So, what do the authors of the brilliant keyboard mod (hamish, nitrocaster, I am looking at you
Exploiting Lenovo's UEFI vulnerability/backdoor to flash unsigned BIOS
Exploiting Lenovo's UEFI vulnerability/backdoor to flash unsigned BIOS
Dmytro Oleksiuk aka Cr4sh recently documented a privileges escalation vulnerability in Lenovo's EFI code which, among other things, can be used to remove write protection of the BIOS portion of the firmware (the EC portion is already writable, making the keyboard and battery mods possible). Cr4sh went as far as releasing a proof of concept of the vulnerability https://github.com/Cr4sh/ThinkPwn/ and people already started thinking about the possible use case of flashing a whitelist-free bios, at least on *30 generation machines https://github.com/Cr4sh/ThinkPwn/issues/2
So, what do the authors of the brilliant keyboard mod (hamish, nitrocaster, I am looking at you
) think about all this?
DDDDD
So, what do the authors of the brilliant keyboard mod (hamish, nitrocaster, I am looking at you
-
nitrocaster
- Junior Member

- Posts: 400
- Joined: Fri Mar 04, 2016 8:38 am
- Location: Moscow, Russia
Re: Exploiting Lenovo's UEFI vulnerability/backdoor to flash unsigned BIOS
Looks like a nice opportunity. I haven't looked at the BIOS code yet, though.
For those who interested in buying X220/X230 FHD kit: Read this before sending me a PM!
X230: i7-3520M | 16GB RAM | 512GB M.2 Micron M600 | LG LP125WF2-SPB4 FHD IPS | 9c Li-Ion | Win8.1 Pro 64
X230: i7-3520M | 16GB RAM | 512GB M.2 Micron M600 | LG LP125WF2-SPB4 FHD IPS | 9c Li-Ion | Win8.1 Pro 64
-
TheChuckster
- Posts: 38
- Joined: Fri Jan 27, 2017 5:26 pm
- Location: San Francisco, CA
Re: Exploiting Lenovo's UEFI vulnerability/backdoor to flash unsigned BIOS
Depends on how "write protection" works, someone would have to study the BIOS code, and use this exploit to have the UEFI call a custom function that rewrites the firmware (in the escalated privilege level). hamish didn't want to mess with firmware flashing code, understandably so; you end up with tons of bricked hardware along the way until you figure it out. I guess since I have a chip clip and flashing hardware, it's not the end of the world to mess up. Still, someone needs to RE the actual firmware flashing process (hamish took a bit of a look at the EC flashing code).
-
- Similar Topics
- Replies
- Views
- Last post
-
-
Hardware Maintenance Diskette for UEFI BIOS - Replacing S/N on UEFI Machines
by TPCollector » Fri Jan 13, 2017 9:13 pm » in Thinkpad - General HARDWARE/SOFTWARE questions - 10 Replies
- 2358 Views
-
Last post by TPCollector
Sat Jan 14, 2017 7:49 pm
-
-
-
Is Lenovo Diagnostics part of UEFI?
by m4rtin » Thu Mar 02, 2017 3:06 pm » in ThinkPad T430/T530 and later Series - 0 Replies
- 1042 Views
-
Last post by m4rtin
Thu Mar 02, 2017 3:06 pm
-
-
-
X220/X230 to flash or not to flash coreboot after FHD mod
by carcuevas » Sat Jan 14, 2017 7:14 am » in ThinkPad X200/201/220 and X300/301 Series - 22 Replies
- 3312 Views
-
Last post by jaspen-meyer
Fri Apr 14, 2017 9:34 am
-
-
-
safe to flash T500 7VET94WW bios with whitelist bios for 6FET92WW
by TPFanatic » Wed Apr 26, 2017 7:35 pm » in ThinkPad T400/410/420 and T500/510/520 Series - 4 Replies
- 720 Views
-
Last post by TPFanatic
Thu Apr 27, 2017 6:28 pm
-
Who is online
Users browsing this forum: No registered users and 2 guests



