• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

[NEWS] Pentium Computers Vulnerable to Attack?

MrGuvernment

Fully [H]
2FA
Joined
Aug 3, 2004
Messages
24,218
this is a scary one....


+--------------------------------------------------------------------+
| Pentium Computers Vulnerable to Attack? |
| from the sounds-like-more-work-than-it's-worth dept. |
| posted by ScuttleMonkey on Tuesday April 11, @13:19 (Intel) |
| http://hardware.slashdot.org/article.pl?sid=06/04/11/1655257 |
+--------------------------------------------------------------------+

An anonymous reader writes "One of the latest security scares is coming
from security experts at CanSecWest/core '06 in the form of a possible
[0]hardware-specific attack. The attack is based on the built-in
procedure that Pentium based chips use when they overheat. From the
article: 'When the processor begins to overheat or encounters other
conditions that could threaten the motherboard, the computer interrupts
its normal operation, momentarily freezes and stores its activity, said
Loïc Duflot, a computer security specialist for the French government's
Secretary General for National Defense information technology laboratory.
Cyberattackers can take over a computer by appropriating that safeguard
to make the machine interrupt operations and enter System Management
Mode, Duflot said. Attackers then enter the System Management RAM and
replace the default emergency-response software with custom software
that, when run, will give them full administrative privileges.'"

Discuss this story at:
http://hardware.slashdot.org/comments.pl?sid=06/04/11/1655257

Links:
0. http://www.fcw.com/article94010-04-10-06-Print
 
In other news, CDROM or Floppy drive exposes your system to hackers who have physical access to the machine! News at 11!

This is the lamest "security risk" I think I've ever heard, I don't know why it's getting so much press.
 
Wow, if the hacker already had root access, had a process running in the background, then caused the computer to overheat you might be in trouble from this problem.

However if they already had that running weren't you already screwed. I would be more afraid of my neighbor coming over looking at gay porn then throwing it ou the window of a 10 story building.

Move Along.

Oh yeah btw, ALL computers on the x86 architecture is currently vunerable according to the original aticle

FCW said:
Every computer that runs on x86 chip architecture may be vulnerable to this attack,
 
UltimaParadox said:
Wow, if the hacker already had root access, had a process running in the background, then caused the computer to overheat you might be in trouble from this problem.
i'm not sure if the chip actually has to be overheating to invoke the safegaurd
 
(cf)Eclipse said:
i'm not sure if the chip actually has to be overheating to invoke the safegaurd
It might not have to be overheating, but it would need the code already on the system somehow. As has been pointed out, by that point you're already screwed.
 
hahaha.. i don't think my computer would overheat and just not tell me... it'd be off for a bit of time. and if they're in front of your computer in the first place, you're askin to get hacked (and i don't believe a computer has to be frozen to do what they'd want)
 
Some one pointed this out on another board

http://blog.ncircle.com/archives/2006/04/cansecwestcore0_13.htm
The song goes a little like this:
Enable SMI
Open SMRAM space
Replace default SMI Handler by custom one (do your duty)
Close SMRAM space
Trigger SMI
Gain access to restricted operations.

And for once - XP is not affected....

In the wider picture: works on most systems. Turns out that Linux and the *BSD’s will fall victim to this attack strategy, however, Windows XP is not known to be exploitable because of a few system calls that are not present and more importantly a certain memory range in protected mode is not shared addresses to SMM.

So, for the demo, they did not pick some shabby OS to exploit. How about OpenBSD at level2 (high security) with allowaperture=1
Ummm…it worked. Theo, microphone please?
 
Some Linux zealots I know would call XP's lack of these instructions a bug even as their computers were brought down by this...
 
Uninformed and slightly less than smart media at work again! YAY! If you're at the point where this would hurt you, you have bigger things to worry about.
 
Back
Top