[flalug] Intel CPU cache poisoning: dangerously easy on Linux

From: tom smith (atomsmitty@gmail.com)
Date: Wed Apr 22 2009 - 16:46:49 EDT


http://www.networkworld.com/community/node/41180
"Here's how the attack works in layman’s terms. First off, we need to set the
stage a bit. The exploit code was only written for Intel’s DQ35 motherboards.
The DQ35 is one of their modern boards. According to Joanna’s paper, Intel
reported that their newest motherboards (DQ45’s for example) are not vulnerable
to this attack. An exact list of affected motherboards was not offered in the
research, nor any mention if AMD systems are affected as well.

The goal of the attack is to gain access to the normally very well protected SMM
(system management mode) space. From there you would be able to load your SMM
rootkit into SMM space giving you full control over the hypervisor or operation
system. Another benefit is that your rootkit would be almost undetectable by the
operating system. According to the whitepaper: "The memory controller offers
dedicated locks to limit access to only system firmware (BIOS)."



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 20:46:25 EDT