E lutlile 20GB ea litokomane tsa kahare tsa tekheniki le likhoutu tsa mohloli oa Intel

Tilly Kottmann (Tillie Kottman), moqapi oa sethala sa Android se tsoang Switzerland, ea etellang pele mocha oa Telegraph mabapi le ho lutla ha data, e hatisitsoeng 20 GB ea litokomane tsa kahare tsa tekheniki le khoutu ea mohloli e fumanoeng ka lebaka la tlhaiso-leseling e kholo e tsoang ho Intel e fumaneha phatlalatsa. Sena se boleloa e le sete ea pele ho tsoa pokellong e fanoeng ke mohloli o sa tsejoeng. Litokomane tse ngata li tšoailoe e le makunutu, liphiri tsa khoebo, kapa li ajoa feela tlas'a tumellano ea ho se senole.

Litokomane tsa morao-rao li ngotsoe mathoasong a May 'me li kenyelletsa tlhahisoleseding e mabapi le sethala se secha sa seva sa Cedar Island (Whitley). Ho boetse ho na le litokomane tsa 2019, mohlala, tse hlalosang sethala sa Tiger Lake, empa boholo ba tlhaiso-leseling ke ea 2014. Ntle le litokomane, sete se boetse se na le khoutu, lisebelisoa tsa ho lokisa liphoso, litšoantšo, bakhanni le livideo tsa koetliso.

Ba bang tlhahisoleseding ho tloha sehlopheng:

  • Litaelo tsa Intel ME (Management Engine), lisebelisoa tsa flash le mehlala ea li-platform tse fapaneng.
  • Reference BIOS ts'ebetsong bakeng sa sethala sa Kabylake (Purley), mehlala le khoutu ea ho qala (ka nalane ea phetoho ho tloha git).
  • Lingoliloeng tsa mohloli oa Intel CEFDK (Consumer Electronics Firmware Development Kit).
  • Khoutu ea liphutheloana tsa FSP (Firmware Support Package) le merero ea tlhahiso ea liforomo tse fapaneng.
  • Lisebelisoa tse fapaneng tsa ho lokisa liphoso le nts'etsopele.
  • Simics-simulator ea sethala sa Rocket Lake S.
  • Merero le litokomane tse fapaneng.
  • Bakhanni ba binary ba kh'amera ea Intel e etselitsoeng SpaceX.
  • Merero, litokomane, firmware le lisebelisoa bakeng sa sethala sa Tiger Lake se e-so lokolloe.
  • Kabylake FDK livideo tsa koetliso.
  • Intel Trace Hub le lifaele tse nang le li-decoder tsa mefuta e fapaneng ea Intel ME.
  • Ts'ebetsong ea litšupiso ea sethala sa Elkhart Lake le mehlala ea khoutu ho tšehetsa sethala.
  • Litlhaloso tsa li-block tsa Hardware ka puo ea Verilog bakeng sa li-platform tse fapaneng tsa Xeon.
  • Debug BIOS/TXE e hahela liforomo tse fapaneng.
  • Bootguard SDK.
  • Simulator ea ts'ebetso ea Intel Snowridge le Snowfish.
  • Merero e fapaneng.
  • Lithempleite tsa thepa ea ho rekisa.

Intel e re e butse lipatlisiso mabapi le ketsahalo ena. Ho latela tlhaiso-leseling ea pele, data e fumanoe ka sistimi ea tlhahisoleseling "Intel Resource le Setsi sa Moralo", e nang le tlhaiso-leseling e fokolang ea phihlello bakeng sa bareki, balekane le lik'hamphani tse ling tseo Intel e sebelisanang le tsona. Ho ka etsahala hore ebe tlhahisoleseling e kentsoe le ho hatisoa ke motho ea nang le phihlello ea sistimi ena ea tlhahisoleseling. E mong oa basebetsi ba mehleng ba Intel hlalositsoe ha a ntse a bua ka mofuta oa hae ho Reddit, a bonts'a hore ho lutla hoo e ka ba sephetho sa ts'abo ea mohiruoa kapa ho qhekella e mong oa baetsi ba liboto tsa bo-mme ba OEM.

Motho ea sa tsejoeng ea rometseng litokomane hore li phatlalatsoe a supahore data e jarollotsoe ho tsoa ho seva e sa sireletsehang e tšoaretsoeng Akamai CDN eseng ho tsoa ho Intel Resource le Design Center. Seva e fumanoe ka tsietsi nakong ea skena ea batho ba bangata ba sebelisang nmap 'me e ile ea qhekelloa ka ts'ebeletso e tlokotsing.

Lingoliloeng tse ling li boletse ka monyetla oa ho fumanoa ha li-backdoors ho khoutu ea Intel, empa lipolelo tsena ha li na motheo ebile li thehiloe feela
boteng poleloana "Save the RAS backdoor request pointer to IOH SR 17" ka maikutlo ho e 'ngoe ea lifaele tsa khoutu. Boemong ba ACPI RAS e bolela "Botšepehi, Boteng, Bokhoni ba Tšebeletso". Khoutu ka boeona e sebetsana le ho lemoha le ho lokisa liphoso tsa mohopolo, ho boloka sephetho ho ngoliso ea 17 ea hub ea I / O, 'me ha e na "backdoor" ka kutloisiso ea ts'ireletso ea tlhahisoleseding.

Sehlopha se se se abuoe ho marang-rang a BitTorrent mme se fumaneha ka sehokelo sa makenete. Boholo ba polokelo ea zip bo ka ba 17 GB (notlolola li-password "Intel123" le "intel123").

Ho phaella moo, ho ka hlokomeloa hore qetellong ea July Tilly Kottmann e hatisitsoeng sebakeng sa sechaba dikahare libaka tsa polokelo tse fumanoeng ka lebaka la ho lutla ha data ho tsoa ho lik'hamphani tse ka bang 50. Lethathamo le na le lik'hamphani tse kang
Microsoft, Adobe, Johnson Controls, GE, AMD, Lenovo, Motorola, Qualcomm, Mediatek, Disney, Daimler, Roblox le Nintendo, hammoho le libanka tse fapa-fapaneng, litšebeletso tsa lichelete, lik'hamphani tsa likoloi le tsa maeto.
Mohloli o ka sehloohong oa ho lutla e ne e le tlhophiso e fosahetseng ea lisebelisoa tsa DevOps le ho siea linotlolo tsa phihlello libakeng tsa polokelo ea sechaba.
Bongata ba lipolokelo li kopitsoe ho tsoa lits'ebetsong tsa lehae tsa DevOps tse ipapisitseng le li-platform tsa SonarQube, GitLab le Jenkins, tseo phihlello ho tsona. e ne e se joalo e lekantsoe hantle (maemong a fumanehang webong a li-platform tsa DevOps li ne li sebelisoa litlhophiso tsa kamehla, tse bolelang monyetla oa phihlello ea sechaba mererong).

Ho phaella moo, mathoasong a July, ka lebaka leo tenyetseha Ts'ebeletso ea Waydev, e neng e sebelisoa ho hlahisa litlaleho tsa tlhahlobo mabapi le ts'ebetso ea polokelo ea Git, e ne e na le ho lutla ha database, ho kenyeletsoa le li-tokens tsa OAuth bakeng sa ho fihlella polokelong ea GitHub le GitLab. Li-tokens tse joalo li ka sebelisoa ho kopanya polokelo ea polokelo ea bareki ba Waydev. Li-tokens tse hapuoeng li ile tsa sebelisoa hamorao ho sekisetsa meaho dave.com и morwallo.io.

Source: opennet.ru

Eketsa ka tlhaloso