LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-12-2015, 06:43 PM   #1
aus9
LQ 5k Club
 
Registered: Oct 2003
Location: Western Australia
Distribution: Icewm
Posts: 5,842

Rep: Reputation: Disabled
Intel sinkhole rootkit info


Hi

Just seen this page
http://www.itnews.com.au/News/407809...-16-years.aspx

links to
https://github.com/xoreaxeaxeax/sinkhole

I am hoping rootkit hunter and other such tools might be able to detect it?

If not, is there any concerns on Linux for people using these Intel processors made between 1995 and 2011?

thanks for reading
 
Old 08-13-2015, 01:03 AM   #2
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
By the looks of it this would be undetectable by rkhunter though there is a hint that the OS could, perhaps, be patched to make it detectable.
http://www.theregister.co.uk/2015/08...el_processors/
Since it's baked into the CPU though I wouldn't think there's much can be done in software.
 
Old 08-13-2015, 09:01 AM   #3
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
"with a special operating system driver, he managed to install a rootkit into the SMM." is too vague.
Is it me, or is this ironic to any one else?

16 year old hole, 5 years after the fact, and this is news?
Seems more like click-bait.
 
Old 08-13-2015, 01:30 PM   #4
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Quote:
Originally Posted by Habitual View Post
"with a special operating system driver, he managed to install a rootkit into the SMM." is too vague.
Is it me, or is this ironic to any one else?

16 year old hole, 5 years after the fact, and this is news?
Seems more like click-bait.
Is there a previous source?
If not, then I would say it's news. If a new fatal flaw were suddenly found in a rare classic car I'd still call it news for people who are into cars.
 
Old 08-13-2015, 06:36 PM   #5
aus9
LQ 5k Club
 
Registered: Oct 2003
Location: Western Australia
Distribution: Icewm
Posts: 5,842

Original Poster
Rep: Reputation: Disabled
Hi Habitual

Quote:
16 year old hole, 5 years after the fact, and this is news?
Seems more like click-bait.
Then I guess you have not even bothered to read the new link
Quote:
Domas said when he revealed the hardware bug at the Black Hat conference in Las Vegas last week.

Read more: http://www.itnews.com.au/News/407809...#ixzz3ik0JPHcY
and yes I do get offended when a LQ member may be suggesting I am some kind of troll or other such nastiness.
 
Old 08-14-2015, 05:39 AM   #6
fatmac
LQ Guru
 
Registered: Sep 2011
Location: Upper Hale, Surrey/Hants Border, UK
Distribution: Mainly Devuan, antiX, & Void, with Tiny Core, Fatdog, & BSD thrown in.
Posts: 5,492

Rep: Reputation: Disabled
You would need to get root priviledges to use it, so why bother going the extra mile, when you already have the system. I think it is more theoretical than practical.
 
Old 08-14-2015, 07:31 AM   #7
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by aus9 View Post
and yes I do get offended when a LQ member may be suggesting I am some kind of troll or other such nastiness.
I was critical of the article, not you. So Relax.
 
Old 08-14-2015, 01:10 PM   #8
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Quote:
Originally Posted by fatmac View Post
You would need to get root priviledges to use it, so why bother going the extra mile, when you already have the system. I think it is more theoretical than practical.
As somebody commented when The Register ran this: Privilege escalation bugs and server compromises happen all the time -- and the last resort is often to wipe and start again. With this method you can't wipe and start again (well, not without using the exploit yourself) as the malware is in your motherboard's firmware. So, no matter how this gets there (in second hand equipment even?) you couldn't find it or remove it at that time as you would have had no knowledge of its existence.
Oddly enough it reminds me of this:
http://www.theregister.co.uk/2015/08...irmware_nasty/
 
Old 08-14-2015, 06:07 PM   #9
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Habitual View Post
"with a special operating system driver, he managed to install a rootkit into the SMM." is too vague.
Dunno but I do remember there was SMM stuff in the news a couple of years back.
 
  


Reply

Tags
sinkhole rootkit



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rootkit hunter false positive for Xzibit Rootkit on CentOS 4.8? abefroman Linux - Security 2 12-20-2009 08:19 AM
NOOB INFO: ia64 versions are *NOT* for Intel Core 2 Duo or Quad 64 bit processors thriftee Debian 4 01-31-2009 11:33 AM
Help Me!! Rootkit Axaline Linux - Newbie 8 10-26-2007 02:42 AM
PPC (PowerPC) G4: Altivec & SMP Support: info, etc.; also, Mac Mini info, etc. HowDoIProgramIt Linux - Hardware 0 05-29-2007 01:19 PM
Sound problem 10.0.... intel 830 chipset, lspci info inside RodCas Slackware 8 02-25-2005 01:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration