X86 rootkit
github.com
github.com
Exploiting non-vulnerable SMM code through a remap flaw in x86 architecture. Ouch.
Not only can this arbitrarily exploit the running OS. It might actually be able to physically destroy the computer it's running on, for example by abusing thermal controls.
Doesn't affect Sandy bridge or newer.
The author is legit. Here's a somewhat recent talk he gave: https://www.youtube.com/watch?v=C8--cXwuuFQ
edit: quick google shows Battelle Memorial is a 'known' CIA front company.
/tinfoilhat mode
Now Im starting to suspect this SMM escalation was in their arsenal and he overheard some details in the cafeteria?
What is the relevance of a CIA front? The software was demo'd, explained, and makes sense.
More likely, the software is quite powerful and was developed into a larger, more automated version that Domas/Battelle/CIA/whoever doesn't want to give away.
Remember that SMM is _the_ trusted base for UEFI secure boot.
Fortunately, it's `just` a root => SMM escalation, which are already more common than anyone would really like to admit.
The proceedings paper has much more detail[1]. Installing the rootkit requires some very careful crafting and requires ring 0 to request memory remapping and set up far pointer descriptors.
1. (pdf) https://www.blackhat.com/docs/us-15/materials/us-15-Domas-Th...
Scary.
"[...] SMM code is installed during the boot process by system firmware, the diversity of which typically precludes a widespread attack. However select components of system firmware are derived from a set of Unified Extensible Firmware Interface (UEFI) template code provided by Intel. Such is the case for the initial SMM entry point, which is almost universally deployed on modern systems. An attack directed against this specific code sequence achieves the widest possible coverage. [...]"
So theoretically it's exploitable on all Operating Systems. The exploit is using the combination of a hardware bug and UEFI code.
The hardware bug consists in allowing to relocate the APIC (Advanced Programmable Interrupt Controller) memory range to the memory range used by the SMM (System Management Mode) and so influencing the data in some of SMMs memory.
[0] https://www.blackhat.com/docs/us-15/materials/us-15-Domas-Th...
It's fortunate that newer platforms seem to be immune (see https://security-center.intel.com/advisory.aspx?intelid=INTE... ), but remediation after exploit via total hardware replacement would _suck_ for anybody with servers just a couple of years old.
This exploit still requires ring 0, which, hopefully, the code running in TXT doesn't give access too willy nilly.
[1] http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...
However it does mention ring -2 is under the hypervisor, so.. that allows guest->host escape under VT-x?
Most hypervisors don't even implement APIC relocation properly (I believe KVM fixes it to 0xfee00000).
Even if APIC were relocatable in a guest, Host SMM runs outside of the hypervisor, and wouldn't be influenced by the guest (the guest's APIC MMIO accesses are all virtualized: either converted into VMEXITs on sandybridge and earlier, or potentially passed through to the APIC access page.)
Although OS/2 and eComstation use ring 2 a lot which made them hard to emulate for a while.