Results 1 to 9 of 9

Thread: 18-Year old x86 design flaw opens door to rootkits according to Researcher

  1. #1
    HEXUS.Squirrel Output's Avatar
    Join Date
    Nov 2007
    Posts
    2,220
    Thanks
    986
    Thanked
    437 times in 309 posts
    • Output's system
      • Motherboard:
      • Gigabyte AORUS Master X570
      • CPU:
      • AMD Ryzen 9 3950X
      • Memory:
      • 32GB (2x16GB) DDR4 Kingston Fury Renegade @ 3600MHz CL16
      • Storage:
      • Sandisk Ultra 3D 2TB
      • Graphics card(s):
      • Sapphire Nitro+ RX 7800 XT
      • PSU:
      • EVGA SuperNOVA 750 G3
      • Case:
      • bequiet Dark Base Pro 900 Rev.2
      • Operating System:
      • Windows 10 Pro x64

    18-Year old x86 design flaw opens door to rootkits according to Researcher

    http://www.itworld.com/article/29658...cher-says.html

    Now that this has become known, how quickly do you think it will take before we see this being exploited in the wild?

  2. #2
    Banned
    Join Date
    Jun 2008
    Posts
    2,129
    Thanks
    13
    Thanked
    189 times in 160 posts

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Quote Originally Posted by Output View Post
    Now that this has become known, how quickly do you think it will take before we see this being exploited in the wild?
    No idea, but I am currently downloading your complete collection of goat porn.

  3. #3
    HEXUS.Squirrel Output's Avatar
    Join Date
    Nov 2007
    Posts
    2,220
    Thanks
    986
    Thanked
    437 times in 309 posts
    • Output's system
      • Motherboard:
      • Gigabyte AORUS Master X570
      • CPU:
      • AMD Ryzen 9 3950X
      • Memory:
      • 32GB (2x16GB) DDR4 Kingston Fury Renegade @ 3600MHz CL16
      • Storage:
      • Sandisk Ultra 3D 2TB
      • Graphics card(s):
      • Sapphire Nitro+ RX 7800 XT
      • PSU:
      • EVGA SuperNOVA 750 G3
      • Case:
      • bequiet Dark Base Pro 900 Rev.2
      • Operating System:
      • Windows 10 Pro x64

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Quote Originally Posted by abaxas View Post
    No idea, but I am currently downloading your complete collection of goat porn.
    That doesn't say "goat stimulator". It says "Goat Simulator".

  4. Received thanks from:

    mikerr (09-08-2015)

  5. #4
    Senior Member Bonebreaker777's Avatar
    Join Date
    Dec 2012
    Location
    Herts, UK
    Posts
    2,035
    Thanks
    55
    Thanked
    203 times in 186 posts
    • Bonebreaker777's system
      • Motherboard:
      • MSI H97I AC
      • CPU:
      • Xeon 1225 v3 + Freezer 11 L
      • Memory:
      • 2 x 4GB 1600Mhz 1T-8-8-8-20 1.35V Crucial BallistiX Tactical VLP
      • Storage:
      • 128GB CRUCIAL MX100///XPEnology server + 3 x WD Purple 3TB
      • Graphics card(s):
      • Intel HD 4600
      • PSU:
      • be quiet! L8 300W PSU BN220
      • Case:
      • Cooler Master Elite 120
      • Operating System:
      • Windows 10 Pro 64bit
      • Monitor(s):
      • Samsung SyncMaster 226BW
      • Internet:
      • Virgin 100Mb

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Quote Originally Posted by output View Post
    that doesn't say "goat stimulator". It says "goat simulator".
    :d :d :d
    Last edited by Bonebreaker777; 09-08-2015 at 03:23 PM.

  6. Received thanks from:

    Millennium (09-08-2015)

  7. #5
    HEXUS.Squirrel Output's Avatar
    Join Date
    Nov 2007
    Posts
    2,220
    Thanks
    986
    Thanked
    437 times in 309 posts
    • Output's system
      • Motherboard:
      • Gigabyte AORUS Master X570
      • CPU:
      • AMD Ryzen 9 3950X
      • Memory:
      • 32GB (2x16GB) DDR4 Kingston Fury Renegade @ 3600MHz CL16
      • Storage:
      • Sandisk Ultra 3D 2TB
      • Graphics card(s):
      • Sapphire Nitro+ RX 7800 XT
      • PSU:
      • EVGA SuperNOVA 750 G3
      • Case:
      • bequiet Dark Base Pro 900 Rev.2
      • Operating System:
      • Windows 10 Pro x64

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Quote Originally Posted by Bonebreaker777 View Post
    :d :d :d
    I have no idea what that emoticon is meant to mean in response.

    Anyway, back on topic and being serious, while I hope that it would be deemed too much effort to exploit, I'm pessimistic and thinking we'll hear of something within six months.

