Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
napper-for-tpm — Strumento di verifica delle vulnerabilità TPM per CVE-2018-6622. Questo strumento sarà pubblicato al Black Hat Asia 2019 e al Black Hat Europe 2019. | Kitploit
Strumenti/GitHubGitHub/kkamagui/napper-for-tpm
Sicurezza Sistemi EmbeddedAnalisi delle VulnerabilitàExploitPenetration TestingSicurezza HardwareAnalisi del Firmware
GitHubkkamagui/napper-for-tpm

napper-for-tpm

Strumento di verifica delle vulnerabilità TPM per CVE-2018-6622. Questo strumento sarà pubblicato al Black Hat Asia 2019 e al Black Hat Europe 2019.

Vedi Repository
1071934 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
root@kitploit:~
                     ,----------------,              ,---------,
                ,-----------------------,          ,"        ,"|
              ," Napper v1.3 for TPM ," |        ,"        ,"  |
             +-----------------------+  |      ,"        ,"    |
             |  .-----------------Z  |  |     +---------+      |
             |  |               Z |  |  |     | -==----'|      |
             |  |   ︶     ︶ z   |  |  |     |         |      |
             |  |       -         |  |  |/----| ==== oo |      |
             |  |                 |  |  |   ,/| ((((    |    ,"
             |  `-----------------'  |," .;'/ | ((((    |  ,"
             +-----------------------+  ;;  | |         |,"     
                /_)______________(_/  //'   | +---------+
           ___________________________/___  `,
          /  oooooooooooooooo  .o.  oooo /    \,"---------
         / ==ooooooooooooooo==.o.  ooo= /    ,`\--{-D)  ,"
         `-----------------------------'    '----------"

 Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
         Project link: https://github.com/kkamagui/napper-for-tpm 
        Please contribute your summary report to the Napper project!                    

1. Avviso

"Napper" è un nuovo strumento di verifica delle vulnerabilità per il TPM discreto e il firmware TPM (Intel PTT). CVE-2018-6622 e una CVE sconosciuta sono correlate allo stato di sospensione S3 o alla sospensione dell'Advanced Configuration and Power Interface (ACPI). L'attaccante può sovvertire il TPM con la sospensione S3, e le funzionalità di attestazione remota e sigillo/scongelamento che utilizzano i Platform Configuration Registers (PCR) possono essere neutralizzate. Se desideri informazioni dettagliate su CVE-2018-6622 e sulla CVE sconosciuta, leggi il nostro articolo USENIX, A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping e la presentazione Black Hat Europe 2019 BitLeaker: Subverting BitLocker with One Vulnerability.

1.1. Presentazione e articolo

Napper e CVE-2018-6622 sono stati presentati nelle conferenze di sicurezza di seguito.

  • Black Hat Asia 2019: Finally, I Can Sleep Tonight: Catching Sleep Mode Vulnerabilities of the TPM with the Napper
  • USENIX Security 2018: A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping

Una CVE sconosciuta relativa a Intel Platform Trust Technology (PTT) è stata presentata nelle conferenze di sicurezza di seguito.

  • BitLeaker: Subverting BitLocker with One Vulnerability

Puoi guardare il video dimostrativo qui sotto.

  • Napper v1.0 Demo

1.2. Contributi

Accogliamo sempre con favore i tuoi contributi. Il report di riepilogo di Napper che contribuisci renderà il mondo più sicuro.

1.3. Licenza

Napper ha licenza GPL v2.

2. Introduzione a Napper

Trusted Platform Module (TPM) è un dispositivo resistente alle manomissioni progettato per fornire funzioni di sicurezza basate su hardware o firmware. Un chip TPM ha un generatore di numeri casuali, memoria non volatile, moduli di crittografia/decifratura e Platform Configuration Registers (PCR), che possono essere utilizzati per varie applicazioni di sicurezza come BitLocker, DM-Crypt, Trusted Boot (tboot) e Open Cloud Integrity Technology (Open CIT).

Il TPM è stato ampiamente distribuito nei dispositivi commerciali per fornire una solida base per la costruzione di piattaforme affidabili, specialmente nei dispositivi utilizzati nei sistemi aziendali e governativi. Poiché il TPM è il punto critico nella piattaforma affidabile, molti ricercatori hanno cercato di trovare vulnerabilità nel TPM e hanno concluso che è difficile violarlo senza accesso fisico. Tuttavia, questo non è più vero.

Le vulnerabilità che abbiamo trovato possono sovvertire il TPM con Advanced Configuration and Power Interface (ACPI). L'ACPI in PC, laptop e server fornisce sei stati di sospensione (S0-S5) per ridurre il consumo energetico. Quando il sistema entra nello stato di sospensione, CPU, dispositivi e RAM vengono spenti. Poiché il sistema spegne i componenti inclusi i dispositivi di sicurezza, dovrebbe reinizializzarli durante il risveglio e questo potrebbe rappresentare la superficie d'attacco. Abbiamo trovato vulnerabilità su questa superficie d'attacco senza accesso fisico.

Per mitigare le vulnerabilità, presentiamo anche contromisure e un nuovo strumento, "Napper", per verificare le vulnerabilità del TPM. Napper è un dispositivo USB avviabile basato su Linux, e contiene un modulo kernel e un software di verifica delle vulnerabilità. Quando avvii un sistema con Napper, fa fare un pisolino al tuo sistema per verificare le vulnerabilità e riferirti il risultato.

3. Come usare lo strumento "Napper"

Napper è composto da un modulo kernel speciale e strumenti tpm2 personalizzati. Napper è basato su Ubuntu 18.04, e lo abbiamo personalizzato e adattato per creare un'immagine Live CD. Se vuoi solo verificare la vulnerabilità TPM e trovare un modo semplice per farlo, passa alla Sezione 3.1 e usa l'immagine Napper Live CD con la tua memoria USB. Napper Live CD contiene non solo uno strumento binario ma anche il codice sorgente completo di Napper. Se stai usando Ubuntu 18.04 ora e vuoi costruire Napper da zero, passa alla Sezione 3.2 e costruiscilo.

3.1. Usare la propria memoria USB con l'immagine Napper Live CD (versione breve)

3.1.1. Ottenere l'immagine Napper Live CD dal progetto Napper

Le immagini Napper Live CD sono nella pagina delle release del progetto Napper.

3.1.2. Scrivere l'immagine Napper Live CD sulla propria memoria USB

Se stai usando il sistema operativo Microsoft Windows, usa Win32 Disk Imager e scrivi l'immagine Napper Live CD sulla tua memoria USB.

Se stai usando Linux o Mac OS X, usa un comando dd qui sotto.```

Please change sdX to your USB storage name.

$> sudo dd if=Napper-LiveCD.iso of=/dev/sdX bs=4096 $> sync

root@kitploit:~
### 3.1.3. Riavvia il sistema con la tua memoria USB ed esegui Napper
Se colleghi la tua memoria USB e modifichi la sequenza di avvio per avviare da essa, puoi vedere il menu di avvio di Napper qui sotto e avviare il Live CD di Napper selezionando la prima opzione.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/525cb00d8f948ccc1653bd4fd08c8baf293615ad80ec52082b6c04efe7484f57.png" alt="napper_boot_menu"/> </center>

Dopo la sequenza di avvio, puoi vedere il file README.txt sul desktop e l'icona dello strumento Napper sulla barra delle applicazioni a sinistra. Per controllare il tuo sistema, fai clic sull'icona superiore della barra delle applicazioni e digita `napper` come password. L'`ID` e la `password` dello strumento Napper sono impostati su `napper`. Mentre Napper testa il tuo sistema, metterà il sistema in sospensione e lo riattiverà. Pertanto, devi premere un tasto sulla tastiera per riattivare il sistema dallo stato di sospensione ACPI S3.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/50fdb76d396e32fe811b7f9e23849fd4b66fccee5c4325b5f8c4f167938c51b2.png" alt="napper_run"/> </center>

Se il tuo sistema ha una vulnerabilità TPM, Napper riporterà un riepilogo che indica che il tuo sistema è vulnerabile qui sotto. In tal caso, passa alla Sezione 4 e condividi il riepilogo con il nostro progetto, Napper, tramite [Segnalazione di problemi del progetto Napper](https://github.com/kkamagui/napper-for-tpm/issues) o [Sito web](https://kkamagui.github.io/).
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/37d28f91902c745a21bd3be9c8f373394694127db5037cc4fb522e1e660c0e65.png" alt="napper_summary"/> </center>

## 3.2. Costruisci Napper da zero con Ubuntu 18.04 (Versione Lunga)
### 3.2.1. Scarica Ubuntu 18.04 e clona il codice sorgente di Napper
Napper è basato su Ubuntu 18.04. Pertanto, lo scarichi dal [Sito ufficiale di Ubuntu](https://www.ubuntu.com/download/desktop) e lo installi sul tuo sistema di destinazione. Successivamente, cloni il codice sorgente di Napper dal [sito del progetto Napper, https://www.github.com/kkamagui/napper-for-tpm](https://www.github.com/kkamagui/napper-for-tpm) e lo costruisci con i comandi seguenti.```
# Clone Napper source code from project site.
$> git clone https://github.com/kkamagui/napper-for-tpm.git

