• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Intel's Skylake and Kaby Lake-based Systems Vulnerable to USB Exploit

Joined
Jun 21, 2016
Messages
2,058 (0.72/day)
System Name AM4 / 775
Processor 2600x / C2D E7600
Motherboard B450 Aorus / ASUS P5G41C-M LX
Cooling TT Esports Duo / Chinesium cooler
Memory 16GB DDR4 3ghz / 4GB DDR2 800mhz
Video Card(s) 2060 Super / 5700-XT / GTX 650Ti
Storage 120GB + 1TB SSD / 160GB SSD
Display(s) Samsung CRG5 144hz QD
Case CiT shit chassis modded / Coolermaster Elite 430
Audio Device(s) Soundblaster FX / Audigy 2 ZX
Power Supply Superflower Leadex III GOLD / BeQuiet 450w bronze.
Mouse Razer Basilisk
Keyboard Read Dragon Kumara
Software Windows 10 Pro x64
Benchmark Scores 1 Billion
With Intfail doing well we can see AMDuhh should win now.
 
Joined
Jul 31, 2014
Messages
480 (0.13/day)
System Name Diablo | Baal | Mephisto | Andariel
Processor i5-3570K@4.4GHz | 2x Xeon X5675 | i7-4710MQ | i7-2640M
Motherboard Asus Sabertooth Z77 | HP DL380 G6 | Dell Precision M4800 | Lenovo Thinkpad X220 Tablet
Cooling Swiftech H220-X | Chassis cooled (6 fans + HS) | dual-fanned heatpipes | small-fanned heatpipe
Memory 32GiB DDR3-1600 CL9 | 96GiB DDR3-1333 ECC RDIMM | 32GiB DDR3L-1866 CL11 | 8GiB DDR3L-1600 CL11
Video Card(s) Dual GTX 670 in SLI | Embedded ATi ES1000 | Quadro K2100M | Intel HD 3000
Storage many, many SSDs and HDDs....
Display(s) 1 Dell U3011 + 2x Dell U2410 | HP iLO2 KVMoIP | 3200x1800 Sharp IGZO | 1366x768 IPS with Wacom pen
Case Corsair Obsidian 550D | HP DL380 G6 Chassis | Dell Precision M4800 | Lenovo Thinkpad X220 Tablet
Audio Device(s) Auzentech X-Fi HomeTheater HD | None | On-board | On-board
Power Supply Corsair AX850 | Dual 750W Redundant PSU (Delta) | Dell 330W+240W (Flextronics) | Lenovo 65W (Delta)
Mouse Logitech G502, Logitech G700s, Logitech G500, Dell optical mouse (emergency backup)
Keyboard 1985 IBM Model F 122-key, Ducky YOTT MX Black, Dell AT101W, 1994 IBM Model M, various integrated
Software FAAAR too much to list
Ok, here's a comment from one of the more paranoid members of TPU, e.g. me:
1) This exploit heavily relies on debugging interface being enabled. On 99.9% of all skylake systems(even laptops and tablets) it is not.
2) In order to enable the debugging interface you have to be able to update BIOS and ME firmware. So, it's not going to be as simple as sticking something in USB port (some boards even have ME locked via jumper)
3) The method itself, even if successful and meets all preconditions, is so unpractical, that you may as well ignore it. No Evil NSA Agent, or Crazy Russian Hacker is going to break into your house, update your BIOS, stick something weird into your USB port, just so he can monitor and log all of your naughty porn history.

It may be interesting from an academic perspective, but it will never become a new "rubber ducky", because it requires unrestricted access to the target system (which kind of defeats the purpose).

BTW, I haven't seen anyone blaming MS for Kernel Mode Debugging, or Google for ADB. Those present more imminent danger and are network-friendly.

For me and you, no. But for high-value targets on the other hand (political dissidents, journalists in various places, security researchers researching certain targets, people with access to very cutting-endge IP for example), it's a perfectly valid attack point. Once you are a target, you should worry. For the rest of us, we fly by being too many to target.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,449 (2.42/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
The hacker who discovered this obviously has some insight into the machine code so this smells like an inside job. Regardless, all software is hack-able. If you are afraid someone will compromise your system using a USB stick you best lock up your PC in a safe before leaving the house.
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,474 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
For me and you, no. But for high-value targets on the other hand (political dissidents, journalists in various places, security researchers researching certain targets, people with access to very cutting-endge IP for example), it's a perfectly valid attack point. Once you are a target, you should worry. For the rest of us, we fly by being too many to target.
You've probably skipped the "unpractical" part. If you have access to UEFI firmware, it will be easy to exploit existing UEFI bugs, rather than doing this circle-jerk in order to do the same thing.

It's like, if you are a hypothetical evil NSA agent, and you need to surveil some anti-political rebel journalist, you are going to dress up as a phone company employee and install a tiny ultrasonic speaker into user's PC, alongside a trojan which uses webcam mic to record all conversations, then you implant an ultrasonic mic into his landline phone and transmit the recorded conversations via Dail-up while no one is home. By the time you are done installing all of this, the Journalist will probably accept you as a family member, or at least an accidental roommate, and tell you his secrets anyway.
 
Joined
Jul 31, 2014
Messages
480 (0.13/day)
System Name Diablo | Baal | Mephisto | Andariel
Processor i5-3570K@4.4GHz | 2x Xeon X5675 | i7-4710MQ | i7-2640M
Motherboard Asus Sabertooth Z77 | HP DL380 G6 | Dell Precision M4800 | Lenovo Thinkpad X220 Tablet
Cooling Swiftech H220-X | Chassis cooled (6 fans + HS) | dual-fanned heatpipes | small-fanned heatpipe
Memory 32GiB DDR3-1600 CL9 | 96GiB DDR3-1333 ECC RDIMM | 32GiB DDR3L-1866 CL11 | 8GiB DDR3L-1600 CL11
Video Card(s) Dual GTX 670 in SLI | Embedded ATi ES1000 | Quadro K2100M | Intel HD 3000
Storage many, many SSDs and HDDs....
Display(s) 1 Dell U3011 + 2x Dell U2410 | HP iLO2 KVMoIP | 3200x1800 Sharp IGZO | 1366x768 IPS with Wacom pen
Case Corsair Obsidian 550D | HP DL380 G6 Chassis | Dell Precision M4800 | Lenovo Thinkpad X220 Tablet
Audio Device(s) Auzentech X-Fi HomeTheater HD | None | On-board | On-board
Power Supply Corsair AX850 | Dual 750W Redundant PSU (Delta) | Dell 330W+240W (Flextronics) | Lenovo 65W (Delta)
Mouse Logitech G502, Logitech G700s, Logitech G500, Dell optical mouse (emergency backup)
Keyboard 1985 IBM Model F 122-key, Ducky YOTT MX Black, Dell AT101W, 1994 IBM Model M, various integrated
Software FAAAR too much to list
You've probably skipped the "unpractical" part. If you have access to UEFI firmware, it will be easy to exploit existing UEFI bugs, rather than doing this circle-jerk in order to do the same thing.

It's like, if you are a hypothetical evil NSA agent, and you need to surveil some anti-political rebel journalist, you are going to dress up as a phone company employee and install a tiny ultrasonic speaker into user's PC, alongside a trojan which uses webcam mic to record all conversations, then you implant an ultrasonic mic into his landline phone and transmit the recorded conversations via Dail-up while no one is home. By the time you are done installing all of this, the Journalist will probably accept you as a family member, or at least an accidental roommate, and tell you his secrets anyway.

Intercepting the machine in the mail or customs is safer and easier. And for all the bit's you've listed, a pro can do easily in under an hour if they're fully prepared.
 
Joined
Dec 29, 2010
Messages
3,456 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
Woot, now this is some progress. Who cares about IPC when it's even faster to hack now!
 
Joined
Mar 23, 2012
Messages
777 (0.18/day)
Location
Norway
System Name Games/internet/usage
Processor I7 5820k 4.2 Ghz
Motherboard ASUS X99-A2
Cooling custom water loop for cpu and gpu
Memory 16GiB Crucial Ballistix Sport 2666 MHz
Video Card(s) Radeon Rx 6800 XT
Storage Samsung XP941 500 GB + 1 TB SSD
Display(s) Dell 3008WFP
Case Caselabs Magnum M8
Audio Device(s) Shiit Modi 2 Uber -> Matrix m-stage -> HD650
Power Supply beQuiet dark power pro 1200W
Mouse Logitech MX518
Keyboard Corsair K95 RGB
Software Win 10 Pro
Woot, now this is some progress. Who cares about IPC when it's even faster to hack now!

We could start measuring Incursions Per Clock in stead.
 
Joined
Feb 19, 2006
Messages
6,270 (0.94/day)
Location
New York
Processor INTEL CORE I9-9900K @ 5Ghz all core 4.7Ghz Cache @1.305 volts
Motherboard ASUS PRIME Z390-P ATX
Cooling CORSAIR HYDRO H150I PRO RGB 360MM 6x120mm fans push pull
Memory CRUCIAL BALLISTIX 3000Mhz 4x8 32gb @ 4000Mhz
Video Card(s) EVGA GEFORECE RTX 2080 SUPER XC HYBRID GAMING
Storage ADATA XPG SX8200 Pro 1TB 3D NAND NVMe,Intel 660p 1TB m.2 ,1TB WD Blue 3D NAND,500GB WD Blue 3D NAND,
Display(s) 50" Sharp Roku TV 8ms responce time and Philips 75Hz 328E9QJAB 32" curved
Case BLACK LIAN LI O11 DYNAMIC XL FULL-TOWER GAMING CASE,
Power Supply 1600 Watt
Software Windows 10
That isn't a U SKU CPU, so it's not affected.


Yeah but I also have this one coming today and looks like it will be vulnerable.
ASUS Premium High Performance 15.6" FHD Laptop(Intel Core i7-5500U, 8GB RAM, 1TB HDD, DVD,Windows 10- Black)

looks like I'm gonna need my tinfoil again! lol
 
Joined
Jul 29, 2014
Messages
484 (0.14/day)
Location
Fort Sill, OK
Processor Intel 7700K 5.1Ghz (Intel advised me not to OC this CPU)
Motherboard Asus Maximus IX Code
Cooling Corsair Hydro H115i Platinum
Memory 48GB G.Skill TridentZ DDR4 3200 Dual Channel (2x16 & 2x8)
Video Card(s) nVIDIA Titan XP (Overclocks like a champ but stock performance is enough)
Storage Intel 760p 2280 2TB
Display(s) MSI Optix MPG27CQ Black 27" 1ms 144hz
Case Thermaltake View 71
Power Supply EVGA SuperNova 1000 Platinum2
Mouse Corsair M65 Pro (not recommded, I am on my second mouse with same defect)
Software Windows 10 Enterprise 1803
Benchmark Scores Yes I am Intel fanboy that is my benchmark score.
Joined
Jul 5, 2013
Messages
25,559 (6.47/day)
The hacker who discovered this obviously has some insight into the machine code so this smells like an inside job. Regardless, all software is hack-able. If you are afraid someone will compromise your system using a USB stick you best lock up your PC in a safe before leaving the house.

It should be noted however, that this hacking method can NOT be used to bypass full disc encryption, if the system is off when the attempt is made. I am referring to Truecrypt, VeraCrypt and the like. Bitlocker does not count as it requires part of the OS to remain unencrypted.
 
Joined
Jul 5, 2013
Messages
25,559 (6.47/day)
Intel...

So classic!
 
Joined
Jul 5, 2013
Messages
25,559 (6.47/day)
Ok, here's a comment from one of the more paranoid members of TPU, e.g. me:
1) This exploit heavily relies on debugging interface being enabled. On 99.9% of all skylake systems(even laptops and tablets) it is not.
2) In order to enable the debugging interface you have to be able to update BIOS and ME firmware. So, it's not going to be as simple as sticking something in USB port (some boards even have ME locked via jumper)
3) The method itself, even if successful and meets all preconditions, is so unpractical, that you may as well ignore it. No Evil NSA Agent, or Crazy Russian Hacker is going to break into your house, update your BIOS, stick something weird into your USB port, just so he can monitor and log all of your naughty porn history.

It may be interesting from an academic perspective, but it will never become a new "rubber ducky", because it requires unrestricted access to the target system (which kind of defeats the purpose).

BTW, I haven't seen anyone blaming MS for Kernel Mode Debugging, or Google for ADB. Those present more imminent danger and are network-friendly.

Hey be nice, Crazy Russian Hacker is cool! [ https://www.youtube.com/user/CrazyRussianHacker ]

And FYI, ADB is not as network friendly as you think. Trust me on that one!
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,474 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
Hey be nice, Crazy Russian Hacker is cool! [ https://www.youtube.com/user/CrazyRussianHacker ]

And FYI, ADB is not as network friendly as you think. Trust me on that one!
Just like JTAG over USB is not as easy to work with as advertised (or flashing UEFI firmware with homemade tools for that matter).

ah....that CrazyRussianHacker... then we are all doomed, because "Safety is numbeg one pgiogity"! :roll:
 
Joined
Jul 5, 2013
Messages
25,559 (6.47/day)
Just like JTAG over USB is not as easy to work with as advertised (or flashing UEFI firmware with homemade tools for that matter).

ah....that CrazyRussianHacker... then we are all doomed, because "Safety is numbeg one pgiogity"! :roll:

Right? Been watching his video's for a while and his english is getting better as time does on. But we're getting off-topic..
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,474 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
I only know about this dude, because he keeps popping up in Youtube suggested videos, no matter how hard I try to avoid him.
Almost like RED21 with his DIY cheeseburger.:banghead:
 
Top