ISC StormCast for Friday, December 8th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 December 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, December 8th, 2017 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:11.8 | Remember about two weeks ago, Intel released a set of patches for its management engine, infamous Intel M.E and also active management technology or AMT, |
| 0:24.8 | to patch a couple of flaws. Well, we now got more details about this flaw at Blackhead Europe. |
| 0:33.7 | Positive Technologies who worked with Intel on these flaws and who originally discovered it, |
| 0:40.3 | did a demonstration of how to exploit these vulnerabilities. |
| 0:45.4 | Due to this particular code running outside of anything the operating system controls |
| 0:51.7 | any kind of security software that you are running on your system |
| 0:57.2 | like antivirus and the like is of course pretty much useless. On the other hand, this subsystem |
| 1:04.1 | is actually powered on as soon as you connect the computer to power. You don't actually have to really start up the system. |
| 1:13.6 | So this allows you to attack this subsystem on a computer that's turned off. |
| 1:19.6 | On the other hand, you do need physical access to the system |
| 1:23.6 | unless you can gain access via any of the remote control software like IPMI. |
| 1:30.3 | But in this case, you would need to get past authentication. |
| 1:35.3 | Of course, there have been in the past a couple of authentication bypass vulnerabilities in various IPMI or VPro implementations. |
| 1:45.0 | But at the very least, this opens up the possibility of a pretty nasty evil mate attack. |
| 1:51.5 | Usually that's a vulnerability that where you refer to leaving a laptop, unsupervised, in a hotel room, |
| 1:59.0 | and then a mate or someone with access to the hotel room would |
| 2:02.5 | be able to exploit it. |
| 2:04.3 | In this case they would have full access to the management engine. |
| 2:08.9 | They could introduce additional code or they could just swap out the firmware on it. |
| 2:15.7 | Now the particular exploit was demoed here at Blackhead Europe took advantage of a stack-based |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

