Results 1 to 3 of 3

Thread: Hacker Finds Hidden 'God Mode' on Old x86 CPUs

  1. #1

    Hacker Finds Hidden 'God Mode' on Old x86 CPUs

    Some x86 CPUs have hidden backdoors that let you seize root by sending a command to an undocumented RISC core that manages the main CPU, security researcher Christopher Domas told the Black Hat conference here Thursday (Aug. 9).

    The command — ".byte 0x0f, 0x3f" in Linux — "isn't supposed to exist, doesn't have a name, and gives you root right away," Domas said, adding that he calls it "God Mode."

    The backdoor completely breaks the protection-ring model of operating-system security, in which the OS kernel runs in ring 0, device drivers run in rings 1 and 2, and user applications and interfaces ("userland") run in ring 3, furthest from the kernel and with the least privileges. To put it simply, Domas' God Mode takes you from the outermost to the innermost ring in four bytes.
    "We have direct ring 3 to ring 0 hardware privilege escalation," Domas said. "This has never been done."
    That's because of the hidden RISC chip, which lives so far down on the bare metal that Domas half-joked that it ought to be thought of as a new, deeper ring of privilege, following the theory that hypervisors and chip-management systems can be considered ring -1 or ring -2.
    "This is really ring -4," he said. "It's a secret, co-located core buried alongside the x86 chip. It has unrestricted access to the x86."
    The good news is that, as far as Domas knows, this backdoor exists only on VIA C3 Nehemiah chips made in 2003 and used in embedded systems and thin clients. The bad news is that it's entirely possible that such hidden backdoors exist on many other chipsets.
    "These black boxes that we're trusting are things that we have no way to look into," he said. "These backdoors probably exist elsewhere."

    More at: https://www.tomshardware.com/news/x8...ode,37582.html
    Never attempt to teach a pig to sing; it wastes your time and annoys the pig.

    Robert Heinlein

    Give a man an inch and right away he thinks he's a ruler

    Groucho Marx

    I love mankind…it’s people I can’t stand.

    Linus, from the Peanuts comic

    You cannot have liberty without morality and morality without faith

    Alexis de Torqueville

    Those who fail to learn from the past are condemned to repeat it.
    Those who learn from the past are condemned to watch everybody else repeat it

    A Zero Hedge comment



  2. Remove this section of ads by registering.
  3. #2
    The "undocumented RISC core" might be responsible for lack of speed increases in modern CPUs.

  4. #3
    No worries. The many nations of the world that have access to these back doors will keep them safe for your protection.
    "Foreign aid is taking money from the poor people of a rich country, and giving it to the rich people of a poor country." - Ron Paul
    "Beware the Military-Industrial-Financial-Pharma-Corporate-Internet-Media-Government Complex." - B4L update of General Dwight D. Eisenhower
    "Debt is the drug, Wall St. Banksters are the dealers, and politicians are the addicts." - B4L
    "Totally free immigration? I've never taken that position. I believe in national sovereignty." - Ron Paul

    Proponent of real science.
    The views and opinions expressed here are solely my own, and do not represent this forum or any other entities or persons.



Similar Threads

  1. Intel CPUs Vulnerable To New 'BranchScope' Attack
    By DamianTV in forum Privacy & Data Security
    Replies: 2
    Last Post: 03-28-2018, 01:51 AM
  2. Replies: 1
    Last Post: 04-19-2017, 05:30 AM
  3. Replies: 9
    Last Post: 07-03-2013, 09:49 PM
  4. Ecuador Finds Hidden Microphone At London Embassy
    By kcchiefs6465 in forum U.S. Political News
    Replies: 4
    Last Post: 07-03-2013, 09:31 PM
  5. Replies: 0
    Last Post: 06-01-2013, 11:53 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •