NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Hacking News

Hacking News


Intel vPro Hacked

Allows for attacks against Xen and Linux

By Marius Oiaga, Technology News Editor

6th of January 2009, 15:29 GMT

Adjust text size:


Intel vPro
Enlarge picture
Intel vPro, a technology developed by the chip maker and applauded for delivering robust hardware-based security, has been hacked. InvisibleThings' Joanna Rutkowska, founder and CEO, and Rafal Wojtczuk, principle researcher, are getting ready to demonstrate the hack at Black Hat DC 2009, this February. According to the security researchers, they have put together the proof-of-concept for the hack, and will demo practical attacks on Intel Trusted Execution Technology at next month's Black Hat.

The Intel Trusted Execution Technology (Intel TXT) was especially designed in order to provide an additional layer of hardware security for virtual environments and operating system kernels. The additional protection tier is available on PCs with Intel vPro technology, the company revealed.

“Our research shows how an attacker can compromise the integrity of a software loaded via an Intel TXT-based loader in a generic way. We have created a proof-of-concept code that demonstrates the successful attack against tboot — Intel's implementation of the trusted boot process for Xen and Linux. Our attack comprises two stages. The first stage requires an implementation flaw in a specific system software. The second stage of the attack is possible thanks to a certain design decision made in the current TXT release,” Rutkowska and Wojtczuk stated.

Rutkowska explained that the Intel TXT technology was set up to guarantee a trusted way for system software (this implied both a Virtual Machine/Hypervisor and an actual OS kernel) to load and to execute. The security researchers claimed that the attack would permit the system to be infected with malware from BIOS rootkits to boot sector viruses, and the Intel TXT technology would still allow the operating system or virtual machine to load.

“While evaluating the effectiveness of the Intel TXT technology, as part of a work done for a customer, we have identified several implementation flaws in the Intel's system software, which allowed to conduct the above mentioned stage-one attack. We have provided Intel with extensive description of the flaws in December 2008, and Intel is currently working on fixing those vulnerabilities,” Rutkowska and Wojtczuk added.

TAGS:

Intel | Intel vPro | Intel Trusted Execution Technology | Intel TXT
Read by 1,885 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


U.S. Computer Security Policies are Unfit for Cyberwar

British Police Can Hack Computers

Voicemail Hack Costs Business Owner $43,000

No Prison Time for Romanian NASA and U.S Navy Hacker

Several High Profile Twitter Accounts Hacked

SSL Security Broken

Russian Hackers Wreak Havoc in the West

Google Calendar Phishing Scam Resurfaces

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM