50

Joanna Rutkowska on Twitter: "Attacking #IntelME by @h0t_max & @_markel...

 6 years ago
source link: https://twitter.com/rootkovska/status/938458875522666497
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Conversation

Attacking #IntelME by

&

at #BHEU 1. Requires malformed file on SPI flash (needs physical access or bug in BIOS) 2. Bug in early-loaded module, so ME "disabling" by HAP is not a cure 3. Culprit is classic(!) stack overflow 4. Full code exec in ME Congrats!


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK