New Intel CPUs Can Be “Hacked” Using The USB Port And A Hardware Feature

IT | Jan 22, 2017 | Master3395

On Modern Intel CPUs, the USB 3.0 port can be used to access the hardware debugging interface JTAG via DCI. According to a research duo at Positive Security, the availability of DCI can pose as a major vulnerability allowing the attacker gain full control of the CPU without doing much. However, a security key is required to use DCI which is disabled by default.

Hardware debugging of stuff like kernel, drivers, hypervisors, etc. on Intel CPUs can be done using the JTAG (Joint Test Action Group) interface. Earlier, JTAG debugging interface could only be accessed using a unique device which had to be connected to the motherboard. 

In later versions, starting from Skylake and Kabylake processors, Intel simplified the connection process and introduced DCI (Direct Connect Interface) which allows JTAG access via the USB 3.0 port present on the machine. This is handy in the case of portable computers like laptops.

According to the Positive Security researchers, Maxim Goryachy and Mark Ermolov, the ability to access CPUs via the USB port can be dangerous. They note that the target computer could be tagged as vulnerable even if the DCI interface is just enabled, there are no software or hardware changes to be made. However, DCI is disabled by default on Intel CPUs. It can be enabled using the BIOS configuration, and a proprietary key is required to access JTAG.

The duo Goryachy and Ermolov demonstrated the vulnerability – at the Chaos Communication Congress (33C3) last year –  which can be used to gain full control of the Intel CPUs. They believe that CPU access mechanisms like this can take destructive USB devices, like Killer USB, to a whole new level.

Here is the demo video:

Keywords: intel, hack, usb, cpu, kabylake

Author: Master3395


comments powered by Disqus

Page 1 of 417  >  >>

All Chromium browsers now get better integration with Windows 10


Jul 20, 2019 | Category: General | Comments

"All" gets better thanks to new Microsoft Edge.

With its entry into the Chromium world, Microsoft has been a great provider to the browser platform we are well acquainted with, including Google Chrome. The latest news means that all Chromium-based browsers are now getting closer to Windows 10.

read more…

Do you have such a wireless USB receiver? Then you need to update now


Jul 19, 2019 | Category: IT | Comments

You can be hacked through your Logitech product.

When you buy a wireless keyboard or a wireless mouse from Logitech, you are welcome to use a wireless USB receiver.

read more…

Microsoft is blocking the May 10 update of Windows 10 for owners of this computer


Jul 18, 2019 | Category: Microsoft | Comments

Error with the graphics card.

Surface Book 2 will not be able to install the May update (1903) at this time.

read more…

Page 1 of 417  >  >>