Kuputshuzwe u-20GB wemibhalo yezobuchwepheshe yangaphakathi namakhodi omthombo we-Intel

Tilly Kottmann (UTillie Kottmann), umthuthukisi wenkundla ye-Android evela eSwitzerland, ohola isiteshi seTelegramu mayelana nokuvuza kwedatha, eshicilelwe U-20 GB wemibhalo yezobuchwepheshe yangaphakathi kanye nekhodi yomthombo etholwe ngenxa yokuvuza okukhulu kolwazi oluvela ku-Intel kutholakala esidlangalaleni. Lokhu kuthiwa kuyisethi yokuqala eqoqweni elinikelwe umthombo ongaziwa. Amadokhumenti amaningi amakwa njengayimfihlo, eyimfihlo yenkampani, noma asatshalaliswa ngaphansi kwesivumelwano sokungadaluli.

Imibhalo yakamuva ibhalwe ngasekuqaleni kukaMeyi futhi ihlanganisa ulwazi mayelana nenkundla yeseva entsha yeCedar Island (Whitley). Kukhona futhi imibhalo evela ku-2019, isibonelo echaza inkundla ye-Tiger Lake, kodwa ulwazi oluningi lwango-2014. Ngaphezu kwemibhalo, isethi iqukethe ikhodi, amathuluzi okulungisa iphutha, imidwebo, abashayeli, namavidiyo okuqeqesha.

Abanye ulwazi kusukela kusethi:

  • I-Intel ME (Injini Yokuphatha), izinsiza ze-flash nezibonelo zamapulatifomu ahlukene.
  • Ukuqaliswa kwe-BIOS eyinkomba yesikhulumi se-Kabylake (Purley), izibonelo nekhodi yokuqalisa (ngomlando woshintsho olusuka ku-git).
  • Imibhalo engumthombo ye-Intel CEFDK (Ikhithi Yokuthuthukisa I-Firmware Yabathengi).
  • Ikhodi yamaphakheji e-FSP (Iphakheji Yokusekela I-Firmware) kanye nezikimu zokukhiqiza zamapulatifomu ahlukahlukene.
  • Izinsiza ezahlukahlukene zokulungisa iphutha nokuthuthukisa.
  • Izifaniso-simulator yesikhulumi se-Rocket Lake S.
  • Izinhlelo namadokhumenti ahlukahlukene.
  • Abashayeli kanambambili bekhamera ye-Intel eyenzelwe i-SpaceX.
  • I-Schematics, imibhalo, i-firmware kanye namathuluzi weplathifomu ye-Tiger Lake engakakhululwa.
  • Kabylake FDK amavidiyo wokuqeqesha.
  • I-Intel Trace Hub namafayela anama-decoder ezinguqulo ezihlukene ze-Intel ME.
  • Ukuqaliswa okuyisethenjwa kweplathifomu ye-Elkhart Lake nezibonelo zekhodi ukusekela inkundla.
  • Izincazelo zamabhulokhi wehadiwe ngolimi lwe-Verilog zamapulatifomu e-Xeon ahlukene.
  • I-Debug BIOS/TXE yakhela amapulatifomu ahlukene.
  • I-Bootguard SDK.
  • Inqubo yokulingisa i-Intel Snowridge ne-Snowfish.
  • Izikimu ezihlukahlukene.
  • Izifanekiso zezinto zokuthengisa.

I-Intel ithe isivule uphenyo ngalesi sigameko. Ngokusho kolwazi lokuqala, idatha itholwe ngohlelo lolwazi "I-Intel Resource kanye ne-Design Center", equkethe ulwazi olulinganiselwe lokufinyelela kumakhasimende, ozakwethu nezinye izinkampani i-Intel esebenzisana nazo. Ngokunokwenzeka, ulwazi lwalayishwa futhi lwanyatheliswa othile okwazi ukufinyelela lolu hlelo lolwazi. Omunye wabasebenzi bangaphambili be-Intel kuveziwe ngenkathi exoxa ngenguqulo yakhe ku-Reddit, okubonisa ukuthi ukuvuza kungase kube umphumela wokucekelwa phansi yisisebenzi noma ukugetshengwa komunye wabakhiqizi bebhodi le-OEM.