  8. #6
    Senior Member Bonebreaker777's Avatar
    Join Date
    Dec 2012
    Location
    Herts, UK
    Posts
    2,035
    Thanks
    55
    Thanked
    203 times in 186 posts
    • Bonebreaker777's system
      • Motherboard:
      • MSI H97I AC
      • CPU:
      • Xeon 1225 v3 + Freezer 11 L
      • Memory:
      • 2 x 4GB 1600Mhz 1T-8-8-8-20 1.35V Crucial BallistiX Tactical VLP
      • Storage:
      • 128GB CRUCIAL MX100///XPEnology server + 3 x WD Purple 3TB
      • Graphics card(s):
      • Intel HD 4600
      • PSU:
      • be quiet! L8 300W PSU BN220
      • Case:
      • Cooler Master Elite 120
      • Operating System:
      • Windows 10 Pro 64bit
      • Monitor(s):
      • Samsung SyncMaster 226BW
      • Internet:
      • Virgin 100Mb

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Quote Originally Posted by Output View Post
    I have no idea what that emoticon is meant to mean in response.

    Anyway, back on topic and being serious, while I hope that it would be deemed too much effort to exploit, I'm pessimistic and thinking we'll hear of something within six months.
    Somehow I believe it will be nothing serious.

  9. #7
    don't stock motherhoods
    Join Date
    Jun 2005
    Posts
    1,298
    Thanks
    809
    Thanked
    125 times in 108 posts
    • Millennium's system
      • Motherboard:
      • MSI X470 Gaming Plus
      • CPU:
      • AMD 3600x @ 3.85 with Turbo
      • Memory:
      • 4*G-Skill Samsung B 3200 14T 1T
      • Storage:
      • WD850 and OEM961 1TB, 1.5TB SSD SATA, 4TB Storage, Ext.
      • Graphics card(s):
      • 3070 FE HHR NVidia (Mining Over)
      • PSU:
      • ToughPouwer 1kw (thinking of an upgrade to 600w)
      • Case:
      • Fractal Design Define S
      • Operating System:
      • Windows 101 Home 64bit
      • Monitor(s):
      • HiSense 55" TV 4k 8bit BT709 18:10
      • Internet:
      • Vodafone 12 / month, high contentions weekends 2, phone backup.

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Oh well there goes my planned Skylake build !
    (jokin)
    hexus trust : n(baby):n(lover):n(sky)|>P(Name)>>nopes

    Be Careful on the Internet! I ran and tackled a drive by mining attack today. It's not designed to do anything than provide fake texts (say!)

  10. #8
    Senior Member Peter Parker's Avatar
    Join Date
    Jan 2008
    Location
    London
    Posts
    348
    Thanks
    98
    Thanked
    62 times in 47 posts
    • Peter Parker's system
      • Motherboard:
      • ASUS Z170 Pro Gaming
      • CPU:
      • i5-6600K
      • Memory:
      • 16GB DDR4
      • Storage:
      • Kingston 128GB SSD + 2x3TB
      • Graphics card(s):
      • GTX970
      • PSU:
      • SilverStone ST50EF
      • Case:
      • Silverstone Grandia GD01S-MXR
      • Operating System:
      • Fedora 33

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    Quote Originally Posted by Output View Post
    Now that this has become known, how quickly do you think it will take before we see this being exploited in the wild?
    I've seen some posts on Hacker News over the last few months about SMM, so this isn't exactly breaking news.

    According to Domas, the chip maker is aware of the issue and has mitigated it in its latest CPUs. The company is also rolling out firmware updates for older processors, but not all of them can be patched, he said.

    To exploit the vulnerability and install the rootkit, attackers would need to already have kernel or system privileges on a computer. That means the flaw cant be used by itself to compromise a system, but could make an existing malware infection highly persistent and completely invisible.
    ...
    Even if BIOS/UEFI updates are made available by computer manufacturers, their rate of adoption is likely to be very low, especially among consumers.
    So it sounds like a CPU firmware patch can help, which I believe Microsoft, Apple, and Ubuntu updates can all distribute. Also root/admin permissions are needed anyway, at which point it's kind of too late. As stated though it could lead to permanently undetectable infection. I'd bet some government agency has been exploiting this for years.

  11. Received thanks from:

    Output (09-08-2015)

  12. #9
    HEXUS.Squirrel Output's Avatar
    Join Date
    Nov 2007
    Posts
    2,220
    Thanks
    986
    Thanked
    437 times in 309 posts
    • Output's system
      • Motherboard:
      • Gigabyte AORUS Master X570
      • CPU:
      • AMD Ryzen 9 3950X
      • Memory:
      • 32GB (2x16GB) DDR4 Kingston Fury Renegade @ 3600MHz CL16
      • Storage:
      • Sandisk Ultra 3D 2TB
      • Graphics card(s):
      • Sapphire Nitro+ RX 7800 XT
      • PSU:
      • EVGA SuperNOVA 750 G3
      • Case:
      • bequiet Dark Base Pro 900 Rev.2
      • Operating System:
      • Windows 10 Pro x64

    Re: 18-Year old x86 design flaw opens door to rootkits according to Researcher

    I wasn't aware of the Hacker News posts, so this was the first I had heard of it.

    My main thought was that there is likely still many people on older kit that for all we know may not have it mitigated, particularly those that are more susceptible to getting infected by malware that could fall victim to it.

    Thinking about it with the details given though as Peter Parker reiterates, even if you do use a susceptible CPU it sounds like any other malware scenario - that you just need to use common sense as usual and you should hopefully be able to avoid it.

    I think I basically interpreted the article as saying "Most CPUs are probably vulnerable, everyone should get ready for hell."
    Last edited by Output; 09-08-2015 at 10:56 PM.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •