/?pid=19322

Updated:12:30 PM EDT Apr 18


this is ggmania.com subsite Intel AMT security hole lets hackers take control of corporate laptops - TechAmok

Intel AMT security hole lets hackers take control of corporate laptops - [security]
04:01 AM EST - Jan,13 2018 - post a comment

Intel is off to a rough start in 2018 with yet another security issue found impacting their products. Coming fast on the heels of Spectre and Meltdown is a security vulnerability in Intel's Active Management Technology (AMT). The Intel Core processor with vPro feature is intended to help IT staff manage networked assets. Ironically, it is supposed to help administrators protect devices. This security risk flushes all that down the toilet. According to researchers at F-Secure, "The issue allows a local intruder to backdoor almost any corporate laptop in a matter of seconds, even if the BIOS password, TPM Pin, Bitlocker and login credentials are in place. No, we're not making this stuff up." This flaw has a high destructive potential and can be executed very quickly. The attacker does need to have physical access to the laptop but there are several scenarios where this could prove to be a trivial issue. Harry Sintonen, one of F-Secure's senior security consultants, describes using the 'evil maid' scenario. This is where a pair of attackers identify a target and while one distracts the mark, the other accesses the computer. Since the exploit can be completed in seconds, this tactic is quite viable.

The way the attack is accomplished is by rebooting the computer and then entering the boot menu. In most circumstances, this is the end of the line for an attacker because any competent IT pro would have enabled the BIOS password and the exploit could go no further. However, on AMT machines, the attacker can select Intel's Management Engine BIOS Extension (MEBx) and log in using the default password 'admin.' They can then change the password, enable remote access and set the user's opt-in to 'None.' What he has essentially done here is set up the machine to allow remote access without the user's knowledge that the computer is being exploited. To remote in, the attacker does have to be on the same network segment. However, Sintonen says that wireless access can be achieved with only a few extra steps.



Add your comment (free registrationrequired)

Short overview of recent news articles

Apr,18 2024 Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit
Apr,18 2024 I Will Build You a PC Right Now!
Apr,17 2024 These games carry REAL security risks! BEWARE!
Apr,17 2024 Visible First to Offer Annual Payment Plan, with Discount up to 26%
Apr,17 2024 Is Coding Still Worth Learning in 2024?
Apr,17 2024 All New Atlas - Boston Dynamics
Apr,16 2024 The NEW Chip Inside Your Phone! (NPUs)
Apr,16 2024 XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel!
Apr,15 2024 The Most 2024 Laptop - Razer Blade 14 Review
Apr,15 2024 NEVER install these programs on your PC... EVER!!!
Apr,14 2024 Use Live Translate on Galaxy S24 series to translate a call's
Apr,14 2024 I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam?
Apr,13 2024 Samsung Galaxy Ring - This Just Got Interesting
Apr,13 2024 Piracy Is Over Party - WAN Show April 12, 2024
Apr,13 2024 Conan O'Brien Needs a Doctor While Eating Spicy Wings
Apr,13 2024 Beatbox Jcob recreats every sound
Apr,13 2024 Intel is Gunning for NVIDIA
Apr,13 2024 Building a Budget DIY Home Surveillance System
Apr,12 2024 Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop
Apr,11 2024 DARK MATTER Trailer (2024) New Sci-Fi Movies 4K
Apr,11 2024 How to Build a PC, the last guide you'll ever need! (2024 Update)
Apr,10 2024 Intel 300 CPU Review - The Pentium Replacement is Finally Here...
Apr,10 2024 Wubuntu, the Dubious Linux Windows
Apr,09 2024 A Lite Version Of Windows 11 To Be Released This Year
Apr,09 2024 This $150 Smartphone might be All You Need
Apr,09 2024 I Can't Believe These are Real - Reacting to Ridiculous PCs on
Apr,08 2024 A new video shows AirPower prototype charging an Apple Watch
Apr,08 2024 Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved
Apr,08 2024 20 COOL GADGETS YOU SHOULD SEE
Apr,08 2024 New HTTP/2 vulnerability leaves servers in danger of devastating DoS
Apr,07 2024 3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance?
Apr,06 2024 The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024
Apr,06 2024 Top NEW RELEASES on Netflix in APRIL 2024
Apr,05 2024 Magician vs Slow-Mo Camera (Skill Challenge)
Apr,05 2024 Re-Ranking All Current GPUs From Worst to Best (2024 Update)
Apr,04 2024 Ripple to ISSUE STABLE COIN utilizing XRP AUTO-Bridging Function
Apr,04 2024 HW News - Intel Battlemage Appears, Open Source GPU, Xbox Handheld
Apr,03 2024 Vivo X Fold 3 Pro Hands-On: The New Best Foldable Hardware
Apr,02 2024 OPNSense: Protect Your Home LAN With a Transparent Filtering Bridge
Mar,31 2024 Ultimate Guide to Virtualization: Run MacOS, Linux, and Windows all
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs