Šta je novo?

Intel sapatnici - proverite da li je firmware okrpljen

pojma nemam sta ovde treba da bude ali pise da sam ispecovan :)

preksinoc sam odradio i novi bios koji navodno isto krpi nesto od ovoga...

win7, iskljucen apdejt i cekam novi simplix pa je mozda zbog toga ova poruka...

na linuxu sam probao ovo isto da uradim ali pojma nisam imao sta i gde treba pa sam batalio...

nakon apdejta chipseta i pokretanja fix-a koji se nalazio u istom folderu nestale su i sve greske:
 

Prilozi

  • 2018-01-14 23_20_31-INTEL-SA-00086 Detection Tool.png
    2018-01-14 23_20_31-INTEL-SA-00086 Detection Tool.png
    47.3 KB · Pregleda: 153
  • Screen Shot 2018-01-14 at 11.54.37 PM.png
    Screen Shot 2018-01-14 at 11.54.37 PM.png
    31.2 KB · Pregleda: 127
  • 2018-01-15 00_05_32-INTEL-SA-00086 Detection Tool.png
    2018-01-15 00_05_32-INTEL-SA-00086 Detection Tool.png
    44.9 KB · Pregleda: 120
  • 2018-01-15 00_12_39-INTEL-SA-00086 Detection Tool.png
    2018-01-15 00_12_39-INTEL-SA-00086 Detection Tool.png
    40.8 KB · Pregleda: 114
Poslednja izmena:
Kod mene nije, a ranjiv je. Kakav glupost, otkud mi vrijeme da se bavim ovakvim *****izmima.


*** Host Computer Information ***
Name: manjaro
Manufacturer: LENOVO
Model: 80XH
Processor Name: Intel(R) Core(TM) i3-6006U CPU @ 2.00GHz
OS Version: (4.14.12-1-MANJARO)

*** Intel(R) ME Information ***
Engine: Intel(R) Management Engine
Version: 11.6.13.1212
SVN: 1

*** Risk Assessment ***
Based on the analysis performed by this tool: This system is vulnerable.
Explanation:
The detected version of the Intel(R) Management Engine firmware
is considered vulnerable for INTEL-SA-00086.
Contact your system manufacturer for support and remediation of this system.

For more information refer to the INTEL-SA-00086 Detection Tool Guide or the
Intel Security Advisory Intel-SA-00086 at the following link:
https://www.intel.com/sa-00086-support
 
Evo rezultat, šta sada, koga slušati, kome verovati :D
Untitled-1.jpg
12.jpg
MaxthonSnap20180115034901.jpg
Ovaj kaže nije, ovaj kaže malo jeste, malo nije, a acer kaže nisi na listi :)
 
Prvi i drugi su za različite propuste. Prvi za MEI propust a drugi za Meltdown/Spectre.
 
pokrpljen je i linux na masini, ne znam kakvo je stanje bilo sa prethodnim bios-om.

hvala jos jednom kolegi mrtavker, morao sam da pokrenem tool kao root i navedem verziju pythona.
 

Prilozi

  • Screen Shot 2018-01-15 at 5.27.20 PM.png
    Screen Shot 2018-01-15 at 5.27.20 PM.png
    89.4 KB · Pregleda: 90
ma ni tim testovima ne treba 100% verovati.
probacu i ja ovo posto su izbacili pre neki dan novi bios koji bas ovo krpi pa da vidim ako je nesto ostalo busno...

isto je i kod mene :d
 

Prilozi

  • Screen Shot 2018-01-15 at 7.54.41 PM.png
    Screen Shot 2018-01-15 at 7.54.41 PM.png
    44.5 KB · Pregleda: 78
Poslednja izmena:
Ovo znaci da je sve ok ili probati sa jos nekim programom?

SS.jpg
 
I kod mene raspad sistema, a bas nemam ni volje ni vremena da ganjam sisteme i peceve.

7edtCm2.png
 
Nijedan distro nema kompletne patcheve za Spectre 1/2.
 
Za određene distroe i CPU-e, može se dodati mikrokod.

Linux Processor Microcode Data File

Intel Processor Microcode Package for Linux
20180108 Release

-- Updates upon 20171117 release --
IVT C0 (06-3e-04:ed) 428->42a
SKL-U/Y D0 (06-4e-03:c0) ba->c2
BDW-U/Y E/F (06-3d-04:c0) 25->28
HSW-ULT Cx/Dx (06-45-01:72) 20->21
Crystalwell Cx (06-46-01:32) 17->18
BDW-H E/G (06-47-01:22) 17->1b
HSX-EX E0 (06-3f-04:80) 0f->10
SKL-H/S R0 (06-5e-03:36) ba->c2
HSW Cx/Dx (06-3c-03:32) 22->23
HSX C0 (06-3f-02:6f) 3a->3b
BDX-DE V0/V1 (06-56-02:10) 0f->14
BDX-DE V2 (06-56-03:10) 700000d->7000011
KBL-U/Y H0 (06-8e-09:c0) 62->80
KBL Y0 / CFL D0 (06-8e-0a:c0) 70->80
KBL-H/S B0 (06-9e-09:2a) 5e->80
CFL U0 (06-9e-0a:22) 70->80
CFL B0 (06-9e-0b:02) 72->80
SKX H0 (06-55-04:b7) 2000035->200003c
GLK B0 (06-7a-01:01) 1e->22

-- Microcode update instructions --
This package contains Intel microcode files in two formats:
* microcode.dat
* intel-ucode directory

microcode.dat is in a traditional text format. It is still used in some
Linux distributions. It can be updated to the system through the old microcode
update interface which is avaialble in the kernel with
CONFIG_MICROCODE_OLD_INTERFACE=y.

To update the microcode.dat to the system, one need:
1. Ensure the existence of /dev/cpu/microcode
2. Write microcode.dat to the file, e.g.
dd if=microcode.dat of=/dev/cpu/microcode bs=1M

intel-ucode dirctory contains binary microcode files named in
family-model-stepping pattern. The file is supported in most modern Linux
distributions. It's generally located in the /lib/firmware directory,
and can be updated throught the microcode reload interface.

To update the intel-ucode package to the system, one need:
1. Ensure the existence of /sys/devices/system/cpu/microcode/reload
2. Copy intel-ucode directory to /lib/firmware, overwrite the files in
/lib/firmware/intel-ucode/
3. Write the reload interface to 1 to reload the microcode files, e.g.
echo 1 > /sys/devices/system/cpu/microcode/reload
 
Meni je na Kubuntu 17.10 stigao redovnim udpate-om:

[ 0.000000] microcode: microcode updated early to revision 0xc2, date = 2017-11-16

C2 bi trebalo da je aktuelna verzija za 6700K.
 
Poslednja izmena:
Za određene distroe i CPU-e, može se dodati mikrokod.

A šta kod tebe pokazuje dmesg | grep microcode?

Zbunjuje me ovaj novembarski datum.

Kod:
dmesg | grep microcode
[    0.000000] microcode: microcode updated early to revision 0x23, date = 2017-11-20
[    0.835352] microcode: sig=0x306c3, pf=0x2, revision=0x23
[    0.835383] microcode: Microcode Update Driver: v2.2.
 
Poslednja izmena:
@dolmen

I kod mene je isto kao kod tebe. Devuan Ceres (unstable), i5 4460.
 
[Pogledajte prilog 245218

Kod mene će još malo pa stući i sve podvarijante(Mint 18.1, kernel 4.13.0-32, microcode 3.20180108.0+relly20170707(Haswell)) :D
 
Poslednja izmena:
Nazad
Vrh Dno