[html]
<a href="http://www.cs.vu.nl/~ast/intel/">http://www.cs.vu.nl/~ast/intel/</a>
<br />
<br />
<a href="https://www.networkworld.com/article/3236064/servers/minix-the-most-popular-os-in-the-world-thanks-to-intel.html">https://www.networkworld.com/article/3236064/servers/minix-the-most-popular-os-in-the-world-thanks-to-intel.html</a>
<br />
<a href="https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it">https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it</a>
<br />
<a href="https://mjg59.dreamwidth.org/48429.html">https://mjg59.dreamwidth.org/48429.html</a>
<br />
<a href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr">https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr</a>
<br />
<br />
Since 2008, most of Intel’s chipsets have contained a tiny homunculus computer called the “Management Engine” (ME).
<br />
Intel CPU On-chip Management Engine (there is presently no way to disable or limit the Management Engine in general)
<br />
1) an implementation of a TPM.
<br />
2) code to handle media DRM
<br />
3) Active Management (AMT) module in some Management Engines (AMT can be disabled, Ctrl-p during boot, access to AMT requires a password), provides:
<br />
a web UI that allows you to do things like reboot a machine
<br />
remote install media (AMT supports providing an ISO remotely, via emulated USB device)
<br />
(if the OS is configured appropriately) get a remote console. would be able to interact with your graphical console as if you were physically present.
<br />
<br />
any packets sent to the machine's wired network port on port 16992 or 16993 will be redirected to the ME and passed on to AMT (OS never sees these packets)
<br />
lspci should show a communication controller with "MEI" or "HECI" in the description
<br />
<br />
Я аж вспрыгнул смотреть спеку на свою материнку, но у меня в чипсете такой фичи не задокументировано, так что перепрошить не получится.
<br />
All of the code inside the ME is secret, signed, and tightly controlled by Intel.
[/html]
Отредактировано Лис (2017-11-08 08:13:53)