
Strumento di verifica delle vulnerabilità TPM per CVE-2018-6622. Questo strumento sarà pubblicato al Black Hat Asia 2019 e al Black Hat Europe 2019.
,----------------, ,---------,
,-----------------------, ," ,"|
," Napper v1.3 for TPM ," | ," ," |
+-----------------------+ | ," ," |
| .-----------------Z | | +---------+ |
| | Z | | | | -==----'| |
| | ︶ ︶ z | | | | | |
| | - | | |/----| ==== oo | |
| | | | | ,/| (((( | ,"
| `-----------------' |," .;'/ | (((( | ,"
+-----------------------+ ;; | | |,"
/_)______________(_/ //' | +---------+
___________________________/___ `,
/ oooooooooooooooo .o. oooo / \,"---------
/ ==ooooooooooooooo==.o. ooo= / ,`\--{-D) ,"
`-----------------------------' '----------"
Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
Project link: https://github.com/kkamagui/napper-for-tpm
Please contribute your summary report to the Napper project!
"Napper" è un nuovo strumento di verifica delle vulnerabilità per il TPM discreto e il firmware TPM (Intel PTT). CVE-2018-6622 e una CVE sconosciuta sono correlate allo stato di sospensione S3 o alla sospensione dell'Advanced Configuration and Power Interface (ACPI). L'attaccante può sovvertire il TPM con la sospensione S3, e le funzionalità di attestazione remota e sigillo/scongelamento che utilizzano i Platform Configuration Registers (PCR) possono essere neutralizzate. Se desideri informazioni dettagliate su CVE-2018-6622 e sulla CVE sconosciuta, leggi il nostro articolo USENIX, A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping e la presentazione Black Hat Europe 2019 BitLeaker: Subverting BitLocker with One Vulnerability.
Napper e CVE-2018-6622 sono stati presentati nelle conferenze di sicurezza di seguito.
Una CVE sconosciuta relativa a Intel Platform Trust Technology (PTT) è stata presentata nelle conferenze di sicurezza di seguito.
Puoi guardare il video dimostrativo qui sotto.
Accogliamo sempre con favore i tuoi contributi. Il report di riepilogo di Napper che contribuisci renderà il mondo più sicuro.
Napper ha licenza GPL v2.
Trusted Platform Module (TPM) è un dispositivo resistente alle manomissioni progettato per fornire funzioni di sicurezza basate su hardware o firmware. Un chip TPM ha un generatore di numeri casuali, memoria non volatile, moduli di crittografia/decifratura e Platform Configuration Registers (PCR), che possono essere utilizzati per varie applicazioni di sicurezza come BitLocker, DM-Crypt, Trusted Boot (tboot) e Open Cloud Integrity Technology (Open CIT).
Il TPM è stato ampiamente distribuito nei dispositivi commerciali per fornire una solida base per la costruzione di piattaforme affidabili, specialmente nei dispositivi utilizzati nei sistemi aziendali e governativi. Poiché il TPM è il punto critico nella piattaforma affidabile, molti ricercatori hanno cercato di trovare vulnerabilità nel TPM e hanno concluso che è difficile violarlo senza accesso fisico. Tuttavia, questo non è più vero.
Le vulnerabilità che abbiamo trovato possono sovvertire il TPM con Advanced Configuration and Power Interface (ACPI). L'ACPI in PC, laptop e server fornisce sei stati di sospensione (S0-S5) per ridurre il consumo energetico. Quando il sistema entra nello stato di sospensione, CPU, dispositivi e RAM vengono spenti. Poiché il sistema spegne i componenti inclusi i dispositivi di sicurezza, dovrebbe reinizializzarli durante il risveglio e questo potrebbe rappresentare la superficie d'attacco. Abbiamo trovato vulnerabilità su questa superficie d'attacco senza accesso fisico.
Per mitigare le vulnerabilità, presentiamo anche contromisure e un nuovo strumento, "Napper", per verificare le vulnerabilità del TPM. Napper è un dispositivo USB avviabile basato su Linux, e contiene un modulo kernel e un software di verifica delle vulnerabilità. Quando avvii un sistema con Napper, fa fare un pisolino al tuo sistema per verificare le vulnerabilità e riferirti il risultato.
Napper è composto da un modulo kernel speciale e strumenti tpm2 personalizzati. Napper è basato su Ubuntu 18.04, e lo abbiamo personalizzato e adattato per creare un'immagine Live CD. Se vuoi solo verificare la vulnerabilità TPM e trovare un modo semplice per farlo, passa alla Sezione 3.1 e usa l'immagine Napper Live CD con la tua memoria USB. Napper Live CD contiene non solo uno strumento binario ma anche il codice sorgente completo di Napper. Se stai usando Ubuntu 18.04 ora e vuoi costruire Napper da zero, passa alla Sezione 3.2 e costruiscilo.
Le immagini Napper Live CD sono nella pagina delle release del progetto Napper.
Se stai usando il sistema operativo Microsoft Windows, usa Win32 Disk Imager e scrivi l'immagine Napper Live CD sulla tua memoria USB.
Se stai usando Linux o Mac OS X, usa un comando dd qui sotto.```
$> sudo dd if=Napper-LiveCD.iso of=/dev/sdX bs=4096 $> sync
### 3.1.3. Riavvia il sistema con la tua memoria USB ed esegui Napper
Se colleghi la tua memoria USB e modifichi la sequenza di avvio per avviare da essa, puoi vedere il menu di avvio di Napper qui sotto e avviare il Live CD di Napper selezionando la prima opzione.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/525cb00d8f948ccc1653bd4fd08c8baf293615ad80ec52082b6c04efe7484f57.png" alt="napper_boot_menu"/> </center>
Dopo la sequenza di avvio, puoi vedere il file README.txt sul desktop e l'icona dello strumento Napper sulla barra delle applicazioni a sinistra. Per controllare il tuo sistema, fai clic sull'icona superiore della barra delle applicazioni e digita `napper` come password. L'`ID` e la `password` dello strumento Napper sono impostati su `napper`. Mentre Napper testa il tuo sistema, metterà il sistema in sospensione e lo riattiverà. Pertanto, devi premere un tasto sulla tastiera per riattivare il sistema dallo stato di sospensione ACPI S3.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/50fdb76d396e32fe811b7f9e23849fd4b66fccee5c4325b5f8c4f167938c51b2.png" alt="napper_run"/> </center>
Se il tuo sistema ha una vulnerabilità TPM, Napper riporterà un riepilogo che indica che il tuo sistema è vulnerabile qui sotto. In tal caso, passa alla Sezione 4 e condividi il riepilogo con il nostro progetto, Napper, tramite [Segnalazione di problemi del progetto Napper](https://github.com/kkamagui/napper-for-tpm/issues) o [Sito web](https://kkamagui.github.io/).
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/37d28f91902c745a21bd3be9c8f373394694127db5037cc4fb522e1e660c0e65.png" alt="napper_summary"/> </center>
## 3.2. Costruisci Napper da zero con Ubuntu 18.04 (Versione Lunga)
### 3.2.1. Scarica Ubuntu 18.04 e clona il codice sorgente di Napper
Napper è basato su Ubuntu 18.04. Pertanto, lo scarichi dal [Sito ufficiale di Ubuntu](https://www.ubuntu.com/download/desktop) e lo installi sul tuo sistema di destinazione. Successivamente, cloni il codice sorgente di Napper dal [sito del progetto Napper, https://www.github.com/kkamagui/napper-for-tpm](https://www.github.com/kkamagui/napper-for-tpm) e lo costruisci con i comandi seguenti.```
# Clone Napper source code from project site.
$> git clone https://github.com/kkamagui/napper-for-tpm.git
# Build Napper.
$> cd napper-for-tpm
$> ./bootstrap
Dopo aver compilato il codice sorgente, puoi eseguire uno strumento Napper con un terminale. Digita il comando seguente nel tuo terminale. Il front-end di Napper è realizzato con script Python.```
$> sudo ./napper.py
,----------------, ,---------,
,-----------------------, ," ,"|
," Napper v 1.3 for TPM ,"| ," ," |
+-----------------------+ | ," ," |
| .-----------------Z | | +---------+ |
| | Z | | | | -==----'| |
| | ︶ ︶ z | | | | | |
| | - | | |/----| ==== oo | |
| | | | | ,/| (((( | ,"
| -----------------' |," .;'/ | (((( | ," +-----------------------+ ;; | | |," /_)______________(_/ //' | +---------+ ___________________________/___ ,
/ oooooooooooooooo .o. oooo / ,"---------
/ ==ooooooooooooooo==.o. ooo= / ,\--{-D) ," -----------------------------' '----------"
Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE Made by Seunghun Han, https://kkamagui.github.io Project link: https://github.com/kkamagui/napper-for-tpm
Checking TPM version for testing. [] Checking TPM version... TPM v2.0. [] Your system has TPM v2.0, and vulnerability checking is needed.
Preparing for sleep. [] Checking the TPM vulnerability testing module... Starting. [] Ready to sleep! Please press "Enter" key. [*] After sleep, please press "Enter" key again to wake up.
[*] Waking up now. Please wait for a while. . . . . . . . . . .
... omitted ...
## 3.3. Esempio di test
Il risultato seguente è un esempio del modello NUC5i5MYHE. Il sistema ha una vecchia versione del BIOS e presenta CVE-2018-6622.```
[sudo] password for napper:
,----------------, ,---------,
,-----------------------, ," ,"|
," Napper v 1.3 for TPM ,"| ," ," |
+-----------------------+ | ," ," |
| .-----------------Z | | +---------+ |
| | Z | | | | -==----'| |
| | ︶ ︶ z | | | | | |
| | - | | |/----| ==== oo | |
| | | | | ,/| (((( | ,"
| `-----------------' |," .;'/ | (((( | ,"
+-----------------------+ ;; | | |,"
/_)______________(_/ //' | +---------+
___________________________/___ `,
/ oooooooooooooooo .o. oooo / \,"---------
/ ==ooooooooooooooo==.o. ooo= / ,`\--{-D) ,"
`-----------------------------' '----------"
Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
Made by Seunghun Han, https://kkamagui.github.io
Project link: https://github.com/kkamagui/napper-for-tpm
Checking TPM version for testing.
[*] Checking TPM version... TPM v2.0.
[*] Your system has TPM v2.0, and vulnerability checking is needed.
Preparing for sleep.
[*] Checking the TPM vulnerability testing module... Starting.
[*] Ready to sleep! Please press "Enter" key.
[*] After sleep, please press "Enter" key again to wake up.
[*] Waking up now. Please wait for a while. . . . . . . . . . .
[*] Checking the resource manager process... Starting.
[*] Reading PCR values of TPM and checking a vulnerability... Vulnerable.
[*] Show all PCR values:
Bank/Algorithm: TPM_ALG_SHA1(0x0004)
PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Bank/Algorithm: TPM_ALG_SHA256(0x000b)
PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[*] Extending 0xdeadbeef to all static PCRs.
[*] Show all PCR values:
Bank/Algorithm: TPM_ALG_SHA1(0x0004)
PCR_00: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_01: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_02: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_03: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_04: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_05: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_06: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_07: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_08: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_09: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_10: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_11: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_12: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_13: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_14: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_15: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_16: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
Bank/Algorithm: TPM_ALG_SHA256(0x000b)
PCR_00: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_01: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_02: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_03: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_04: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_05: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_06: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_07: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_08: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_09: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_10: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_11: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_12: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_13: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_14: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_15: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_16: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
Summary. Please contribute summary below to the Napper project, https://www.github.com/kkamagui/napper-for-tpm.
[*] Your TPM version is 2.0, and it is vulnerable.
Please download the latest BIOS firmware from the manufacturer's site and update it.
[*] TPM v2.0 information.
Manufacturer: IFX
Vendor strings: SLB9 665
Firmware Version: 00050028 0007B302
Revision: 116
Year: 2014
Day of year: 303
[*] System information.
Baseboard manufacturer: Intel Corporation
Baseboard product name: NUC5i5MYBE
Baseboard version: H47797-205
BIOS vendor: Intel Corporation
BIOS version: MYBDWi5v.86A.0026.2015.0820.1501
BIOS release date: 08/20/2015
System manufacturer:
System product name:
La causa principale di CVE-2018-6622 e del CVE sconosciuto è la gestione impropria di un caso anomalo di sospensione S3, ed è possibile rimuovere la vulnerabilità seguendo due opzioni.
Abbiamo preparato questa sezione per te. Non esitare a contattarci.
Aggiorneremo questo campo con i tuoi contributi. Stiamo testando diversi dispositivi che abbiamo e aggiorneremo presto il risultato.
| Model | Status | BIOS Vendor | BIOS Version | BIOS Release Date (MM/DD/YY) | TPM 2.0 Manufacturer | Vendor String | TPM Firmware Version |
|---|
| ASUS Q170M-C | Vulnerabile | American Megatrends Inc. | 4001 | 11/09/2018 | Infineon (IFX) | SLB9665 | 5.51.8.12800 |
| Dell Optiplex 7040 | Vulnerabile | Dell | 1.11.1 | 10/10/2018 | NTC | rls NPCT | 1.3.2.8 |
| Dell Optiplex 7050 | Vulnerabile | Dell | 1.11.0 | 11/01/2018 | NTC | rls NPCT | 1.3.2.8 |
| GIGABYTE H170-D3HP | Vulnerabile | American Megatrends Inc. | F20g | 03/09/2018 | Infineon (IFX) | SLB9665 | 5.61.10.57600 |
| GIGABYTE Q170M-MK | Vulnerabile | American Megatrends Inc. | F23 | 04/12/2018 | Infineon (IFX) | SLB9665 | 5.51.8.12802 |
| HP Spectre x360 | Vulnerabile | American Megatrends | F.24 | 01/07/2019 | Infineon (IFX) | SLB9665 | 5.62.12.13824 |
| Intel NUC5i5MYHE | Vulnerabile | Intel | MYBDWi5v.86A. 0049.2018. 1107.1046 | 11/07/2018 | Infineon (IFX) | SLB9665 | 5.40.7.45826 |
| Lenovo T480 (20L5A00TKR) | Sicuro | Lenovo | N24ET44W (1.19 ) | 11/07/2018 | Infineon (IFX) | SLB9670 | 7.63.14.6400 |
| Lenovo T580 | Sicuro | Lenovo | N27ET20W (1.06 ) | 01/22/2018 | STMicroelectronics | 73.4.17568.4452 | |
| Microsoft Surface Pro 4 | Sicuro | Microsoft Corporation | 108.2439.769 | 12/07/2018 | Infineon (IFX) | SLB9665 | 5.62.12.13826 |