![]() |
|
Intel ME Removal {Help} - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Computers (https://sinister.li/Forum-Computers) +--- Forum: Hardware & Customization (https://sinister.li/Forum-Hardware-Customization) +--- Thread: Intel ME Removal {Help} (/Thread-Intel-ME-Removal-Help) |
Intel ME Removal {Help} - S3xySmurf - 11-09-2017 Ok so a little backstory into Intel ME, I have taken some snippets of information to get my point across (Now I could just be paranoid about this). Intel’s Management Engine (ME) technology is built into almost all modern Intel CPUs, Intel’s ME technology is a hardware-level system within Intel CPUs that consists of closed-source firmware running on a dedicated microprocessor, ME has access to many, if not all, of the platform’s integrated devices, such as Intel network controllers. It can also access the main system RAM (the DDR RAM) through DMA. Much has changed in Intel’s platform since some of this was reported, however, so the state of ME now isn’t well understood. Intel, of course, keeps many of the details veiled in secrecy for security purposes. Low-level code executing independently from the system OS is necessary for features such as network boot or wake-from-USB. This type of code is firmware and its existence is a given on modern hardware. The driver gives a regular app a way to use the hardware through the OS, but the driver itself controls the hardware by communicating with its firmware. The firmware is a program, so it needs a processor and RAM to run. ME is an operating system which runs in Root -3, it’s an OS running in parallel that is capable of accessing the same hardware at the same time as the system OS but it's not aware of the system OS (That we know of) but ME can talk directly to the internet and to me it seems like a consumer PC shouldn't have it running if anyone ever managed to crack the Intel master key it could potentially give them access to millions of PC's all at once and you wouldn't even know if you've been targeted as there's no way to access this little microprocessor which has complete control over your PC without your knowledge. Even Google is trying to remove it from there systems and a move like this suggests a lot, Google is trying to remove not because of the features I've posted here but because of the sheer complexity of ME, now enough paranoid rambling onto the problem at hand. I'm trying to remove intel ME by dumping the firmware and using https://github.com/corna/me_cleaner but I'm having difficulty figuring out the <CHIP MODEL> Here is the output of intelmetool -s Code: MEI not hidden on PCI, checking if visible
MEI found: [8086:a13a] Sunrise Point-H CSME HECI #1
ME Status : 0x90000245
ME Status 2 : 0x86110306
ME: FW Partition Table : OK
ME: Bringup Loader Failure : NO
ME: Firmware Init Complete : YES
ME: Manufacturing Mode : NO
ME: Boot Options Present : NO
ME: Update In Progress : NO
ME: Current Working State : Normal
ME: Current Operation State : M0 with UMA
ME: Current Operation Mode : Normal
ME: Error Code : No Error
ME: Progress Phase : Clean Moff->Mx wake
ME: Power Management Event : Pseudo-global reset
ME: Progress Phase State : Unknown 0x11
ME: Extend Register not valid
ME: timeout waiting for data: expected 8, available 0
ME: GET FW VERSION message failed
ME: timeout waiting for data: expected 5, available 0
ME: GET FWCAPS message failedHere is the output of lspci -v Code: 00:16.0 Communication controller: Intel Corporation Sunrise Point-H CSME HECI #1 (rev 31)
Subsystem: ASUSTeK Computer Inc. Sunrise Point-H CSME HECI
Flags: bus master, fast devsel, latency 0, IRQ 130
Memory at f754d000 (64-bit, non-prefetchable) [size=4K]
Capabilities: [50] Power Management version 3
Capabilities: [8c] MSI: Enable+ Count=1/1 Maskable- 64bit+
Kernel driver in use: mei_me
Kernel modules: mei_meFor those of you who don't know. More info on Ring -3 https://www.blackhat.com/presentations/bh-usa-09/TERESHKIN/BHUSA09-Tereshkin-Ring3Rootkit-SLIDES.pdf :/ complete remote access to most devices. RE: Intel ME Removal {Help} - peter lee - 11-09-2017 Posting because I'm interested RE: Intel ME Removal {Help} - S3xySmurf - 11-09-2017 Ok so I couldn't figure out which "Chip Model" I have but I did manage to dump my SPI any way using chipsec but now I'm getting another error which I'm really confused about. New error: Code: Full image detected
The ME/TXE region is corrupted or missingifdtool -d output: Code: File rom.bin is 16777216 bytes
FLMAP0: 0x00040003
NR: 0
FRBA: 0x40
NC: 1
FCBA: 0x30
FLMAP1: 0x58100208
ISL: 0x58
FPSBA: 0x100
NM: 2
FMBA: 0x80
FLMAP2: 0x00310330
PSL: 0x3103
FMSBA: 0x300
FLUMAP1: 0x000006df
Intel ME VSCC Table Length (VTL): 6
Intel ME VSCC Table Base Address (VTBA): 0x000df0
ME VSCC table:
JID0: 0x001840ef
SPI Componend Device ID 1: 0x18
SPI Componend Device ID 0: 0x40
SPI Componend Vendor ID: 0xef
VSCC0: 0x20252025
Lower Erase Opcode: 0x20
Lower Write Enable on Write Status: 0x50
Lower Write Status Required: No
Lower Write Granularity: 64 bytes
Lower Block / Sector Erase Size: 4KB
Upper Erase Opcode: 0x20
Upper Write Enable on Write Status: 0x50
Upper Write Status Required: No
Upper Write Granularity: 64 bytes
Upper Block / Sector Erase Size: 4KB
JID1: 0x001840c8
SPI Componend Device ID 1: 0x18
SPI Componend Device ID 0: 0x40
SPI Componend Vendor ID: 0xc8
VSCC1: 0x20252025
Lower Erase Opcode: 0x20
Lower Write Enable on Write Status: 0x50
Lower Write Status Required: No
Lower Write Granularity: 64 bytes
Lower Block / Sector Erase Size: 4KB
Upper Erase Opcode: 0x20
Upper Write Enable on Write Status: 0x50
Upper Write Status Required: No
Upper Write Granularity: 64 bytes
Upper Block / Sector Erase Size: 4KB
JID2: 0x001820c2
SPI Componend Device ID 1: 0x18
SPI Componend Device ID 0: 0x20
SPI Componend Vendor ID: 0xc2
VSCC2: 0x20452045
Lower Erase Opcode: 0x20
Lower Write Enable on Write Status: 0x50
Lower Write Status Required: No
Lower Write Granularity: 64 bytes
Lower Block / Sector Erase Size: 4KB
Upper Erase Opcode: 0x20
Upper Write Enable on Write Status: 0x50
Upper Write Status Required: No
Upper Write Granularity: 64 bytes
Upper Block / Sector Erase Size: 4KB
OEM Section:
00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
10: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
30: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
Found Region Section
FLREG0: 0x00000000
Flash Region 0 (Flash Descriptor): 00000000 - 00000fff
FLREG1: 0x0fff0280
Flash Region 1 (BIOS): 00280000 - 00ffffff
FLREG2: 0x027f0003
Flash Region 2 (Intel ME): 00003000 - 0027ffff
FLREG3: 0x00020001
Flash Region 3 (GbE): 00001000 - 00002fff
FLREG4: 0x00007fff
Flash Region 4 (Platform Data): 07fff000 - 00000fff (unused)
FLREG5: 0x00007fff
Flash Region 5 (Reserved): 07fff000 - 00000fff (unused)
FLREG6: 0x00007fff
Flash Region 6 (Reserved): 07fff000 - 00000fff (unused)
FLREG7: 0x00007fff
Flash Region 7 (Reserved): 07fff000 - 00000fff (unused)
FLREG8: 0x00007fff
Flash Region 8 (EC): 07fff000 - 00000fff (unused)
Found Component Section
FLCOMP 0x125c00f5
Dual Output Fast Read Support: not supported
Read ID/Read Status Clock Frequency: 48MHz
Write/Erase Clock Frequency: 48MHz
Fast Read Clock Frequency: 48MHz
Fast Read Support: supported
Read Clock Frequency: 17MHz
Component 2 Density: UNUSED
Component 1 Density: 16MB
FLILL 0xad604221
Invalid Instruction 3: 0xad
Invalid Instruction 2: 0x60
Invalid Instruction 1: 0x42
Invalid Instruction 0: 0x21
FLPB 0xc7c4b9b7
Flash Partition Boundary Address: 0x9b7000
Found PCH Strap Section
PCHSTRP0: 0x00800000
PCHSTRP1: 0x00000100
PCHSTRP2: 0x00000000
PCHSTRP3: 0x00000000
PCHSTRP4: 0x00000000
PCHSTRP5: 0x00010000
PCHSTRP6: 0x00000100
PCHSTRP7: 0x00000000
PCHSTRP8: 0x00000000
PCHSTRP9: 0x00000000
PCHSTRP10: 0x00030000
PCHSTRP11: 0x00000100
PCHSTRP12: 0x00000000
PCHSTRP13: 0x00000000
PCHSTRP14: 0x00000000
PCHSTRP15: 0x00010000
PCHSTRP16: 0x00000100
PCHSTRP17: 0x00000000
Found Master Section
FLMSTR1: 0x00a00b00 (Host CPU/BIOS)
EC Region Write Access: disabled
Platform Data Region Write Access: disabled
GbE Region Write Access: enabled
Intel ME Region Write Access: disabled <--- we don't have write access
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: disabled
EC Region Read Access: disabled
Platform Data Region Read Access: disabled
GbE Region Read Access: enabled
Intel ME Region Read Access: disabled <--- we don't have read access
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR2: 0x00c00d00 (Intel ME)
EC Region Write Access: disabled
Platform Data Region Write Access: disabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled <--- we have write access
Host CPU/BIOS Region Write Access: disabled
Flash Descriptor Write Access: disabled
EC Region Read Access: disabled
Platform Data Region Read Access: disabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled <--- we have read access
Host CPU/BIOS Region Read Access: disabled
Flash Descriptor Read Access: enabled
FLMSTR3: 0x00800800 (GbE)
EC Region Write Access: disabled
Platform Data Region Write Access: disabled
GbE Region Write Access: enabled
Intel ME Region Write Access: disabled <--- No write access
Host CPU/BIOS Region Write Access: disabled
Flash Descriptor Write Access: disabled
EC Region Read Access: disabled
Platform Data Region Read Access: disabled
GbE Region Read Access: enabled
Intel ME Region Read Access: disabled <--- no read access
Host CPU/BIOS Region Read Access: disabled
Flash Descriptor Read Access: disabled
FLMSTR5: 0x02002000 (EC)
EC Region Write Access: disabled
Platform Data Region Write Access: disabled
GbE Region Write Access: disabled
Intel ME Region Write Access: disabled <--- we don't have write access
Host CPU/BIOS Region Write Access: disabled
Flash Descriptor Write Access: disabled
EC Region Read Access: disabled
Platform Data Region Read Access: disabled
GbE Region Read Access: disabled
Intel ME Region Read Access: disabled <--- we don't have read access
Host CPU/BIOS Region Read Access: disabled
Flash Descriptor Read Access: disabled
Found Processor Strap Section
????: 0x00000000
????: 0x80108012
????: 0x00000210
????: 0xffffffff
????: 0xffffffff
????: 0xffffffff
????: 0xffffffff
????: 0xffffffffThe above means I have to use an external programmer to flash the chip, so I may do this at another time when I have a little free time for now looks like ME staying put :/ if you get the same results you can use ifdtool -u to unlock and give you access but I'm at an end as I don't have an external programmer laying around. ifdtool -u & re-dump the rom.bin.new file Code: File rom.bin.new is 16777216 bytes
FLMAP0: 0x00040003
NR: 0
FRBA: 0x40
NC: 1
FCBA: 0x30
FLMAP1: 0x58100208
ISL: 0x58
FPSBA: 0x100
NM: 2
FMBA: 0x80
FLMAP2: 0x00310330
PSL: 0x3103
FMSBA: 0x300
FLUMAP1: 0x000006df
Intel ME VSCC Table Length (VTL): 6
Intel ME VSCC Table Base Address (VTBA): 0x000df0
ME VSCC table:
JID0: 0x001840ef
SPI Componend Device ID 1: 0x18
SPI Componend Device ID 0: 0x40
SPI Componend Vendor ID: 0xef
VSCC0: 0x20252025
Lower Erase Opcode: 0x20
Lower Write Enable on Write Status: 0x50
Lower Write Status Required: No
Lower Write Granularity: 64 bytes
Lower Block / Sector Erase Size: 4KB
Upper Erase Opcode: 0x20
Upper Write Enable on Write Status: 0x50
Upper Write Status Required: No
Upper Write Granularity: 64 bytes
Upper Block / Sector Erase Size: 4KB
JID1: 0x001840c8
SPI Componend Device ID 1: 0x18
SPI Componend Device ID 0: 0x40
SPI Componend Vendor ID: 0xc8
VSCC1: 0x20252025
Lower Erase Opcode: 0x20
Lower Write Enable on Write Status: 0x50
Lower Write Status Required: No
Lower Write Granularity: 64 bytes
Lower Block / Sector Erase Size: 4KB
Upper Erase Opcode: 0x20
Upper Write Enable on Write Status: 0x50
Upper Write Status Required: No
Upper Write Granularity: 64 bytes
Upper Block / Sector Erase Size: 4KB
JID2: 0x001820c2
SPI Componend Device ID 1: 0x18
SPI Componend Device ID 0: 0x20
SPI Componend Vendor ID: 0xc2
VSCC2: 0x20452045
Lower Erase Opcode: 0x20
Lower Write Enable on Write Status: 0x50
Lower Write Status Required: No
Lower Write Granularity: 64 bytes
Lower Block / Sector Erase Size: 4KB
Upper Erase Opcode: 0x20
Upper Write Enable on Write Status: 0x50
Upper Write Status Required: No
Upper Write Granularity: 64 bytes
Upper Block / Sector Erase Size: 4KB
OEM Section:
00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
10: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
30: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
Found Region Section
FLREG0: 0x00000000
Flash Region 0 (Flash Descriptor): 00000000 - 00000fff
FLREG1: 0x0fff0280
Flash Region 1 (BIOS): 00280000 - 00ffffff
FLREG2: 0x027f0003
Flash Region 2 (Intel ME): 00003000 - 0027ffff
FLREG3: 0x00020001
Flash Region 3 (GbE): 00001000 - 00002fff
FLREG4: 0x00007fff
Flash Region 4 (Platform Data): 07fff000 - 00000fff (unused)
FLREG5: 0x00007fff
Flash Region 5 (Reserved): 07fff000 - 00000fff (unused)
FLREG6: 0x00007fff
Flash Region 6 (Reserved): 07fff000 - 00000fff (unused)
FLREG7: 0x00007fff
Flash Region 7 (Reserved): 07fff000 - 00000fff (unused)
FLREG8: 0x00007fff
Flash Region 8 (EC): 07fff000 - 00000fff (unused)
Found Component Section
FLCOMP 0x125c00f5
Dual Output Fast Read Support: not supported
Read ID/Read Status Clock Frequency: 48MHz
Write/Erase Clock Frequency: 48MHz
Fast Read Clock Frequency: 48MHz
Fast Read Support: supported
Read Clock Frequency: 17MHz
Component 2 Density: UNUSED
Component 1 Density: 16MB
FLILL 0xad604221
Invalid Instruction 3: 0xad
Invalid Instruction 2: 0x60
Invalid Instruction 1: 0x42
Invalid Instruction 0: 0x21
FLPB 0xc7c4b9b7
Flash Partition Boundary Address: 0x9b7000
Found PCH Strap Section
PCHSTRP0: 0x00800000
PCHSTRP1: 0x00000100
PCHSTRP2: 0x00000000
PCHSTRP3: 0x00000000
PCHSTRP4: 0x00000000
PCHSTRP5: 0x00010000
PCHSTRP6: 0x00000100
PCHSTRP7: 0x00000000
PCHSTRP8: 0x00000000
PCHSTRP9: 0x00000000
PCHSTRP10: 0x00030000
PCHSTRP11: 0x00000100
PCHSTRP12: 0x00000000
PCHSTRP13: 0x00000000
PCHSTRP14: 0x00000000
PCHSTRP15: 0x00010000
PCHSTRP16: 0x00000100
PCHSTRP17: 0x00000000
Found Master Section
FLMSTR1: 0xffffff00 (Host CPU/BIOS)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR2: 0xffffff00 (Intel ME)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR3: 0xffffff00 (GbE)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR5: 0x02002000 (EC)
EC Region Write Access: disabled
Platform Data Region Write Access: disabled
GbE Region Write Access: disabled
Intel ME Region Write Access: disabled
Host CPU/BIOS Region Write Access: disabled
Flash Descriptor Write Access: disabled
EC Region Read Access: disabled
Platform Data Region Read Access: disabled
GbE Region Read Access: disabled
Intel ME Region Read Access: disabled
Host CPU/BIOS Region Read Access: disabled
Flash Descriptor Read Access: disabled
Found Processor Strap Section
????: 0x00000000
????: 0x80108012
????: 0x00000210
????: 0xffffffff
????: 0xffffffff
????: 0xffffffff
????: 0xffffffff
????: 0xffffffffIf anyone else has more experience in this area any input is appreciated. |