Showing posts with label PCs. Show all posts
Showing posts with label PCs. Show all posts

Tuesday, May 2, 2017

PCs with Intel Server Chipsets, Launched in Past 9-Years, Can be Hacked Remotely


Monday, May 01, 2017 Swati Khandelwal



A critical remote code execution (RCE) vulnerability has been discovered in the remote management features on computers shipped with Intel processors for nearly a decade, which could allow attackers to take control of the computers remotely.

The RCE flaw (CVE-2017-5689) resides in the Intel's Management Engine (ME) technologies such as Active Management Technology (AMT), Small Business Technology (SBT), and Intel Standard Manageability (ISM), according to an advisory published Monday by Intel.

These features allow a systems administrator to remotely manage large fleets of computers over a network (via ports 16992 or 16993) in an organization or an enterprise.



Since these functions are present only in enterprise solutions, and mostly in server chipsets, the vulnerability doesn't affect chips running on Intel-based consumer PCs.

According to the Intel advisory, this critical security vulnerability was discovered and reported in March by security researcher Maksim Malyutin of Embedi, and could be exploited in two ways:

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel AMT and ISM. However, Intel SBT is not vulnerable to this issue.
An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel AMT, ISM, and SBT.

How Bad is this Vulnerability
In short, a potential attacker can log into a vulnerable machine's hardware and silently perform malicious activities, like tampering with the machine, installing virtually undetectable malware, using AMT's features.

The PC's operating system never knows what's going around because AMT has direct access to the computer's network hardware. When AMT is enabled, any packet sent to the PC's wired network port will be redirected to the Management Engine and passed on to AMT – the OS never sees those packets.



These insecure management features have been made available in various, but not all, Intel chipsets for nearly a decade, starting from Nehalem Core i7 in 2008 to this year's Kaby Lake Core, with a higher degree of a flaw for users on Intel vPro systems.

Fortunately, none of these Management Engine features come enabled by default, and system administrators must first enable the services on their local network. So, basically if you are using a computer with ME features enabled, you are at risk.

Despite using Intel chips, modern Apple Mac computers do not ship with the AMT software and are thus not affected by the flaw.


Affected Firmware Versions & How to Patch
The security flaw affects Intel manageability firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 for Intel's AMT, ISM, and SBT platforms. However, versions before 6 or after 11.6 are not impacted.

Intel has rated the vulnerability as highly critical and released new firmware versions, instructions to detect if any workstation runs AMT, ISM, or SBT, a detection guide to check if your system is vulnerable, and a mitigation guide for those organizations that can not immediately install updates.

The chipmaker is recommending vulnerable customers install a firmware patch as soon as possible.

"Fixing this requires a system firmware update in order to provide new ME [management engine] firmware (including an updated copy of the AMT code). Many of the affected machines are no longer receiving firmware updates from their manufacturers, and so will probably never get a fix," CoreOS security engineer Matthew Garrett explained in a blog post. "Anyone who ever enables AMT on one of these devices will be vulnerable."

"That's ignoring the fact that firmware updates are rarely flagged as security critical (they don't generally come via Windows Update), so even when updates are made available, users probably won't know about them or install them."You can head on to Intel advisory for further details.

Tuesday, November 1, 2016

Microsoft stops sales of Windows 7 Pro, Windows 8.1 to PC makers...It's all Windows 10





After extending deadline by two years, Microsoft sticks a fork in the world's most popular operating system.


Microsoft today quietly put an end to sales of Windows 7 licenses to computer makers, marking a major milestone for the seven-year-old OS.
According to Microsoft’s rules, the Redmond, Wash. company stopped selling Windows 7 Professional or any version of Windows 8.1 to OEMs (original equipment manufacturers) as of Oct. 31.
The end of Windows 7 and Windows 8.1 left only Windows 10 as a long-term choice for OEMs that pre-load Windows on their wares.
The original end-of-sales deadline for Windows 7 Professional was to be Oct. 31, 2014—two years after the launch of Windows 8—but early that year Microsoft broke with practice and only called for an end to consumer systems. It left open the cut-off for Windows 7 Professional, saying it would give a one-year warning before it demanded that OEMs stop selling PCs with that edition.
Organizations with enterprise licensing agreements and Software Assurance—the annuity-like program that provides additional rights—may continue to purchase new PCs, then downgrade the OS from the already-installed Windows 10 to Windows 7 if they want to keep using the older edition.
And new Windows 7 Professional PCs won’t vanish immediately; OEMs will be allowed to use what licenses they have in stock.
For example, Dell’s online store today still listed 17 different notebook configurations equipped with Windows 7 Professional. The same goes for smaller computer sellers, like Puget Systems, an Auburn, Wash. custom PC maker: Such shops can continue to build new Windows 7 Professional PCs until their supply of licenses dries up.
Microsoft pulled the plug on Windows 7 even though it remains the most popular operating system on the planet. Windows 7 has lost about a fifth of its user share since the mid-2015 launch of Windows 10, but according to U.S. analytics vendor Net Applications, it powered 48% of all personal computers in October, more than twice Windows 10’s share.
Windows 7 support is to continue until January 2020, giving users just over three years to migrate to another operating system.



Wednesday, October 5, 2016

Service providers still act like utilities





By Bob O'Donnell on October 4, 2016, 10:45 AM




If you ever want to enliven a cocktail party filled with executives from the telco or cable industry, just start talking about dumb pipes. As in, “your service doesn’t offer anything more than a simple connection from my devices to the internet content I want—it’s a dumb pipe.”

Of course, most of you will never have to worry about going through such an awkward social encounter, but if you do—that zinger is bound to get things going.

All kidding aside, the notion that carriers and other service providers offer little more than basic connectivity has been an industry hot button for some time. Even now, despite a number of efforts to spice things up, most telcos and cable service providers are seen as companies that provide a very indistinct connectivity service that people only reluctantly pay for.

The primary differentiators for competitive players in this space are price, price and, oh yeah, price, with maybe a bit of coverage or service quality thrown in for good measure. It’s little wonder that many consumers hold these companies in such low esteem—they just don’t see the value in the services beyond basic connectivity. It’s also not surprising that so many people are looking at cord-cutting, cord replacement, or other options.

But it doesn’t have to be this way.

The amount of data that telco and cable service providers have access to should allow them to generate some very interesting, useful and valuable services that consumers should be happy to pay for. Now, admittedly, there are some serious privacy and regulatory concerns that have to be taken into consideration, but with appropriate anonymizing techniques, there are

Tuesday, September 27, 2016

Warning You Can't Install Linux On Microsoft Signature Edition PCs from Lenovo


Microsoft-signature-edition-linux
In past few months, Microsoft opened the source code of a lot of its projects, convincing people that the company loves Linux.

But a new report shows that Microsoft is not really a big supporter of Linux.

Microsoft has banned Linux on some Windows 10 powered Signature Edition PCs, which provides the cleanest Windows experience on the market.

Signature Edition PCs are different from other systems because it is carefully and meticulously configured by Microsoft to run Windows 10 with no bloatware, paid promotional web shortcuts, or other pre-installed apps, for providing better performance.

But besides bloatware and other pre-installed apps, Microsoft won't allow you to install Linux (or any operating system) on it.

This news is not a rumor as a Reddit user BaronHK reported that he found it impossible to install Linux on the Signature Edition Lenovo Yoga 900 ISK2 UltraBook because Microsoft has locked the SSD in a proprietary RAID mode that can only be read by Windows.

When contacted Lenovo, the company confirmed that it had signed an agreement with Microsoft to make this happen.
"This system has a Signature Edition of Windows 10 Home installed. It is locked per our agreement with Microsoft," a Lenovo employee responded to a comment made by BaronHK about the issue.
Lenovo laptops that are not allowing its users to install Linux include the aforementioned Yoga 900 ISK2, the Yoga 900S, as well as the Yoga 710S.
linux-microsoft
Some have suggested that the issue that prevents Linux from being installed could be Microsoft decision, while others believe that the issue could be related to how the systems have been configured by Lenovo.

For now, all which is clear is that, if you own a Lenovo Signature Edition laptop, you can not install Linux on it.

Microsoft and Lenovo still have to officially comment on this possible restriction configured for Signature Edition PCs.
Related Posts Plugin for WordPress, Blogger...