funsec mailing list archives

Re: Pentium Computers Vulnerable to Attack?


From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Wed, 12 Apr 2006 01:13:14 -0600

On 4/12/06, Dude VanWinkle <dudevanwinkle () gmail com> wrote:
Err nevermind about that last question, I guess SMM is still part of
the OS, sorry for the brainfart all

Crap, not part of the OS, but the code... well here let me make sure I
got this right.

When your macine gets a signal to enter system management mode, it
takes a bit of code (written to memory during boot?) that enables it
to run at 16bit, till it gets the OK signal. When it gets the OK
signal, the processor grabs its previous 32 bit environment (dumped to
memory when SMM was triggered?) and runs that.

This part of Xserver enables you to overwrite the part of memory that
holds the SMM "image",and the true danger is that from there it could
overwrite the part of memory that holds the
"what-I-was-doing-before-smm" image?

if I got that right (a longshot), then this seems pretty hard to
actually be afraid of (even more of a longshot).

(sorry for the triple post)
-JP

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: