Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
napper-for-tpm — TPM脆弱性チェックツール(CVE-2018-6622対応)。このツールはBlack Hat Asia 2019およびBlack Hat Europe 2019で公開されます。 | Kitploit
ツール/GitHubGitHub/kkamagui/napper-for-tpm
組み込みシステムセキュリティ脆弱性分析エクスプロイトペネトレーションテストハードウェアセキュリティファームウェア解析
GitHubkkamagui/napper-for-tpm

napper-for-tpm

TPM脆弱性チェックツール(CVE-2018-6622対応)。このツールはBlack Hat Asia 2019およびBlack Hat Europe 2019で公開されます。

リポジトリを見る
107194年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
root@kitploit:~
                     ,----------------,              ,---------,
                ,-----------------------,          ,"        ,"|
              ," Napper v1.3 for TPM ," |        ,"        ,"  |
             +-----------------------+  |      ,"        ,"    |
             |  .-----------------Z  |  |     +---------+      |
             |  |               Z |  |  |     | -==----'|      |
             |  |   ︶     ︶ z   |  |  |     |         |      |
             |  |       -         |  |  |/----| ==== oo |      |
             |  |                 |  |  |   ,/| ((((    |    ,"
             |  `-----------------'  |," .;'/ | ((((    |  ,"
             +-----------------------+  ;;  | |         |,"     
                /_)______________(_/  //'   | +---------+
           ___________________________/___  `,
          /  oooooooooooooooo  .o.  oooo /    \,"---------
         / ==ooooooooooooooo==.o.  ooo= /    ,`\--{-D)  ,"
         `-----------------------------'    '----------"

 Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
         Project link: https://github.com/kkamagui/napper-for-tpm 
        Please contribute your summary report to the Napper project!                    

1. 注意

"Napper"は、ディスクリートTPMおよびファームウェアTPM(Intel PTT)向けの新しい脆弱性チェックツールです。CVE-2018-6622と未知のCVEは、Advanced Configuration and Power Interface(ACPI)のS3スリープ状態またはサスペンドに関連しています。攻撃者はS3スリープでTPMを無効化でき、Platform Configuration Registers(PCR)を使用するリモートアテステーションやシール/アンシール機能を無効化できます。CVE-2018-6622と未知のCVEの詳細については、USENIXの論文A Bad Dream: Subverting Trusted Platform Module While You Are SleepingおよびBlack Hat Europe 2019のプレゼンテーションBitLeaker: Subverting BitLocker with One Vulnerabilityをお読みください。

1.1. 発表と論文

NapperとCVE-2018-6622は、以下のセキュリティカンファレンスで紹介されました。

  • Black Hat Asia 2019: Finally, I Can Sleep Tonight: Catching Sleep Mode Vulnerabilities of the TPM with the Napper
  • USENIX Security 2018: A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping

Intel Platform Trust Technology (PTT)に関連する未知のCVEは、以下のセキュリティカンファレンスで紹介されました。

  • BitLeaker: Subverting BitLocker with One Vulnerability

以下のデモビデオをご覧ください。

  • Napper v1.0 デモ

1.2. 貢献

皆様の貢献を常に歓迎します。あなたが貢献したNapperのサマリーレポートが世界を安全にします。

1.3. ライセンス

NapperはGPL v2ライセンスです。

2. Napperの紹介

Trusted Platform Module(TPM)は耐タンパーデバイスであり、ハードウェアベースまたはファームウェアベースのセキュリティ機能を提供するように設計されています。TPMチップは、乱数生成器、不揮発性ストレージ、暗号化/復号化モジュール、およびPlatform Configuration Registers(PCR)を備えており、これらはBitLocker、DM-Crypt、Trusted Boot(tboot)、Open Cloud Integrity Technology(Open CIT)などのさまざまなセキュリティアプリケーションに利用できます。

TPMは、信頼できるプラットフォームを構築するための強固な基盤を提供するために、一般販売されているデバイス、特に企業や政府システムで使用されるデバイスに広く展開されています。TPMは信頼できるプラットフォームの重要なポイントであるため、多くの研究者がTPMの脆弱性を見つけようと試み、物理的なアクセスなしでは破るのは難しいと結論付けていました。しかし、これはもはや真実ではありません。

私たちが見つけた脆弱性は、Advanced Configuration and Power Interface(ACPI)を用いてTPMを無効化できます。PC、ラップトップ、サーバーのACPIは、消費電力を削減するために6つのスリープ状態(S0-S5)を提供します。システムがスリープ状態に入ると、CPU、デバイス、RAMの電源がオフになります。セキュリティデバイスを含むコンポーネントの電源がオフになるため、システムは起動時にそれらを再初期化する必要があり、これが攻撃対象となる可能性があります。私たちは物理的なアクセスなしでこの攻撃対象の脆弱性を発見しました。

脆弱性を緩和するために、私たちは対策と、TPMの脆弱性をチェックする新しいツール「Napper」も提示します。NapperはLinuxベースの起動可能なUSBデバイスであり、カーネルモジュールと脆弱性チェックソフトウェアを備えています。Napperでシステムを起動すると、システムを一時的にスリープさせて脆弱性をチェックし、結果を報告します。

3. 「Napper」ツールの使い方

Napperは、特別なカーネルモジュールとカスタマイズされたtpm2ツールで構成されています。NapperはUbuntu 18.04をベースにしており、Live CDイメージを作成するためにカスタマイズおよび調整されています。TPMの脆弱性をチェックするだけで、簡単な方法を探している場合は、セクション3.1に進み、USBストレージでNapper Live CDイメージを使用してください。Napper Live CDには、バイナリツールだけでなく、Napperの完全なソースコードも含まれています。現在Ubuntu 18.04を使用していて、Napperをスクラッチからビルドしたい場合は、セクション3.2に進んでビルドしてください。

3.1. 独自のUSBストレージをNapper Live CDイメージで使用する(簡易版)

3.1.1. NapperプロジェクトからNapper Live CDイメージを入手する

Napper Live CDイメージは、Napperプロジェクトのリリースページにあります。

3.1.2. Napper Live CDイメージをUSBストレージに書き込む

Microsoft Windowsオペレーティングシステムを使用している場合は、Win32 Disk Imagerを使用してNapper Live CDイメージをUSBストレージに書き込んでください。

LinuxまたはMac OS Xを使用している場合は、以下のddコマンドを使用してください。```

Please change sdX to your USB storage name.

$> sudo dd if=Napper-LiveCD.iso of=/dev/sdX bs=4096 $> sync

root@kitploit:~
### 3.1.3. USBストレージでシステムを再起動し、Napperを実行する
USBストレージを接続し、ブートシーケンスを変更してそこから起動すると、以下のNapperのブートメニューが表示され、最初のオプションを選択してNapper Live CDを起動できます。
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/525cb00d8f948ccc1653bd4fd08c8baf293615ad80ec52082b6c04efe7484f57.png" alt="napper_boot_menu"/> </center>

ブートシーケンス後、デスクトップにREADME.txtファイルが表示され、左側のドックバーにNapperツールのアイコンが表示されます。システムを確認するには、ドックバーの一番上のアイコンをクリックし、パスワードとして`napper`と入力してください。Napperツールの`ID`と`password`は`napper`に設定されています。Napperがシステムをテストしている間、システムはスリープ状態になり、その後復帰します。そのため、ACPI S3スリープ状態からシステムを復帰させるには、キーボードを操作する必要があります。
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/50fdb76d396e32fe811b7f9e23849fd4b66fccee5c4325b5f8c4f167938c51b2.png" alt="napper_run"/> </center>

システムにTPMの脆弱性がある場合、Napperは以下のようにシステムが脆弱であるというサマリーを報告します。その場合は、セクション4に進み、[NapperプロジェクトのIssue Report](https://github.com/kkamagui/napper-for-tpm/issues)または[Webサイト](https://kkamagui.github.io/)を通じて、そのサマリーを私たちのプロジェクトNapperと共有してください。
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/37d28f91902c745a21bd3be9c8f373394694127db5037cc4fb522e1e660c0e65.png" alt="napper_summary"/> </center>

## 3.2. Ubuntu 18.04を使用してNapperをスクラッチからビルドする(詳細版)
### 3.2.1. Ubuntu 18.04のダウンロードとNapperソースコードのクローン
NapperはUbuntu 18.04をベースとしています。そのため、[公式Ubuntu Webサイト](https://www.ubuntu.com/download/desktop)からダウンロードし、対象システムにインストールしてください。その後、[Napperプロジェクトサイト、https://www.github.com/kkamagui/napper-for-tpm](https://www.github.com/kkamagui/napper-for-tpm)からNapperのソースコードをクローンし、以下のコマンドでビルドします。```
# Clone Napper source code from project site.
$> git clone https://github.com/kkamagui/napper-for-tpm.git