# Build Napper.
$> cd napper-for-tpm
$> ./bootstrap

3.2.2. Esegui Napper con un terminale

Dopo aver compilato il codice sorgente, puoi eseguire uno strumento Napper con un terminale. Digita il comando seguente nel tuo terminale. Il front-end di Napper è realizzato con script Python.```

Run Napper

$> sudo ./napper.py ,----------------, ,---------, ,-----------------------, ," ,"| ," Napper v 1.3 for TPM ,"| ," ," | +-----------------------+ | ," ," | | .-----------------Z | | +---------+ | | | Z | | | | -==----'| | | | ︶ ︶ z | | | | | | | | - | | |/----| ==== oo | | | | | | | ,/| (((( | ," | -----------------' |," .;'/ | (((( | ," +-----------------------+ ;; | | |," /_)______________(_/ //' | +---------+ ___________________________/___ , / oooooooooooooooo .o. oooo / ,"--------- / ==ooooooooooooooo==.o. ooo= / ,\--{-D) ," -----------------------------' '----------"

Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE Made by Seunghun Han, https://kkamagui.github.io Project link: https://github.com/kkamagui/napper-for-tpm

Checking TPM version for testing. [] Checking TPM version... TPM v2.0. [] Your system has TPM v2.0, and vulnerability checking is needed.

Preparing for sleep. [] Checking the TPM vulnerability testing module... Starting. [] Ready to sleep! Please press "Enter" key. [*] After sleep, please press "Enter" key again to wake up.

root@kitploit:~
[*] Waking up now. Please wait for a while. . . . . . . . . . .     

... omitted ...
root@kitploit:~
## 3.3. Esempio di test
Il risultato seguente è un esempio del modello NUC5i5MYHE. Il sistema ha una vecchia versione del BIOS e presenta CVE-2018-6622.```
[sudo] password for napper: 
                     ,----------------,              ,---------,
                ,-----------------------,          ,"        ,"|
              ," Napper v 1.3 for TPM ,"|        ,"        ,"  |
             +-----------------------+  |      ,"        ,"    |
             |  .-----------------Z  |  |     +---------+      |
             |  |               Z |  |  |     | -==----'|      |
             |  |   ︶     ︶ z   |  |  |     |         |      |
             |  |       -         |  |  |/----| ==== oo |      |
             |  |                 |  |  |   ,/| ((((    |    ,"
             |  `-----------------'  |," .;'/ | ((((    |  ,"
             +-----------------------+  ;;  | |         |,"     
                /_)______________(_/  //'   | +---------+
           ___________________________/___  `,
          /  oooooooooooooooo  .o.  oooo /    \,"---------
         / ==ooooooooooooooo==.o.  ooo= /    ,`\--{-D)  ,"
         `-----------------------------'    '----------"

 Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
             Made by Seunghun Han, https://kkamagui.github.io
         Project link: https://github.com/kkamagui/napper-for-tpm 

Checking TPM version for testing.
    [*] Checking TPM version... TPM v2.0.
    [*] Your system has TPM v2.0, and vulnerability checking is needed.

Preparing for sleep.
    [*] Checking the TPM vulnerability testing module... Starting.
    [*] Ready to sleep! Please press "Enter" key.
    [*] After sleep, please press "Enter" key again to wake up.

    [*] Waking up now. Please wait for a while. . . . . . . . . . . 
    [*] Checking the resource manager process... Starting.

    [*] Reading PCR values of TPM and checking a vulnerability... Vulnerable.
    [*] Show all PCR values:         
        Bank/Algorithm: TPM_ALG_SHA1(0x0004)
        PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        
        Bank/Algorithm: TPM_ALG_SHA256(0x000b)
        PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

    [*] Extending 0xdeadbeef to all static PCRs.
    [*] Show all PCR values:         
        Bank/Algorithm: TPM_ALG_SHA1(0x0004)
        PCR_00: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_01: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_02: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_03: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_04: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_05: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_06: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_07: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_08: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_09: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_10: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_11: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_12: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_13: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_14: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_15: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_16: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        
        Bank/Algorithm: TPM_ALG_SHA256(0x000b)
        PCR_00: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_01: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_02: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_03: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_04: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_05: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_06: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_07: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_08: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_09: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_10: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_11: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_12: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_13: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_14: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_15: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_16: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41

Summary. Please contribute summary below to the Napper project, https://www.github.com/kkamagui/napper-for-tpm.
    [*] Your TPM version is 2.0, and it is vulnerable.
        Please download the latest BIOS firmware from the manufacturer's site and update it.

