INSIDE THE INTEL MANAGEMENT ENGINE

CCC! 10 minutes!

streaming.media.ccc.de/34c3/hallb

STRAP IN
Positive Technologies researchers Maxim Goryachy and Mark Ermolov have discovered a vulnerability that allows running unsigned code. The vulnerability can be used to activate JTAG debugging for the Intel Management Engine processor core. When combined with DCI, this allows debugging ME via USB.

Intel Management Engine is a proprietary technology that consists of a microcontroller integrated into the Platform Controller Hub (PCH) microchip with a set of built-in peripherals. The PCH carries communication between the processor and external devices; therefore, Intel ME has access to some critical data on the computer, and the ability to execute third-party code allows compromising the platform completely.
Researchers have been long interested in such capabilities, but recently we have seen a surge of interest in Intel ME.
Intel provides its engineers with the ability to perform ME debugging via JTAG, in addition to allowing third-party developers to debug ISH via DCI (as previously discussed by us at 33c3). Anyone could use the vulnerability we have found to activate JTAG debugging for ME. In our presentation, we will describe the built-in ME debugging mechanism and how to activate it with the help of this vulnerability.

Other urls found in this thread:

streaming.media.ccc.de/34c3/hallb
streaming.media.ccc.de/34c3
youtube.com/watch?v=lhbSD1Jba0Q
distrochooser.de/en
downloadcenter.intel.com/download/26755/INTEL-SA-00075-Detection-and-Mitigation-Tool
intel.com/content/www/us/en/support/articles/000025619/software.html
downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools
34c3ctf.ccc.ac/register/
twitter.com/SFWRedditGifs

>streaming.media.ccc.de/34c3/hallb
if that isn't working, try this

streaming.media.ccc.de/34c3

RISC V literally when?

Literally when someone gets it to run faster than microcontrolers in toasters

...

>Not running old as fuck first gen i7s or AMD hardware instead.

>implying that's safe
Pretty sure ME is all the way back to the Core2 era and AMD has had it for awhile now.

Is my Phenom safe?

Uhhhhhhh....
Uhhhhhhh....
Uhhhhhhh....

If do you want a showman go to youtube watch some e-celebs.

>watching this on Libreboot X200

>The virgin compsec wizard vs the Chad linus tech tips.

Yes.
Modern amd hardware also have the same problem though, through their psp engine (equivalent to intel me).

terrible speaker
i can't watch this

They really should have found someone else to give this talk.
He doesn't need to be a showman. He just needs to be able to talk somewhat coherently. This is really hard to follow.

I want that cat to masterbate my tiny dick.

It's annoying to listen to, almost as much as that voice of woman which reverse-engineered tamagotchis. It isn't hard to prepare what you want to say in advance, like youtube.com/watch?v=lhbSD1Jba0Q for example.

mfw trying to listen to this guy

/who/ participating in the ctf this year

Too busy masturbating to milf futa doujins and shitposting on Sup Forums, but I'm watching it nonetheless.
Take my energy and good luck.

>intel system debugger
is this free?

Only if you're a manufacturer or the NSA or find it on the internet.

Video does not load famalam
Chrome here

>tfw intel killed the stream.

literally watching it right now you fags
use mpv or go home

>signal angel
LMAO

Yes. 1100T (AM3) or FX-8150 (AM3+) are pretty much the best you can get if you want pre-PSP CPU.

Was instslling libreboot hard to do on the x200?
Considering buying an x200 and librebooting it during winter break.
Also did you upgrade the monitor? If so I need recommendations on replacement monitors.
Thanks for the reply in advance.

what went wrong?

>exploit does not persist through restart
>hackerman tries to hack your intel ME
>just flip the power off then on
ez

Atleast they're good in somethings.

> 1100T (AM3) or FX-8150 (AM3+) are pretty much the best you can get if you want pre-PSP CPU.
Or dual/quad opteron 6xxx.

>you don't notice
>hackerman steals all your loli folders
>restart the PC
>never notice
Perfect crime

Jesus christ what a mouthbreather
listening him to breathe out is really annoying


He should step away from the mike to breathe in

>it is feature it is not bug

>it is a feature

He can work for ubisoft now.

