Tuesday, July 5, 2016
System Management Mode (SMM) BIOS Vulnerability
Lenovo Security Advisory: LEN-8324
Potential Impact: Execution of code in SMM by an attacker with local administrative access
Severity: High
Scope of Impact: Industry-wide
Lenovo’s Product Security Incident Response Team (PSIRT) is fully aware of the uncoordinated disclosure by an independent researcher of a BIOS vulnerability located in the System Management Mode (SMM) code that impacts certain Lenovo PC devices. Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information.
Since that time, Lenovo has actively undertaken its own investigation, which remains ongoing. At this point, Lenovo knows that vulnerable SMM code was provided to Lenovo by at least one of our Independent BIOS Vendors (IBVs). Independent BIOS vendors (IBVs) are software development firms that specialize in developing the customized BIOS firmware that is loaded into the PCs of original equipment manufacturers, including Lenovo. Following industry standard practice, IBVs start with the common code base created by chip vendors, such as Intel or AMD, and add additional layers of code that are specifically designed to work with a particular computer. Lenovo currently works with the industry’s three largest IBVs.
The package of code with the SMM vulnerability was developed on top of a common code base provided to the IBV by Intel. Importantly, because Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose. But, as part of the ongoing investigation, Lenovo is engaging all of its IBVs as well as Intel to identify or rule out any additional instances of the vulnerability's presence in the BIOS provided to Lenovo by other IBVs, as well as the original purpose of the vulnerable code.
Lenovo is committed to the security of its products and is working with its IBVs and Intel to develop a fix that eliminates this vulnerability as rapidly as possible. Additional information regarding the fix will be posted as soon as it is available on the Product Security Advisory web site: https://support.lenovo.com/us/en/product_security/home
- wong chee tat :)
Saturday, September 28, 2013
Dell BIOS in some Latitude laptops and Precision Mobile Workstations vulnerable to buffer overflow
Dell BIOS in some Latitude laptops and Precision Mobile Workstations vulnerable to buffer overflow
Overview
Dell BIOS in some older Latitude laptops and Precision Mobile Workstations are vulnerable to buffer overflows (CWE-119), which can bypass the signed BIOS enforcement standard.Description
| CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer Dell BIOS in some older Latitude laptops and Precision Mobile Workstations is vulnerable to buffer overflows in the rbu_packet.pktNum and rbu_packet.pktSize values. These values can be set by an attacker while performing an illegitimate BIOS update. The BIOS reads these values when reconstructing the BIOS image, before any signature check occurs. More information is available from the BIOS Security presentation at Black Hat USA 2013. |
Impact
| By convincing a user with root or administrative privileges to execute a malicious BIOS update, an attacker can bypass the signed BIOS enforcement to install an arbitrary BIOS image that could contain a rootkit or malicious code that persists across operating system re-installations and official BIOS updates. |
Solution
| Apply an Update Dell has released updated BIOS versions for the affected Latitude and Precision systems that can be downloaded from their support site. Dell has provided the following list of fixed BIOS versions: Dell System Released Rev =================================================== Latitude D530 8/22/2013 A12 Latitude D531 7/16/2013 A12 Latitude D630 7/16/2013 A19 Latitude D631 7/26/2013 A12 Latitude D830 7/16/2013 A17 Precision M2300 7/16/2013 A11 Precision M4300 7/16/2013 A17 Precision M6300 7/16/2013 A15 Latitude E5400 7/16/2013 A19 Latitude E5500 7/16/2013 A19 Latitude E4200 7/16/2013 A24 Latitude E4300 7/16/2013 A26 Latitude E6400 7/16/2013 A34 Latitude E6400 ATG 7/16/2013 A34 Latitude E6400 / ATG / XFR 7/16/2013 A34 Latitude XT2 7/18/2013 A15 Latitude E6500 7/16/2013 A29 Latitude Z600 7/16/2013 A11 Precision M2400 7/16/2013 A28 Precision M4400 7/16/2013 A29 Precision M6400 7/16/2013 A13 Precision M6500 7/18/2013 A10 |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Dell Computer Corporation, Inc. | Affected | 11 Jul 2013 | 22 Aug 2013 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 6.2 | AV:L/AC:H/Au:N/C:C/I:C/A:C |
| Temporal | 4.9 | E:POC/RL:OF/RC:C |
| Environmental | 3.7 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://www.blackhat.com/us-13/archives.html#Butterworth
- http://www.mitre.org/work/cybersecurity/blog/cyber_tools_butterworth.html
- http://support.dell.com/
Credit
Thanks to Corey Kallenberg, John Butterworth, and Xeno Kovah of the MITRE Corporation for reporting this vulnerability. Thanks also to Rick Martinez from Dell.This document was written by Adam Rauf.
Other Information
- CVE IDs: CVE-2013-3582
- Date Public: 15 Aug 2013
- Date First Published: 15 Aug 2013
- Date Last Updated: 22 Aug 2013
- Document Revision: 54
- wong chee tat :)
Monday, May 13, 2013
Shane Todd's laptop showed access to suicide, depression-related websites
By Kimberly Spykerman
POSTED: 13 May 2013 9:58 PM
SINGAPORE: Internet history on American researcher Shane Todd's laptop showed that he had run searches on suicide and depression-related websites in the days before he died. This was revealed on the first day of a coroner's inquiry into his death.
Dr Todd's body was found hanging from a black strap in front of a closed toilet door in his bedroom. According to the police, the strap had a plastic buckle attached to it which acted as a stopper -- securing it against the top end of the toilet door.
Internet history on his laptop revealed that he had accessed suicide-related websites 19 times between March and June 2012. The last one was accessed only the day before his body was found hanged in his apartment.
According to patterns of Internet activity, Dr Todd had searched different methods of committing suicide. Depression-related webpages were also accessed -- mostly in May 2012.
Senior State Counsel Tai Wei Shyong gave these details in an opening statement to the court.
Dr Todd's parents, who have flown here for the inquiry, believe their son was murdered over research he had done while working for the Singapore Institute of Microelectronics.
However, there were notes, believed to be written by Dr Todd, found on his laptop. The notes were found after the investigation officer accessed his laptop using a password written on a post-it pad.
They were for his family, girlfriend, and friends. He said he loved them and asked their forgiveness for the pain he caused them.
Dr Todd's girlfriend and friends took the stand on Monday to describe his state of mind in the months before he died. Calling him a perfectionist, they said he was unhappy and stressed about his work. They also said he had lost weight and a twitching in his hands had become more pronounced in the months leading up to his death.
Dr Todd's girlfriend Shirley Sarmiento said he told her he had suffered from depression since October 2011. He also told her he was unhappy after transferring to another department, and working on a project that he felt could get him into trouble with the American government.
The court heard earlier that Dr Todd had seen a psychiatrist while in Singapore and been prescribed anti-depressant pills.
Officers and paramedics who were first at the scene said there were no signs of forced entry or foul play when they entered Dr Todd's apartment.
However, the counsel for the Todd family questioned if it was right for them to cut the rope holding up Dr Todd's body before the forensics team arrived, saying that that could have changed material evidence at the scene.
The court however heard that it was standard procedure to bring down a body found hanging as the priority was to "save lives". The first-responders also said they remembered seeing Dr Todd's feet on the floor when they entered the room, but could not be sure if his legs were bearing his weight.
The Todd family also said they appreciated the help they had received for the inquiry.
Rick Todd, the father of Dr Todd, said: "We really appreciate the process going on here. It's a slow process so we really appreciate the way Singapore conducts its court system."
Earlier, he and his wife thanked the Singapore government for allowing them to be part of the inquest.
The inquiry continues.
- CNA/ac
- wong chee tat :)
Tuesday, November 9, 2010
Male Reproductive system highly affected due to the usage of laptop
Male Reproductive system highly affected due to the usage of laptop
According to the urologist, Yelim Sheynkin of State University of New York at Stony Brook, the recent survey conducted and study carried out in fertility and sterility showed that the reproductive system of male gets affected due to the usage of laptop. Only solution they have come across is using laptop on the desk.
The study was carried out, with the help of thermometers which was used to measure the temperature of the scrotums of about 29 youngsters, by poising a laptop on their knees. Even with the usage of a pad for the laptop, the scrotum of men was heated up promptly.
Sheynkin, the urologist says that almost every one out of six couples in America suffers from the problems of conceiving. Most of the problem raised due to infertility that has affected the male members, as millions of people in the reproductive age are using laptops, the scrotal temperature of them increases and according to research it will take only 10-15 minutes for such a step-up.
The known fact is that, under normal conditions the testicles are kept outside the human body, in order to keep them cooler than inside, which is required for the production of sperm.
Though studies have found that laptops affect the fertility of a male, there is no substantial evidence as to how it will affect, Sheynkin said. But researches have proved that heating the scrotal sac even for more than a degree Celsius is sufficient to destroy the sperm.
Other factors like usage of drug as well as nutrition may affect the reproductive system, though dresses like tight jeans and briefs are not supposed to affect the testicles as people are freely moving around with it, which reduces the risk.
The researchers have found that the temperature of the testicles even goes up to 2.5C, when men keep the laptop with their legs closed without any movement.
The usage of lap pad may keep the testicles much cooler, but you cannot fully avoid the heat transferred to the skin. Though using laptop for sometime doesn’t cause much damage and only frequent usage might impart to the problems, as the time for the scrotum to get cooled becomes less.
Finding a solution to the above problem, men can sit with their legs wide apart by keeping the computer on a lap pad to make scrotum much cooler, but still it will take less than half an hour time prior to overheating.
However, even after keeping the legs wide apart, there is a good chance for the temperature to rise, according to Sheynkin.