# Build Napper.
$> cd napper-for-tpm
$> ./bootstrap

3.2.2. 端末でNapperを実行する

ソースコードをビルドした後、端末でNapperツールを実行できます。以下のコマンドを端末に入力してください。NapperのフロントエンドはPythonスクリプトで構成されています。```

Run Napper

$> sudo ./napper.py ,----------------, ,---------, ,-----------------------, ," ,"| ," Napper v 1.3 for TPM ,"| ," ," | +-----------------------+ | ," ," | | .-----------------Z | | +---------+ | | | Z | | | | -==----'| | | | ︶ ︶ z | | | | | | | | - | | |/----| ==== oo | | | | | | | ,/| (((( | ," | -----------------' |," .;'/ | (((( | ," +-----------------------+ ;; | | |," /_)______________(_/ //' | +---------+ ___________________________/___ , / oooooooooooooooo .o. oooo / ,"--------- / ==ooooooooooooooo==.o. ooo= / ,\--{-D) ," -----------------------------' '----------"

Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE Made by Seunghun Han, https://kkamagui.github.io Project link: https://github.com/kkamagui/napper-for-tpm

Checking TPM version for testing. [] Checking TPM version... TPM v2.0. [] Your system has TPM v2.0, and vulnerability checking is needed.

Preparing for sleep. [] Checking the TPM vulnerability testing module... Starting. [] Ready to sleep! Please press "Enter" key. [*] After sleep, please press "Enter" key again to wake up.

root@kitploit:~
[*] Waking up now. Please wait for a while. . . . . . . . . . .     

... omitted ...
root@kitploit:~
## 3.3. テスト例
以下はNUC5i5MYHEモデルの例です。このシステムは古いバージョンのBIOSを持ち、CVE-2018-6622の脆弱性があります。```
[sudo] password for napper: 
                     ,----------------,              ,---------,
                ,-----------------------,          ,"        ,"|
              ," Napper v 1.3 for TPM ,"|        ,"        ,"  |
             +-----------------------+  |      ,"        ,"    |
             |  .-----------------Z  |  |     +---------+      |
             |  |               Z |  |  |     | -==----'|      |
             |  |   ︶     ︶ z   |  |  |     |         |      |
             |  |       -         |  |  |/----| ==== oo |      |
             |  |                 |  |  |   ,/| ((((    |    ,"
             |  `-----------------'  |," .;'/ | ((((    |  ,"
             +-----------------------+  ;;  | |         |,"     
                /_)______________(_/  //'   | +---------+
           ___________________________/___  `,
          /  oooooooooooooooo  .o.  oooo /    \,"---------
         / ==ooooooooooooooo==.o.  ooo= /    ,`\--{-D)  ,"
         `-----------------------------'    '----------"

 Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
             Made by Seunghun Han, https://kkamagui.github.io
         Project link: https://github.com/kkamagui/napper-for-tpm 

Checking TPM version for testing.
    [*] Checking TPM version... TPM v2.0.
    [*] Your system has TPM v2.0, and vulnerability checking is needed.

Preparing for sleep.
    [*] Checking the TPM vulnerability testing module... Starting.
    [*] Ready to sleep! Please press "Enter" key.
    [*] After sleep, please press "Enter" key again to wake up.

    [*] Waking up now. Please wait for a while. . . . . . . . . . . 
    [*] Checking the resource manager process... Starting.

    [*] Reading PCR values of TPM and checking a vulnerability... Vulnerable.
    [*] Show all PCR values:         
        Bank/Algorithm: TPM_ALG_SHA1(0x0004)
        PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        
        Bank/Algorithm: TPM_ALG_SHA256(0x000b)
        PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

    [*] Extending 0xdeadbeef to all static PCRs.
    [*] Show all PCR values:         
        Bank/Algorithm: TPM_ALG_SHA1(0x0004)
        PCR_00: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_01: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_02: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_03: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_04: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_05: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_06: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_07: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_08: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_09: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_10: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_11: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_12: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_13: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_14: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_15: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_16: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        
        Bank/Algorithm: TPM_ALG_SHA256(0x000b)
        PCR_00: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_01: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_02: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_03: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_04: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_05: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_06: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_07: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_08: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_09: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_10: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_11: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_12: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_13: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_14: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_15: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_16: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41

Summary. Please contribute summary below to the Napper project, https://www.github.com/kkamagui/napper-for-tpm.
    [*] Your TPM version is 2.0, and it is vulnerable.
        Please download the latest BIOS firmware from the manufacturer's site and update it.

    [*] TPM v2.0 information.
        Manufacturer: IFX
        Vendor strings: SLB9  665   
        Firmware Version: 00050028 0007B302 
        Revision: 116
        Year: 2014
        Day of year: 303

    [*] System information.
        Baseboard manufacturer: Intel Corporation
        Baseboard product name: NUC5i5MYBE
        Baseboard version: H47797-205
        BIOS vendor: Intel Corporation
        BIOS version: MYBDWi5v.86A.0026.2015.0820.1501
        BIOS release date: 08/20/2015
        System manufacturer:                                  
        System product name:                                  

4. 緩和策

CVE-2018-6622および不明のCVEの根本原因は、異常なS3スリープケースの不適切な処理であり、以下の2つのオプションに従って脆弱性を除去できます。

  • 最新のBIOSファームウェアをシステムに更新する: CVE-2018-6622をIntel、Dell、Lenovoなどの主要メーカーに報告しました。また、Intel PTTの不明のCVEをIntelに報告しました。それらを修正するため、メーカーはすでに新しいファームウェアをリリースしています。最新のBIOSを更新しても脆弱なままの場合は、以下の次のオプションを試して、サマリーレポートを提供してください。
  • BIOSでS3スリープ機能を無効にする: 最近のBIOSファームウェアには、いくつかの理由でS3スリープを無効にする機能があります。そのため、BIOSセットアップに入り、S3スリープを無効にしてください。

5. 貢献

このセクションを用意しました。お気軽にご連絡ください。

  • Bumblebee
  • Gwan-gyeong Mun, Intelの研究者
  • Juneseok Byun, 弘益大学の第2の脳 & 第3の目であるLabに所属
  • JaeRyoung Oh, Blackfort Security, Inc. のCEO
  • Junyoung Jung, 慶熙大学のモバイル&組み込みシステム研究所に所属
  • Matt Oh
  • Seong Bin Park, wellbia.comのアンチチートエンジン開発者およびマルウェア研究者
  • Sung Ki Park, WindowsおよびIT向けデバイスにおけるMicrosoft MVP
  • Yonghwan Roh, Somma, Inc. のCEO

6. テスト結果

このフィールドは皆様の貢献で更新します。当社が保有するいくつかのデバイスをテスト中で、近日中に結果を更新します。

7. 既知の問題

  • 一部のマシンでは、S3スリープ中にUSBストレージの電源がオフになり、再接続できない場合があります。その場合は、USBストレージをシステムの「常時給電ポート」に接続してください。
  • Ubuntu 18.04では、システム内のTPMが見つからない場合があります。その場合は、Napperで再起動して再度試してください。
  • セキュアブートが有効な場合、システムはNapperで起動できません。テストのため、一時的にセキュアブートオプションを無効にしてください。

8. TODO

  • MicrosoftのSurface Book 2、Surface Pro 6、Surface Laptop 2などのデバイスは、Ubuntu 18.04およびKernel 4.18.0-15でサポートされていません。カーネルのアップグレード後にテストが必要です。
ツールをダウンロード
モデルステータスBIOSベンダーBIOSバージョンBIOSリリース日 (MM/DD/YY)TPM 2.0 製造元ベンダー文字列TPMファームウェアバージョン
ASUS Q170M-C脆弱American Megatrends Inc.400111/09/2018Infineon (IFX)SLB96655.51.8.12800
Dell Optiplex 7040脆弱Dell1.11.110/10/2018NTCrls NPCT1.3.2.8
Dell Optiplex 7050脆弱Dell1.11.011/01/2018NTCrls NPCT1.3.2.8
GIGABYTE H170-D3HP脆弱American Megatrends Inc.F20g03/09/2018Infineon (IFX)SLB96655.61.10.57600
GIGABYTE Q170M-MK脆弱American Megatrends Inc.F2304/12/2018Infineon (IFX)SLB96655.51.8.12802
HP Spectre x360脆弱American MegatrendsF.2401/07/2019Infineon (IFX)SLB96655.62.12.13824
Intel NUC5i5MYHE脆弱IntelMYBDWi5v.86A. 0049.2018. 1107.104611/07/2018Infineon (IFX)SLB96655.40.7.45826
Lenovo T480 (20L5A00TKR)安全LenovoN24ET44W (1.19 )11/07/2018Infineon (IFX)SLB96707.63.14.6400
Lenovo T580安全LenovoN27ET20W (1.06 )01/22/2018STMicroelectronics73.4.17568.4452
Microsoft Surface Pro 4安全Microsoft Corporation108.2439.76912/07/2018Infineon (IFX)SLB96655.62.12.13826