Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #187106 > unrolled thread

INTEL-SA-00075

Started bymizett@elude.in
First post2017-09-23 05:50 +0200
Last post2017-09-23 13:30 +0200
Articles 8 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  INTEL-SA-00075 mizett@elude.in - 2017-09-23 05:50 +0200
    Re: INTEL-SA-00075 <tomas@tuxteam.de> - 2017-09-23 08:10 +0200
      Re: INTEL-SA-00075 Reco <recoverym4n@gmail.com> - 2017-09-23 10:40 +0200
        Re: INTEL-SA-00075 <tomas@tuxteam.de> - 2017-09-23 11:00 +0200
          Re: INTEL-SA-00075 Reco <recoverym4n@gmail.com> - 2017-09-23 12:30 +0200
            Re: INTEL-SA-00075 <tomas@tuxteam.de> - 2017-09-23 13:10 +0200
              Re: INTEL-SA-00075 Reco <recoverym4n@gmail.com> - 2017-09-23 13:20 +0200
                Re: INTEL-SA-00075 <tomas@tuxteam.de> - 2017-09-23 13:30 +0200

#187106 — INTEL-SA-00075

Frommizett@elude.in
Date2017-09-23 05:50 +0200
SubjectINTEL-SA-00075
Message-ID<usJC1-6nT-3@gated-at.bofh.it>
INTEL-SA-00075-Linux-Detection-And-Mitigation-Tools

https://downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools

Version: 1.0.3.215 (Latest) Date: 9/12/2017
https://github.com/intel/INTEL-SA-00075-Linux-Detection-And-Mitigation-Tools

DID SOMEONE YET TEST IT  ?

[toc] | [next] | [standalone]


#187112

From<tomas@tuxteam.de>
Date2017-09-23 08:10 +0200
Message-ID<usLNv-7Vv-7@gated-at.bofh.it>
In reply to#187106
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Sep 23, 2017 at 03:31:18AM -0000, mizett@elude.in wrote:
> INTEL-SA-00075-Linux-Detection-And-Mitigation-Tools
> 
> https://downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools
> 
> Version: 1.0.3.215 (Latest) Date: 9/12/2017
> https://github.com/intel/INTEL-SA-00075-Linux-Detection-And-Mitigation-Tools
> 
> DID SOMEONE YET TEST IT  ?

Perhaps you might try to make a point as to *why* someone might
want to test it?

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEUEARECAAYFAlnF+j0ACgkQBcgs9XrR2kYKrQCYvnDNDNEoYaTrVXewRqATuU52
gwCdGOHcGkyAjrnkFKIH1zPCrmj52mc=
=h3iF
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#187116

FromReco <recoverym4n@gmail.com>
Date2017-09-23 10:40 +0200
Message-ID<usO8F-JI-1@gated-at.bofh.it>
In reply to#187112
	Hi.

On Sat, Sep 23, 2017 at 08:07:57AM +0200, tomas@tuxteam.de wrote:
> On Sat, Sep 23, 2017 at 03:31:18AM -0000, mizett@elude.in wrote:
> > INTEL-SA-00075-Linux-Detection-And-Mitigation-Tools
> > 
> > https://downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools
> > 
> > Version: 1.0.3.215 (Latest) Date: 9/12/2017
> > https://github.com/intel/INTEL-SA-00075-Linux-Detection-And-Mitigation-Tools
> > 
> > DID SOMEONE YET TEST IT  ?
> 
> Perhaps you might try to make a point as to *why* someone might
> want to test it?

Looks like it's a toolset from Intel to check if your hardware is
affected by [1] - CVE-2017-5689.
And it's a free software, so after checking the source I ran it, and got
'Not Affected' result.

Frankly, if you *really* need to do something about Intel AMT, you don't
need [1].
What you really need is [2]. But then again, nuclear strike from the
orbit is the only way to be sure ☺.

Reco

[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5689

[2] https://github.com/corna/me_cleaner

[toc] | [prev] | [next] | [standalone]


#187120

From<tomas@tuxteam.de>
Date2017-09-23 11:00 +0200
Message-ID<usOs1-PU-9@gated-at.bofh.it>
In reply to#187116
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Sep 23, 2017 at 11:34:49AM +0300, Reco wrote:

[...]

> Frankly, if you *really* need to do something about Intel AMT, you don't
> need [1].
> What you really need is [2] [...]

Sad, but true :-(

> [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5689
> 
> [2] https://github.com/corna/me_cleaner

- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlnGIUoACgkQBcgs9XrR2kbsVACfSqHRXjmRkHyn1AI0Yw0rbmDj
GSIAni2KsesJQU1xFyDQZZBnrMv9mjj2
=yKxn
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#187126

FromReco <recoverym4n@gmail.com>
Date2017-09-23 12:30 +0200
Message-ID<usPR8-1Sh-11@gated-at.bofh.it>
In reply to#187120
	Hi.