>hurr durr java sux0rs XD

It was pretty easy.
Used a Raspberry Pi 1 Model B and a Pomona 5252 clip to flash.
The only problem I ran into was not using the correct GPIO pins on the Pi but an user helped me out.

>that poo in loo voice.
They invaded even this conference.

>pronouncing s-h-a as "sha"
jesus

uhmmmmmmm
uhmmm sorry

uhmmmmmmmmmmmmmmmm
uhmmmmmmmmmmmmmmmmmmmmmmmm
sorry

fucking signalangel

>signal angel

*apologizes*

Sup Forums is an AMD board, filthy Intel retards can go to where they belong

UHMMMMMMMMMMM
UHMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
SORRY, I don't UNDERSTAND
*smiles nervously*

This doesn't affect GODLIKE Sandy, so no, you don't have to burn your ass on the hot burning stove that is first gen i7.

I was interested in this talk but I couldn't sit through this guy mumbling incoherently.

>distrochooser.de/en
Well, time Sup Forums choose your distro

my computer doesn't even have the Intel Management Engine.
#winning

>when your presentation sucks so hard it terminates 10 minutes early

where the fuck do I get this

It does, you just don't have the Winshit interfacing driver. If you're connected to ethernet you're fucked.

Did you just send me to Sup Forums for saying "opterons are fine"?

>where the fuck do I get this
3 seconds in google
downloadcenter.intel.com/download/26755/INTEL-SA-00075-Detection-and-Mitigation-Tool
intel.com/content/www/us/en/support/articles/000025619/software.html

>It does, you just don't have the Winshit interfacing driver. If you're connected to ethernet you're fucked.
wrong
no hardware installed, nor drivers missing

>claiming to defend AMD while not knowing what a fucking opteron is
you should be ashamed

for linux

What CPU do you have?

>iOS kernel exploitation archaeology
Do will anyone watch this one?

>What CPU do you have?
implying I only have one

Sure, but you have two of the same model, right?

BIG BOOBS

Xeon, then? You have Intel ME. If your device is newer than 2006-ish, and you don't have an Atom, it has the ME engine on the motherboard.

How about a skylake pentium

Yes, has the Intel ME.

>iOS
who gives a fuck about this lol

>for linux
the sa-00086 link has a linux tool

this is for sa-00075:
downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools

(again, 3 seconds in google)

>Sure, but you have two of the same model, right?
of course
2x E5-2699v4 ES

>Xeon, then? You have Intel ME. If your device is newer than 2006-ish, and you don't have an Atom, it has the ME engine on the motherboard.
not according to the intel tool
you've made me paranoid enough to email support about this

>Lets break modern binary code obfuscation

I recommend this one next.

Oh shit nigga I forgot about this year's CCC

FX-8350 then

It was indeed, and the question session was really embarrassing too

How about the WPA2 attack later ?

I'll be watching.

Also recommended. It will be given by the guy that found the flaw.

MOMMY

Is he an English speaker ? don't want to feel as bad as during the IME talk :(

He is dutch afaik, so his english should be gud.

what the fuck is this

>Not watching the godzilla shirt autist talking about code obfuscation instead.

fuck off NSA

>Knowing how to speak shouldn't be a requirement when speaking in public.
It's computer virgins like you that give the field a bad rep. Whats the point in being good at something and completely deficient in literally everything else, including basic human functioning?

So why is that guy wearing a girl top?

this faggot just ruined a great presentation

...

He's german, they are all weird dude, specially after WWII.

>you've made me paranoid enough to email support about this
Did they answer? What did they tell?

...

i wanna lick this faggot's little anus ;-;

That chubby german with the girl hair and top making constant weird mouth sounds like he's munching on some food.
I want to hurt him.

>Using trannyboot.
Embarrassing.

>I want to hurt him.
Hurt his ass with your penis?

Only if he loses some weight and cosplays as felix.
But his shoulders are too wide so he would be a hon.

GODZILLA BOY IS BACK

>girl top
>washed jeans
>combat boots
what the fuck dude

wtf does this mean for shitposters who just shitpost til banned on this dumb fucking board.

Have you already considered ceasing your mental activities?

So can this be exploited remotely or does it have to be done locally? Also does the i7 nehalem have ME?

get ready boyz

34c3ctf.ccc.ac/register/

did anyone solve any?