Welcome, Guest. Please login or register.
March 16, 2010, 06:55:26 PM

Login with username, password and session length

371907 Posts
41189 Topics
93802 Members

Latest Member: allnew001

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  Intel CPU rootkit
« previous next »
Pages: [1] Go Down Print
Author Topic: Intel CPU rootkit  (Read 2828 times)
burebista
Comodo Loves me
****
Offline Offline

Posts: 197



« on: March 19, 2009, 02:59:21 AM »

Today is the day.
Quote
Next week's Thursday, March 19th, 1600 UTC, we will publish a paper (+ exploits) on exploiting Intel® CPU cache mechanisms.
The attack allows for privilege escalation from Ring 0 to the SMM on many recent motherboards with Intel CPUs.
I'm somehow anxious after I read something from her conclusion
Quote
When was the last time you scanned your system for SMM rootkits? Wink
Especially when a guy tell us
Quote
No software you can run on your operating system would be able to detect this type of exploit once you are powned.

So can a more knowledgeable person explain in plain words what's happens now and how CIS can(?) protect us unlucky Intel owners Grin?

Thanks.
Logged

If it ain't broke... fix it until it is.
.FaZio93.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2290



« Reply #1 on: March 19, 2009, 06:11:47 PM »

Similar thread here. Smiley
Logged

Vista Home Prem x32 SP2
CIS 3.14.130099.587
Please remember to follow the Forum Policy.
Bracca
Comodo Loves me
****
Offline Offline

Posts: 101


« Reply #2 on: March 20, 2009, 08:13:37 AM »

Intel Processors have some vulnerabilites in themselves? Does that count Quad core?  Huh
Logged
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1130


« Reply #3 on: March 20, 2009, 09:27:50 AM »

I'd take anything Joanna Rutkowska says with a pinch of salt since she hasn't yet accepted the challenge to prove the workability of her Blue Pill concept getting on for 2 years later. Roll Eyes

http://blogs.zdnet.com/security/?p=334
Logged
GakunGak
Product Translator
Comodo Family Member
*****
Offline Offline

Posts: 55


Comodo Anti-Hero


« Reply #4 on: March 20, 2009, 09:37:39 AM »

Cpu rootkit... Is that even possible?
Logged

I'm from Balkan and dang proud of it!
RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 600



WWW
« Reply #5 on: March 20, 2009, 10:00:06 AM »

How can anything be effective in volatile memory like L1 and L2 cache? One thing is theory but actually building a malware using such concept is completely another thing.
Joanna has all the theory stuff but she just can't seem to deliver anything useful that is actually working in real world scenarios.
Logged

Pfipps
Comodo Family Member
***
Offline Offline

Posts: 90


« Reply #6 on: April 15, 2009, 03:11:32 AM »

This possible security problem is worth noting. But anyway, there are way to many hackers  (or security researchers) who love to make people feel vulnerable, because the average hacker knows the average user will "click on the dancing pigs."

For example, I can run no security programs on a patched windows system with the windows firewall turned on and (almost) never get infected as long as I surf carefully, and don't download everything, for example. Some hacker may say, "I can break you out in 2 minutes!" Yes, if I allow it on my end! I still have to leave a small possibility of something automatic happening on a particular site.
Logged
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3454



« Reply #7 on: April 15, 2009, 11:59:09 AM »

I'm glad I'm using AMD! Wink
Logged

.FaZio93.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2290



« Reply #8 on: April 15, 2009, 04:13:49 PM »

I still have to leave a small possibility of something automatic happening on a particular site.

IMO, that is no "small possibility". Malicious sites with harmful content (e.g. Buffer overflow as just one example) are one of the most common attacks of today and are becoming more popular everyday.

See here:
http://forums.comodo.com/empty-t34529.0.html
http://secunia.com/secunia_research/

I just think that common sense is not enough for any user nowadays (but it sure can help). 
Logged

Vista Home Prem x32 SP2
CIS 3.14.130099.587
Please remember to follow the Forum Policy.
Creasy
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 858


I'm watching you.


« Reply #9 on: April 15, 2009, 11:36:35 PM »

I'm glad I'm using AMD! Wink

Don't worry.
There are vulnerabilities with AMD too.
But fewer than Intel. Grin
Logged

Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3454



« Reply #10 on: April 16, 2009, 12:59:09 PM »

Don't worry.
There are vulnerabilities with AMD too.
But fewer than Intel. Grin

I need a software like nLite for CPUs to protect myself...  Roll Eyes
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1996


The only thing i ask for are eggs.


WWW
« Reply #11 on: April 16, 2009, 11:23:33 PM »

Holy Mother of All rootkits!!! Shocked   Evil

Can someone explane to me what SMM is? Huh
Because if SMM is (ram like) memory: and it is deleted everytime the power is truned off we should be ok right? Huh

If the answer is NO, if i pull my CPU out and put i in a diffent PC will the rootkit still be there?

ALSO i have a Dell XPS 700 mobo IT comes with a boot diganostic disk that can Scan for problems In every part of the CPU Could something like this do the trick in removing the root kit if instructed to?

 Idea If this don't work nothing will.
Pass the CPU trough A VERY STRONG magnetic Field  Wink that should take care of the rootkit If not the CPU also. LOL
« Last Edit: April 16, 2009, 11:57:33 PM by OmeletGuy » Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.062 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com