The processor might support VT-d, but your motherboard chipset also has to support it. Even then, you might get a BIOS that doesn't expose the necessary information. All of these things are subject to market segmentation and other such unpleasantness. In the end, unless you can coerce a DMAR table out of the machine, I'm not sure how you can tell if the thing actually supports VT-d.
- ballard 13y ago0. Is there a way to disable FireWire and Thunderbolt ports on OSX? 1. Is there yet any I/O firewall like Little Snitch or Hands Off! are for files and network? 2. Linux and Windows also desperately need I/O firewalls.
- mike-cardwell 13y agohttp://www.hermann-uwe.de/blog/physical-memory-attacks-via-firewire-dma-part-1-overview-and-mitigation http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...
- kalleboo 13y ago> Don’t panic – if you are using FileVault2 and OS X Lion (10.7.2) and higher, the OS will automatically turn off DMA when locked – you’re still vulnerable to attacks when unlocked, though So, not really a problem then?
- robin_reala 13y agoImagine a Thunderbolt display on a desk. The attacker builds a small box that plugs into the firewire port on the back and exposes the port over wifi (or runs a prewritten script). The target plugs in their computer to work and is rooted.
- tlarkworthy 13y agoInstead of that, I would sniff a supplied keyboard instead.
- deleted 13y ago[deleted]
- captainmuon 13y agoWait, firewire devices are allowed to write to any address in memory they like to? How ridiculous is that? Why is there no memory protection? I wonder how to block this... It seems like it can only write to the lower 4 GB... RAM is cheap... so add an addtional 4 GB and then modify the kernel to load everything critical above the boundary?
- nly 13y agoThe fix is to fill the FireWire port with rubber cement.
- alanh 13y agoMay be effective against casual industrial espionage, but it’s a fat lot of good that’s going to do if your computer was seized. It can’t be hard for a forensics lab to get around that particular defense! http://www.youtube.com/watch?v=ynzcUw9wv0E#t=18 http://www.youtube.com/watch?v=ynzcUw9wv0E#t=18 (where rubber cement is the leaf. just go around it!)
- drakaal 13y agoCouple of caveats. Many Laptops have Firewire ports that are attached via USB for cost reasons. These 1394 ports will do DV, and attached storage but are not DMA. Thunderbolt on Windows 8 has an option for Allow DMA by Default, or not. This option is so that you can do a bit more prioritizing of your bandwidth. Windows 8 also has a setting for "install new hardware automatically" which if you disable you can only install hardware if you are logged in and click the install button. Windows 8 will also not allow you to install a new device if you are not logged in as Admin, or you have the Annoying UAC enabled. So while Mac and some Linux systems will have this vulnerability because you don't have to be an admin to have new hardware enabled if the drivers are on the system, Windows should be safe unless you changed your rights. On a corporate network with machines where the users run in least user privilege, Windows 8, and Windows 7 users are safe.
- alanh 13y agoOS X: Don’t panic – if you are using FileVault2 and OS X Lion (10.7.2) and higher, the OS will automatically turn off DMA when locked – you’re still vulnerable to attacks when unlocked, though Phew.