    [*] TPM v2.0 information.
        Manufacturer: IFX
        Vendor strings: SLB9  665   
        Firmware Version: 00050028 0007B302 
        Revision: 116
        Year: 2014
        Day of year: 303

    [*] System information.
        Baseboard manufacturer: Intel Corporation
        Baseboard product name: NUC5i5MYBE
        Baseboard version: H47797-205
        BIOS vendor: Intel Corporation
        BIOS version: MYBDWi5v.86A.0026.2015.0820.1501
        BIOS release date: 08/20/2015
        System manufacturer:                                  
        System product name:                                  

4. Mitigazioni

La causa principale di CVE-2018-6622 e del CVE sconosciuto è la gestione impropria di un caso anomalo di sospensione S3, ed è possibile rimuovere la vulnerabilità seguendo due opzioni.

  • Aggiornare l'ultimo firmware BIOS sul sistema: Abbiamo segnalato il CVE-2018-6622 ai principali produttori come Intel, Dell e Lenovo. Abbiamo anche segnalato il CVE sconosciuto di Intel PTT a Intel. Per risolverli, il produttore ha già rilasciato un nuovo firmware. Se sei ancora vulnerabile dopo aver aggiornato l'ultimo BIOS, provare la prossima opzione di seguito e contribuisci con il tuo rapporto di riepilogo.
  • Disabilitare la funzionalità di sospensione S3 nel BIOS: Il recente firmware BIOS ha una funzionalità che disabilita la sospensione S3 per diversi motivi. Pertanto, entrare nella configurazione del BIOS e disabilitare la sospensione S3.

5. Contributi

Abbiamo preparato questa sezione per te. Non esitare a contattarci.

  • Bumblebee
  • Gwan-gyeong Mun, ricercatore presso Intel
  • Juneseok Byun presso Lab, il secondo cervello e il terzo occhio dell'Università di Hongik
  • JaeRyoung Oh, CEO di Blackfort Security, Inc.
  • Junyoung Jung presso Mobile & Embedded System Lab. dell'Università di Kyung Hee
  • Matt Oh
  • Seong Bin Park, sviluppatore di motori anti-cheat e ricercatore di malware presso wellbia.com
  • Sung Ki Park, Microsoft MVP in Windows e dispositivi per IT
  • Yonghwan Roh, CEO di Somma, Inc.

6. Risultati dei test

Aggiorneremo questo campo con i tuoi contributi. Stiamo testando diversi dispositivi che abbiamo e aggiorneremo presto il risultato.

7. Problemi noti

  • Alcune macchine spengono l'alimentazione di un'unità USB durante la sospensione S3 e non riescono a riconnetterla. In questo caso, collegare l'unità USB a una "porta sempre alimentata" del sistema.
  • Ubuntu 18.04 a volte non riesce a trovare un TPM nel sistema. In questo caso, riavviare con Napper e riprovare.
  • Se Secure Boot è abilitato, il sistema non può avviarsi con Napper. Per il test, disabilitare temporaneamente l'opzione Secure Boot.

8. TODO

  • I dispositivi Microsoft come Surface Book 2, Surface Pro 6, Surface Laptop 2 non sono supportati da Ubuntu 18.04 e dal Kernel 4.18.0-15. È necessario testare dopo l'aggiornamento del kernel.
Scarica lo strumento
ModelStatusBIOS VendorBIOS VersionBIOS Release Date (MM/DD/YY)TPM 2.0 ManufacturerVendor StringTPM Firmware Version
ASUS Q170M-CVulnerabileAmerican Megatrends Inc.400111/09/2018Infineon (IFX)SLB96655.51.8.12800
Dell Optiplex 7040VulnerabileDell1.11.110/10/2018NTCrls NPCT1.3.2.8
Dell Optiplex 7050VulnerabileDell1.11.011/01/2018NTCrls NPCT1.3.2.8
GIGABYTE H170-D3HPVulnerabileAmerican Megatrends Inc.F20g03/09/2018Infineon (IFX)SLB96655.61.10.57600
GIGABYTE Q170M-MKVulnerabileAmerican Megatrends Inc.F2304/12/2018Infineon (IFX)SLB96655.51.8.12802
HP Spectre x360VulnerabileAmerican MegatrendsF.2401/07/2019Infineon (IFX)SLB96655.62.12.13824
Intel NUC5i5MYHEVulnerabileIntelMYBDWi5v.86A. 0049.2018. 1107.104611/07/2018Infineon (IFX)SLB96655.40.7.45826
Lenovo T480 (20L5A00TKR)SicuroLenovoN24ET44W (1.19 )11/07/2018Infineon (IFX)SLB96707.63.14.6400
Lenovo T580SicuroLenovoN27ET20W (1.06 )01/22/2018STMicroelectronics73.4.17568.4452
Microsoft Surface Pro 4SicuroMicrosoft Corporation108.2439.76912/07/2018Infineon (IFX)SLB96655.62.12.13826