Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

August 27th, 2008, 22:00 GMT · By

Intel Releases Security BIOS Firmware Updates for Several Boards

SHARE:

Adjust text size:

Intel Q35 Chipset Motherboard
Enlarge picture
Intel has issued BIOS security updates for several desktop and mobile motherboards. The updates address a flaw in the Q35 chipset that can be exploited in order to run rootkits within the System Management Mode (SMM). The affected motherboard models are DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, DX38BT and MGM965TW (Mobile).

Earlier this year, at the Black Hat Conference, security researchers from the Invisible Things Lab presented multiple exploits that can be used to hack the Xen hypervisor. One of these exploits made use of a vulnerability in the Q35 Intel chipset. The researchers were forced to keep some slides and the proof-of-concept code secret until Intel issued fixes.

A hypervisor represents the most privileged layer of a virtual machine. It boots along with the primary guest OS, called domain0 (dom0) and benefits from direct access to physical hardware. The other guest operating systems have limited privileges.

The advisory released by Intel along with the updates notes that under certain circumstances an attacker can modify code running in the System Management Mode (SMM). "SMM is a privileged operating environment running outside of OS control," explains the advisory. Running malware under the SMM makes it os-independent and protects it from security software running within the operating systems.

At Black Hat, Sherri Sparks and Shawn Embleton of Clear Hat Consulting presented a keylogger that can be installed in SMM on older systems, but claimed this would be impossible to achieve on newer systems because of a certain security feature. The security feature consists of a bit called D_LCK residing in the SMRAM control register.However, Joanna Rutkowska, Founder and CEO of Invisible Things Lab, bypassed this on Intel VT enabled systems in order to hack the Xen Hypervisor. She explained that the bug in the Q35 chipset allows for the D_LCK bit to be cleared without reboot being necessary.

Even more, Joanna added corrections to the Intel advisory on her blog. First, she claims that this bug is not strictly limited to SMM - "in fact an attacker might also use this bug to directly modify the hypervisor memory, without jumping into the SMM first". She then contradicts the advisory, which claims that administrative (ring0) privileges are needed. "Also, in case of e.g. Linux systems, the Ring0 access is not strictly required to perform the attack, as it's just enough for the attacker to get access to the PCI config space of the device 0:0:0, which e.g. on Linux can be granted to usermode applications via the iopl() system call," she notes.

Since the bug has been fixed, the Invisible Things Lab teams plans to publish the previously kept secret documentation and code next week. The advisory provides information on how to determine if your hardware is affected and how to upgrade its firmware.
FILED UNDER:
Intel
Flaw
Chipset
BIOS
Exploit


4,071 hits · 1 comment
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Intel Unveils New SoC Solution

Intel Goes for Security

Intel Helps Security

More Than One in Five Home Computers Still Infected

PandaLabs Discovers Trojan in Fake UPS Messages

READER COMMENTS:


Comment #1 by: antihacker101 on 14 Feb 2010, 23:52 UTC reply to this comment

this exploit is in action and is the root of the hackings.

for some reason, the hackers targeted me to build this worm that is now being used to do these hackings. since day 1, the ips used where highly anonyous and linked to a client of windstream. each time i worked around it, he would use power user portal and go to tech sites and gain info how to work around any security i would place against him. the source of the dns poisoning for example was from my hubs that were altered. i would call the company who claim its impossible then found parsing injections that would reprogram the hub from telnet type programs.


first i need to set some info straight. the worm works like if different size wheels working with eachother like inside a watch.

the lags you are exzperiencing recently and some of you aka mouse being alive, are linked to early signs of injections. i noticed the worm runs each year and has cycles. i bet in febuary another poor soul will be pinging over 2000 ips per hour 24/7 for months on end. also the phone system is used to inject and spread using radio packets aka dual band. this was validated by a group that directed me to chief engineer of microft whom told me to get a hold of ed gibson.

i showed them how the calls i make get intercepted when microsoft or security related. when did something to the dns which fixed a lot temporarily. everyone who i contact gets infected and their phone will screwup.

one thing i never seen anyone write about yet but is serious is where ev3erything i type is attacked by string injections that can be compared to sql injections. it causes letters and words to disapear or be twisted making this letter for exzample unreadable soon.

im taking a chance cause the last 2 days were used to remove a part of the worm.

this is just a fraction of whats going on. myspace for example isnt caused by a phone situation. whats going on is the hacker uses another browser someowher on yhour system. the hashcodes are using the same space as yours since he uses your id. these hashcodes give him highest priority due to his deep injection into the hardware so you cant overide it while hes there. but i always get it working right by deleting all cookies which also deletes the hash codes


one thing to be aware when it happens to you all where anything you type is wrong or not detected. go to the first letter of this letter for example before you send and delte and retype the first character, this removes the first character set injected and then it will work. also i noticed my X on the keyboard now responds with zx

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM