logoalt Hacker News

Exploiting System Management Mode with a very long interrupt

82 pointsby WhiteDawntoday at 4:03 PM23 commentsview on HN

Comments

cheschiretoday at 7:40 PM

Almost nothing from this GitHub profile posted until the last four days.

From a meta perspective what is going on? What am I missing? Why is this GitHub profile suddenly getting massive attention and making front page so frequently?

show 2 replies
mike_hearntoday at 5:12 PM

The designers of the firmware anticipate this attack but punt it to the vendor, apparently:

    //
    // Platform implementor should choose a timeout value appropriately:
    
    [snip]

    // - The timeout value must be longer than longest possible IO operation in the system
show 1 reply
Hyperlisktoday at 6:46 PM

Related repo from them, mentioned in the readme as well: https://github.com/xoreaxeaxeax/asm-hall-of-shame

> Instruction latency analysis usually focuses on performance optimization—making code run as fast as possible. The Assembly Hall of Shame takes the opposite approach: searching for the absolute floor of single-instruction performance.

Fun stuff!

hyperhellotoday at 5:54 PM

SMM calls for a timeout because it wants everything to be between instructions pro forma. So there’s a very long instruction on a core, but after it completes, the core does stop, right? It seems like to make this into an attack you’d have to a very long instruction that also somehow interacts with the thing the SMM is doing, while it’s doing it.

nazgulsenpaitoday at 4:45 PM

I'm amused at the lengths the readme goes to in order to drive home the fact that this needs to be a LOOOOOOOOOOOOOOOOOOOONG instruction, including the unnecessarily long code block illustration. The topic is interesting anyway, but that makes it way more entertaining.

show 1 reply
londons_exploretoday at 4:52 PM

Unclear why there is a 1 second timeout at all.

Presumably the patch for that will be to make it an infinity timeout.

show 3 replies
Liftyeetoday at 5:23 PM

I don't know much about the specifics of CPU architecture apart from the existence of assembly and different modes. Either way the explanation was still entertaining and interesting. smiiiiiiii

PunchyHamstertoday at 7:31 PM

It's nice to see SMM is as terrible idea now as it was at moment of conception.

All coz they can't be arsed to put a tiny management core separate from the rest and save a penny

kmeisthaxtoday at 4:54 PM

...huh, I was wondering why serial machine code prankster xoreaxeaxeax was keeping lists of extremely long-running instructions.

Hopefully this is at least only possible in kernel mode, right?

Right?!

show 3 replies