Read more: Male Reproductive system highly affected due to the usage of laptop | Tech Know Bits http://techknowbits.com/645/male-reproductive-system-highly-affected-due-to-the-usage-of-laptop#ixzz14n8sHLeD
Friday, June 19, 2009
Laptops Linked To Male Infertility
ScienceDaily (June 13, 2009) — While fatherhood might be far from the minds of most young men, behavior patterns they establish early on may impact their ability to become a dad later in life. Excessive laptop use tops this list of liabilities, according to one reproductive specialist at Loyola University Health System (LUHS).
"Laptops are becoming increasingly common among young men wired into to the latest technology," said Suzanne Kavic, MD, director of the division of reproductive endocrinology at LUHS and associate professor in the department of obstetrics and gynecology and department of medicine at Loyola University Chicago Stritch School of Medicine. "However, the heat generated from laptops can impact sperm production and development making it difficult to conceive down the road."
Kavic recommends placing laptops on desktops to prevent damaging sperm and decreasing counts and motility. Other tips to protect male fertility include:
- Avoiding hot tubs
- Wearing boxers instead of briefs
- Refraining from ejaculating too frequently (the recommendation is to only engage in sexual intercourse every other day around ovulation)
- Exercising moderately (one hour, three to five times per week)
- Avoiding exercise that can generate heat or trauma to the genital area
- Eating well
- Taking a daily multivitamin
- Getting eight hours of sleep per night
- Staying hydrated and limiting caffeine to no more than two cups per day
- Refraining from smoking
- Avoiding drugs and excessive alcohol use
- Minimizing exposure to toxins
- Avoiding excessive weight gain or weight loss
- Practicing stress reduction techniques
Forty percent of fertility issues are attributed to males. Other leading causes of male infertility include varicocoeles or enlarged varicose veins in the scrotum. This condition can raise the temperature in the testicles and damage or kill sperm. Other reasons include genital injuries or defects, certain sexually transmitted infections, prostatitis (an infection or inflammation of the prostate), immune and hormonal disorders and erectile dysfunction. Kavic also notes that underlying health issues and medications may be to blame for fertility issues.
"Medications for depression, blood pressure and certain heart conditions may lower libido or cause impotence," said Kavic. "Men should talk with their physicians to see if medication is necessary or if they can switch to another with fewer side effects."
Reproductive endocrinology services available for males at LUHS include consultations, medical history and physical examinations, semen analysis, intrauterine inseminations by husband donor, assessments for the need for assisted reproductive technology and referrals to support services and alternative medicine.
"With Father's Day around the corner, males should be reminded to take care of their health," said Kavic. "An annual physical exam combined with a healthy lifestyle may make it easier to become a dad when the time is right.- wong chee tat :)
Saturday, March 28, 2009
Fix Corrupted Computer Profile in Vista
Vista Woes?
Just yesterday or so, a fren, A, came and asked for help as she had some problem with her Vista (Business) laptop. She was unable to access her administrator profile but able to access the guest account.
She then showed us (me and Y) the message which is somewhat similar to user profile unable to load.
Y suggested that to boot into the safe mode using F8 and worked it from there. So we boot the lappy into safe mode, and we go straight to the event log. The event log basically logged whatever problems (especially error) that Vista encountered. From there we could get a glimpse of what actually happened in the process and why she was unable to load her administrator profile.
Investigation!
A quick googling around, one of the fixes is to edit the registry settings without reformatting:
In short, you go to regedit (Start --> Run --> "regedit") and edit from there:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
Surprised???
When we delved into the profile list in the registry, I was in for a little surprised!
In her computer profiles, there are a couple of profiles with different SIDs! Three of them are from the system.1 is her original administrator account, 1 guest account and another don’t know what account. Okay, this seems to be confusing! But it wasn't.
Let us analyzed below:
Her original administrator account has been renamed with a .bak extension and her guest account has been "promoted" to the administrator status. Well, the last three digits of the SID ended with 5xx. That seemed impossible right? The administrator account is therefore is visible (to us) but Vista will not allow you to load when the account is selected.
Okay, what's next?
Most important thing is that did she backup her data? If she did, then it would be easier to fix the system. Y asked her if she had any thumb drive or portable hard disk with her. She did not had and a while, she came back with her portable hard disk, and a simple transfer of files are done and it was time to "hack" or "fix" her system via registry modification as mentioned earlier. (Evil grin... hehe)
Fix it
Unrename the .bak and allow the administrator account to be reinstated
Oh, btw, you will not be allowed to change the ".bak" extension to original (no .bak attached at the end) if your SID of both original account and other account are the same. Just see and compared the SIDs(numbers)!
If you goggled around, there are other fixes:
"There was 1 line for each profile. Crucially if a profile is bad there are 3 things worth checking
a) Ensure the key name doesn't end in ".bad"
b) Ensure the RefCount value is 0
c) Ensure the State value is 0"
Test it!
A simple renaming is done and rebooted the system. The laptop screen loaded and she selected the administrator account and she is able to load her original administrator account successfully! (Yay!)
-Special Thanks to Y for info and her help!
- wong chee tat :)