On Sat, Sep 23, 2017 at 10:54:34AM +0200, tomas@tuxteam.de wrote:
> On Sat, Sep 23, 2017 at 11:34:49AM +0300, Reco wrote:
> 
> [...]
> 
> > Frankly, if you *really* need to do something about Intel AMT, you don't
> > need [1].
> > What you really need is [2] [...]
> 
> Sad, but true :-(

I disagree. Not sad, but fun.
Seeing /dev/mei0 disappear for good from yet another of my systems
filled by heart with joy.

Which brings me to this, in case anyone needs to do it *right* way:

1) apt-get install flashrom git

2) reboot with iomem=relaxed put into kernel commandline

3) flashrom -p internal -r /tmp/bad.rom

4) git clone https://github.com/corna/me_cleaner /tmp/me_cleaner

They should put this into Debian main's archive if not into
Debian-installer IMO.

5) python /tmp/me_cleaner -O /tmp/good.rom -s /tmp/bad.rom

6) Cross your fingers.

7) flashrom -p internal -w /tmp/good.rom

8) poweroff (reboot won't cut it), then boot without iomem=relaxed

Of course, you may brick the hardware, or it'll just start to behave
funny but the world would be a better place without Intel AMT.

Reco

[toc] | [prev] | [next] | [standalone]


#187128

From<tomas@tuxteam.de>
Date2017-09-23 13:10 +0200
Message-ID<usQtP-2le-9@gated-at.bofh.it>
In reply to#187126
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Sep 23, 2017 at 01:27:16PM +0300, Reco wrote:
> 	Hi.
> 
> On Sat, Sep 23, 2017 at 10:54:34AM +0200, tomas@tuxteam.de wrote:
> > On Sat, Sep 23, 2017 at 11:34:49AM +0300, Reco wrote:
> > 
> > [...]
> > 
> > > Frankly, if you *really* need to do something about Intel AMT, you don't
> > > need [1].
> > > What you really need is [2] [...]
> > 
> > Sad, but true :-(
> 
> I disagree. Not sad, but fun.
> Seeing /dev/mei0 disappear for good from yet another of my systems
> filled by heart with joy.

That only means your operating system doesn't "see" the mess anymore,
but...

(Don't get me wrong: the folks stubbornly poking at that stuff are my
personal heros -- I just think this is only the beginning).

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlnGQLIACgkQBcgs9XrR2kY31gCeJeDOO/+eSkhwSzj97JTXV5lA
OHwAn2pESENy7q7YASZTmqhgKQam7pJ8
=hCgX
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#187129

FromReco <recoverym4n@gmail.com>
Date2017-09-23 13:20 +0200
Message-ID<usQDw-2op-17@gated-at.bofh.it>
In reply to#187128
On Sat, Sep 23, 2017 at 01:08:34PM +0200, tomas@tuxteam.de wrote:
> On Sat, Sep 23, 2017 at 01:27:16PM +0300, Reco wrote:
> > 	Hi.
> > 
> > On Sat, Sep 23, 2017 at 10:54:34AM +0200, tomas@tuxteam.de wrote:
> > > On Sat, Sep 23, 2017 at 11:34:49AM +0300, Reco wrote:
> > > 
> > > [...]
> > > 
> > > > Frankly, if you *really* need to do something about Intel AMT, you don't
> > > > need [1].
> > > > What you really need is [2] [...]
> > > 
> > > Sad, but true :-(
> > 
> > I disagree. Not sad, but fun.
> > Seeing /dev/mei0 disappear for good from yet another of my systems
> > filled by heart with joy.
> 
> That only means your operating system doesn't "see" the mess anymore,
> but...

For the courageous among us there's 'me_cleaner -S' which removes AMT
blobs from the firmware *and* sets HAP bit.

Reco

[toc] | [prev] | [next] | [standalone]


#187130

From<tomas@tuxteam.de>
Date2017-09-23 13:30 +0200
Message-ID<usQNb-2rT-1@gated-at.bofh.it>
In reply to#187129
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Sep 23, 2017 at 02:12:32PM +0300, Reco wrote:

[...]

> For the courageous among us there's 'me_cleaner -S' which removes AMT
> blobs from the firmware *and* sets HAP bit.

Anyway, thanks for reminding me of that link

Cheers
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlnGQ/4ACgkQBcgs9XrR2kZEYACfbl2SD5KmM45Bt4X/t5dC0egw
aRAAnA1s75CupOlau3Z+pfVK4BqTDkbB
=AY6/
-----END PGP SIGNATURE-----

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web