Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
napper-for-tpm — 针对CVE-2018-6622的TPM漏洞检查工具。该工具将在Black Hat Asia 2019和Black Hat Europe 2019上发布。 | Kitploit
工具/GitHubGitHub/kkamagui/napper-for-tpm
嵌入式系统安全漏洞分析漏洞利用渗透测试硬件安全固件分析
GitHubkkamagui/napper-for-tpm

napper-for-tpm

针对CVE-2018-6622的TPM漏洞检查工具。该工具将在Black Hat Asia 2019和Black Hat Europe 2019上发布。

查看仓库
107194年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
root@kitploit:~
                     ,----------------,              ,---------,
                ,-----------------------,          ,"        ,"|
              ," Napper v1.3 for TPM ," |        ,"        ,"  |
             +-----------------------+  |      ,"        ,"    |
             |  .-----------------Z  |  |     +---------+      |
             |  |               Z |  |  |     | -==----'|      |
             |  |   ︶     ︶ z   |  |  |     |         |      |
             |  |       -         |  |  |/----| ==== oo |      |
             |  |                 |  |  |   ,/| ((((    |    ,"
             |  `-----------------'  |," .;'/ | ((((    |  ,"
             +-----------------------+  ;;  | |         |,"     
                /_)______________(_/  //'   | +---------+
           ___________________________/___  `,
          /  oooooooooooooooo  .o.  oooo /    \,"---------
         / ==ooooooooooooooo==.o.  ooo= /    ,`\--{-D)  ,"
         `-----------------------------'    '----------"

 Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
         Project link: https://github.com/kkamagui/napper-for-tpm 
        Please contribute your summary report to the Napper project!                    

1. 注意事项

“Napper”是一款用于检查离散TPM和固件TPM(Intel PTT)的新型漏洞检测工具。CVE-2018-6622及一个未知CVE与高级配置与电源接口(ACPI)的S3休眠状态或挂起相关。攻击者可利用S3休眠破坏TPM,并使得基于平台配置寄存器(PCR)的远程认证及密封/解封功能失效。如需了解CVE-2018-6622及未知CVE的详细信息,请阅读我们的USENIX论文《A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping》以及Black Hat Europe 2019演讲《BitLeaker: Subverting BitLocker with One Vulnerability》。

1.1. 演讲与论文

Napper及CVE-2018-6622曾在以下安全会议上介绍:

  • Black Hat Asia 2019: Finally, I Can Sleep Tonight: Catching Sleep Mode Vulnerabilities of the TPM with the Napper
  • USENIX Security 2018: A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping

与Intel平台信任技术(PTT)相关的一个未知CVE曾在以下安全会议上介绍:

  • BitLeaker: Subverting BitLocker with One Vulnerability

您可以观看下方演示视频:

  • Napper v1.0 Demo

1.2. 贡献

我们欢迎您的贡献。您提供的Napper汇总报告将使世界更加安全。

1.3. 许可协议

Napper采用GPL v2许可协议。

2. Napper简介

可信平台模块(TPM)是一种防篡改设备,旨在提供基于硬件或固件的安全功能。TPM芯片包含随机数生成器、非易失性存储、加密/解密模块以及平台配置寄存器(PCR),可用于BitLocker、DM-Crypt、可信启动(tboot)和开放云完整性技术(Open CIT)等多种安全应用。

TPM已广泛部署在商用设备中,为构建可信平台提供了坚实基础,尤其是在企业及政府系统中。由于TPM是可信平台的关键节点,许多研究人员曾试图发现TPM中的漏洞,并得出结论:没有物理访问权限很难攻破它。然而,这一结论已不再成立。

我们发现的漏洞可通过高级配置与电源接口(ACPI)破坏TPM。PC、笔记本电脑和服务器中的ACPI提供了六种休眠状态(S0-S5)以降低功耗。当系统进入休眠状态时,CPU、设备和RAM将断电。由于系统会关闭包括安全设备在内的组件,因此在唤醒时需要重新初始化它们,这便成为了攻击面。我们无需物理访问即发现了该攻击面上的漏洞。

为缓解这些漏洞,我们还提出了应对措施并使用新工具“Napper”来检查TPM的漏洞。Napper是一个基于Linux的可启动USB设备,包含内核模块和漏洞检查软件。当您使用Napper启动系统时,它会让系统“小睡”以检查漏洞,并向您报告结果。

3. 如何使用“Napper”工具

Napper包含一个特殊的内核模块和定制的tpm2工具。Napper基于Ubuntu 18.04,我们对其进行了定制和裁剪以制作Live CD镜像。如果您只想检查TPM漏洞并希望采用简单的方式,请跳至第3.1节,使用Napper Live CD镜像与您的USB存储设备。Napper Live CD不仅包含二进制工具,还包含Napper的完整源代码。如果您当前使用Ubuntu 18.04并希望从头构建Napper,请跳至第3.2节进行构建。

3.1. 使用您自己的USB存储设备与Napper Live CD镜像(简版)

3.1.1. 从Napper项目获取Napper Live CD镜像

Napper Live CD镜像存放于Napper项目的发布页面。

3.1.2. 将Napper Live CD镜像写入您的USB存储设备

如果您使用Microsoft Windows操作系统,请使用Win32 Disk Imager并将Napper Live CD镜像写入您的USB存储设备。

如果您使用Linux或Mac OS X,请使用以下dd命令。```

Please change sdX to your USB storage name.

$> sudo dd if=Napper-LiveCD.iso of=/dev/sdX bs=4096 $> sync

root@kitploit:~
### 3.1.3. 使用USB存储重启系统并运行Napper
插入USB存储并更改引导顺序以使用它启动后,您将看到Napper的引导菜单,选择第一个选项即可启动Napper Live CD。
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/525cb00d8f948ccc1653bd4fd08c8baf293615ad80ec52082b6c04efe7484f57.png" alt="napper_boot_menu"/> </center>

启动完成后,您会在桌面上看到README.txt文件,左侧任务栏上有Napper工具图标。要检查您的系统,请点击任务栏顶部的图标,并输入密码`napper`。Napper工具的`ID`和`密码`均设置为`napper`。在Napper测试系统时,它会使系统进入休眠并唤醒。因此,您需要敲击键盘将系统从ACPI S3休眠状态唤醒。
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/50fdb76d396e32fe811b7f9e23849fd4b66fccee5c4325b5f8c4f167938c51b2.png" alt="napper_run"/> </center>

如果您的系统存在TPM漏洞,Napper将在此处报告摘要,表明您的系统易受攻击。如果是这样,请跳转到第4节,并将摘要通过[Napper项目的Issue报告](https://github.com/kkamagui/napper-for-tpm/issues)或[网站](https://kkamagui.github.io/)分享给我们的项目Napper。
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/37d28f91902c745a21bd3be9c8f373394694127db5037cc4fb522e1e660c0e65.png" alt="napper_summary"/> </center>

## 3.2. 从零开始使用Ubuntu 18.04构建Napper(详细版本)
### 3.2.1. 下载Ubuntu 18.04并克隆Napper源代码
Napper基于Ubuntu 18.04。因此,您需要从[Ubuntu官方网站](https://www.ubuntu.com/download/desktop)下载并安装到目标系统上。然后,从[Napper项目站点,https://www.github.com/kkamagui/napper-for-tpm](https://www.github.com/kkamagui/napper-for-tpm)克隆Napper源代码,并使用以下命令构建。```
# Clone Napper source code from project site.
$> git clone https://github.com/kkamagui/napper-for-tpm.git

# Build Napper.
$> cd napper-for-tpm
$> ./bootstrap

3.2.2. 使用终端运行Napper

构建源代码后,您可以使用终端运行Napper工具。请在终端中输入以下命令。Napper前端由Python脚本构成。```

Run Napper

$> sudo ./napper.py ,----------------, ,---------, ,-----------------------, ," ,"| ," Napper v 1.3 for TPM ,"| ," ," | +-----------------------+ | ," ," | | .-----------------Z | | +---------+ | | | Z | | | | -==----'| | | | ︶ ︶ z | | | | | | | | - | | |/----| ==== oo | | | | | | | ,/| (((( | ," | -----------------' |," .;'/ | (((( | ," +-----------------------+ ;; | | |," /_)______________(_/ //' | +---------+ ___________________________/___ , / oooooooooooooooo .o. oooo / ,"--------- / ==ooooooooooooooo==.o. ooo= / ,\--{-D) ," -----------------------------' '----------"

Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE Made by Seunghun Han, https://kkamagui.github.io Project link: https://github.com/kkamagui/napper-for-tpm

Checking TPM version for testing. [] Checking TPM version... TPM v2.0. [] Your system has TPM v2.0, and vulnerability checking is needed.

Preparing for sleep. [] Checking the TPM vulnerability testing module... Starting. [] Ready to sleep! Please press "Enter" key. [*] After sleep, please press "Enter" key again to wake up.

root@kitploit:~
[*] Waking up now. Please wait for a while. . . . . . . . . . .     

... omitted ...
root@kitploit:~
## 3.3. 测试示例
以下是 NUC5i5MYHE 型号的示例结果。该系统具有旧版本的 BIOS,并且存在 CVE-2018-6622。```
[sudo] password for napper: 
                     ,----------------,              ,---------,
                ,-----------------------,          ,"        ,"|
              ," Napper v 1.3 for TPM ,"|        ,"        ,"  |
             +-----------------------+  |      ,"        ,"    |
             |  .-----------------Z  |  |     +---------+      |
             |  |               Z |  |  |     | -==----'|      |
             |  |   ︶     ︶ z   |  |  |     |         |      |
             |  |       -         |  |  |/----| ==== oo |      |
             |  |                 |  |  |   ,/| ((((    |    ,"
             |  `-----------------'  |," .;'/ | ((((    |  ,"
             +-----------------------+  ;;  | |         |,"     
                /_)______________(_/  //'   | +---------+
           ___________________________/___  `,
          /  oooooooooooooooo  .o.  oooo /    \,"---------
         / ==ooooooooooooooo==.o.  ooo= /    ,`\--{-D)  ,"
         `-----------------------------'    '----------"

 Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
             Made by Seunghun Han, https://kkamagui.github.io
         Project link: https://github.com/kkamagui/napper-for-tpm 

Checking TPM version for testing.
    [*] Checking TPM version... TPM v2.0.
    [*] Your system has TPM v2.0, and vulnerability checking is needed.

Preparing for sleep.
    [*] Checking the TPM vulnerability testing module... Starting.
    [*] Ready to sleep! Please press "Enter" key.
    [*] After sleep, please press "Enter" key again to wake up.

    [*] Waking up now. Please wait for a while. . . . . . . . . . . 
    [*] Checking the resource manager process... Starting.

    [*] Reading PCR values of TPM and checking a vulnerability... Vulnerable.
    [*] Show all PCR values:         
        Bank/Algorithm: TPM_ALG_SHA1(0x0004)
        PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        
        Bank/Algorithm: TPM_ALG_SHA256(0x000b)
        PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

    [*] Extending 0xdeadbeef to all static PCRs.
    [*] Show all PCR values:         
        Bank/Algorithm: TPM_ALG_SHA1(0x0004)
        PCR_00: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_01: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_02: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_03: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_04: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_05: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_06: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_07: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_08: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_09: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_10: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_11: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_12: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_13: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_14: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_15: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_16: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
        
        Bank/Algorithm: TPM_ALG_SHA256(0x000b)
        PCR_00: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_01: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_02: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_03: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_04: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_05: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_06: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_07: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_08: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_09: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_10: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_11: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_12: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_13: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_14: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_15: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_16: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
        PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
        PCR_23: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41

Summary. Please contribute summary below to the Napper project, https://www.github.com/kkamagui/napper-for-tpm.
    [*] Your TPM version is 2.0, and it is vulnerable.
        Please download the latest BIOS firmware from the manufacturer's site and update it.

    [*] TPM v2.0 information.
        Manufacturer: IFX
        Vendor strings: SLB9  665   
        Firmware Version: 00050028 0007B302 
        Revision: 116
        Year: 2014
        Day of year: 303

    [*] System information.
        Baseboard manufacturer: Intel Corporation
        Baseboard product name: NUC5i5MYBE
        Baseboard version: H47797-205
        BIOS vendor: Intel Corporation
        BIOS version: MYBDWi5v.86A.0026.2015.0820.1501
        BIOS release date: 08/20/2015
        System manufacturer:                                  
        System product name:                                  

4. 缓解措施

CVE-2018-6622 及未知 CVE 的根本原因是对异常 S3 休眠情况的处理不当,您可以通过以下两种选项来消除该漏洞。

  • 将最新 BIOS 固件更新到您的系统:我们已向 Intel、Dell 和 Lenovo 等主要制造商报告了 CVE-2018-6622。我们还将 Intel PTT 的未知 CVE 报告给了 Intel。为了修复这些漏洞,制造商已发布了新固件。如果更新最新 BIOS 后您仍处于易受攻击状态,请尝试以下选项并提交您的总结报告。
  • 在 BIOS 中禁用 S3 休眠功能:最新的 BIOS 固件出于多种原因提供了禁用 S3 休眠的功能。因此,请进入您的 BIOS 设置并禁用 S3 休眠。

5. 贡献者

我们为您准备了本节内容。请随时联系我们。

  • Bumblebee
  • 文光京,英特尔研究员
  • 卞埈碩,弘益大学第二大脑与第三眼实验室
  • 吴在龙,Blackfort Security, Inc. 首席执行官
  • 郑俊英,庆熙大学移动与嵌入式系统实验室
  • Matt Oh
  • 朴成彬,wellbia.com 反作弊引擎开发人员及恶意软件研究员
  • 朴成基,微软 MVP(Windows 与设备领域)
  • 卢容焕,Somma, Inc. 首席执行官

6. 测试结果

我们将根据您的贡献更新此字段。我们正在测试我们拥有的几台设备,并将很快更新结果。

7. 已知问题

  • 部分机器在 S3 休眠期间会关闭 USB 存储设备的电源,并且无法重新连接。在这种情况下,请将 USB 存储设备插入系统的“始终供电”端口。
  • Ubuntu 18.04 有时无法在系统中找到 TPM。在这种情况下,请重新启动 Napper 并重试。
  • 如果启用了安全启动,系统将无法使用 Napper 启动。测试时,请临时禁用安全启动选项。

8. 待办事项

  • 微软设备,如 Surface Book 2、Surface Pro 6、Surface Laptop 2,尚不受 Ubuntu 18.04 和 Kernel 4.18.0-15 支持。升级内核后需要进行测试。
下载工具
型号状态BIOS 厂商BIOS 版本BIOS 发布日期 (月/日/年)TPM 2.0 制造商固件版本TPM 固件版本
ASUS Q170M-C易受攻击American Megatrends Inc.400111/09/2018Infineon (IFX)SLB96655.51.8.12800
Dell Optiplex 7040易受攻击Dell1.11.110/10/2018NTCrls NPCT1.3.2.8
Dell Optiplex 7050易受攻击Dell1.11.011/01/2018NTCrls NPCT1.3.2.8
GIGABYTE H170-D3HP易受攻击American Megatrends Inc.F20g03/09/2018Infineon (IFX)SLB96655.61.10.57600
GIGABYTE Q170M-MK易受攻击American Megatrends Inc.F2304/12/2018Infineon (IFX)SLB96655.51.8.12802
HP Spectre x360易受攻击American MegatrendsF.2401/07/2019Infineon (IFX)SLB96655.62.12.13824
Intel NUC5i5MYHE易受攻击IntelMYBDWi5v.86A. 0049.2018. 1107.104611/07/2018Infineon (IFX)SLB96655.40.7.45826
Lenovo T480 (20L5A00TKR)安全LenovoN24ET44W (1.19 )11/07/2018Infineon (IFX)SLB96707.63.14.6400
Lenovo T580安全LenovoN27ET20W (1.06 )01/22/2018STMicroelectronics73.4.17568.4452
Microsoft Surface Pro 4安全Microsoft Corporation108.2439.76912/07/2018Infineon (IFX)SLB96655.62.12.13826