Umuntu ongaziwa othumele amadokhumenti ukuze ashicilelwe wakhombaukuthi idatha ilandwe kusuka kuseva engavikelekile esingethwe ku-Akamai CDN hhayi ku-Intel Resource and Design Center. Iseva itholwe ngengozi ngesikhathi sokuskena okukhulu kwabasingathi kusetshenziswa i-nmap futhi yagqekezwa ngesevisi esengozini.

Okunye okushicilelwe kushilo ukutholakala okungenzeka kwama-backdoors kukhodi ye-Intel, kodwa lezi zitatimende azinasisekelo futhi zisekelwe kuphela
ubukhona inkulumo ethi "Londoloza isikhombi sesicelo sangemuva se-RAS ku-IOH SR 17" emazwaneni kwelinye lamafayela ekhodi. Kumongo we-ACPI RAS kusho "Ukuthembeka, Ukutholakala, Ukusebenza". Ikhodi ngokwayo icubungula ukutholwa nokulungiswa kwamaphutha enkumbulo, igcina umphumela kurejista 17 yehabhu le-I/O, futhi ayiqukethe β€œumnyango ongemuva” ngomqondo wokuphepha kolwazi.

Isethi isivele isabalalisiwe kuwo wonke amanethiwekhi e-BitTorrent futhi itholakala nge isixhumanisi sikazibuthe. Usayizi wengobo yomlando ye-zip cishe u-17 GB (vula amaphasiwedi "Intel123" kanye "ne-intel123").

Ukwengeza, kungaphawulwa ukuthi ekupheleni kukaJulayi uTilly Kottmann eshicilelwe endaweni yomphakathi okuqukethwe amakhosombe atholwe ngenxa yokuvuza kwedatha ezinkampanini ezingaba ngu-50. Uhlu luqukethe izinkampani ezifana
I-Microsoft, i-Adobe, i-Johnson Controls, i-GE, i-AMD, i-Lenovo, i-Motorola, i-Qualcomm, i-Mediatek, i-Disney, i-Daimler, i-Roblox ne-Nintendo, kanye namabhange ahlukahlukene, izinsizakalo zezezimali, izinkampani zezimoto nezokuvakasha.
Umthombo oyinhloko wokuvuza bekuwukulungiselela okungalungile kwengqalasizinda ye-DevOps nokushiya okhiye bokufinyelela kumakhosombe omphakathi.
Iningi lamakhosombe likopishwe ezinhlelweni zasendaweni ze-DevOps ngokusekelwe ku-SonarQube, GitLab kanye ne-Jenkins platform, ukufinyelela kuzo. wayengekho kukhawulelwe ngokufanelekile (ezimweni zasendaweni ezifinyeleleka kuwebhu zamapulatifomu e-DevOps zasetshenziswa izilungiselelo ezizenzakalelayo, okusho ukuthi kungenzeka ukufinyelela komphakathi kumaphrojekthi).

Ngaphezu kwalokho, ekuqaleni kukaJulayi, ngenxa yalokho ukuyekethisa Isevisi ye-Waydev, esetshenziselwa ukukhiqiza imibiko yokuhlaziya yomsebenzi kumakhosombe e-Git, ibe nokuvuza kwesizindalwazi, okuhlanganisa naleyo ehlanganisa amathokheni e-OAuth okufinyelela amakhosombe ku-GitHub naku-GitLab. Amathokheni anjalo angasetshenziselwa ukuhlanganisa amakhosombe angasese amaklayenti e-Waydev. Amathokheni athathiwe abe esesetshenziselwa ukubeka engcupheni ingqalasizinda dave.com ΠΈ isikhukhula.io.

Source: opennet.ru

Engeza amazwana