Just in:
Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // UN Acknowledges Uneven Progress on Energy Goals During Sustainability Week // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Sharjah Charity International Extends Helping Hand to Flood Victims // Emirates Offer Support as Wildfires Ravage Greece // Evolution and current state of global crypto adoption – Octa // UAE Delegation Engages in Arab Parliament Committee Discussions // VT Markets Releases Study on Upcoming Bitcoin Halving and Market Implications // Boeing Eyes 2030 Launch for Electric Flying Cars // Keung To Trams Return! “KeungShow HKFanClub” Sponsor Free Tram Rides for All on 30 April to Celebrate Keung To’s 25th Birthday // Czar Workspace: a Modern Workspace Solutions in Dubai // Tech Giant Discharges Workers Following Disruptive Protest // Global Cooperation Takes Center Stage at Dubai International Humanitarian Aid and Development Conference and Exhibition // Saadiyat Grove Set for Smart Transformation Through Aldar-Siemens Alliance // Congress Is Set To Perform Well In Lok Sabha Polls In Karnataka // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // AI Race Heats Up: Meta Unveils Powerful New Llama // Gen Zs Trust User and Expert Insights on Shopee // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field //

Intel chip vulnerability lets hackers easily hijack fleets of PCs

wafer

https://thearabianpost.com/wp-content/uploads/2017/05/1494206198_931_www.zdnet.com

(Image: file photo)

A vulnerability in Intel chips that went undiscovered for almost a decade allows hackers to remotely gain full control over affected Windows PCs without needing a password.

The “critical”-rated bug, disclosed by Intel last week, lies in a feature of Intel’s Active Management Technology (more commonly known as just AMT), which allows IT administrators to remotely carry out maintenance and other tasks on entire fleets of computers as if they were there in person, like software updates and wiping hard drives. AMT also allows the administrator to remotely control the computer’s keyboard and mouse, even if the PC is powered off.

ADVERTISEMENT

To make life easier, AMT was also made available through the web browser — accessible even when the remote PC is asleep — that’s protected by a password set by the admin.

The problem is that a hacker can enter a blank password and still get into the web console, according to independent technical rundowns of the flaw by two security research labs.

Embedi researchers, credited with finding the bug, explained in a whitepaper posted Friday that a flaw in how the default “admin” account for the web interface processes the user’s passwords effectively lets anyone log in by entering nothing at the log-on prompt.

“No doubt it’s just a programmer’s mistake, but here it is: keep silence when challenged and you’re in,” said the researchers.

https://thearabianpost.com/wp-content/uploads/2017/05/1494206198_931_www.zdnet.com

(Image: Intel)

Tenable researchers confirmed the findings in a detailed analysis of the flaw, also posted Friday, saying it was relatively easy to remotely exploit.

Intel’s advisory said that systems — including desktops, laptops, and servers — dating back as early as 2010 and 2011 and running firmware 6.0 and later are affected by the flaw.

But Embedi warned that any affected internet-facing device with open ports 16992 and 16993 are at risk. “Access to ports 16992/16993 are the only requirement to perform a successful attack,” said the Embedi researchers.

Since the disclosure, monitors have seen a spike in port probing activity on the two affected ports.

https://thearabianpost.com/wp-content/uploads/2017/05/1494206198_931_www.zdnet.com

(Image: Sans Institute)

Intel so far hasn’t said how many devices are affected.

However, a search on Shodan, the search engine for open ports and databases, shows more than 8,500 devices are vulnerable at the time of writing, with almost 3,000 in the US alone — but there could be thousands more devices at risk on internal networks.

https://thearabianpost.com/wp-content/uploads/2017/05/1494206198_931_www.zdnet.com

(Screenshot via Shodan)

In a statement, Intel said that it’s working with its hardware partners to address the problem, and “expect computer-makers to make updates available beginning the week of May 8 and continuing thereafter.”

So far, Dell, Fujitsu, HP, and Lenovo have all issued security advisories and have issued guidance on when they will roll out fixes to their customers. Consumer devices aren’t affected by the bug.

The chipmaker has also published a discovery tool to determine if machines are affected.

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
NEOM welcomes leading industry figures and investors to Hong Kong showcase as part of its ‘Discover NEOM’ China tour // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // Czar Workspace: a Modern Workspace Solutions in Dubai // Global Energy Leaders Chart Course for Sustainable Future at IRENA Assembly // DFA Hong Kong Young Design Talent Award 2024 // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // Boeing Eyes 2030 Launch for Electric Flying Cars // Sharjah Charity International Extends Helping Hand to Flood Victims // Abu Dhabi Environment Agency Endorses ADNOC’s Decarbonization Push // Global Cooperation Takes Center Stage at Dubai International Humanitarian Aid and Development Conference and Exhibition // VT Markets Releases Study on Upcoming Bitcoin Halving and Market Implications // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // The International Exhibition of Inventions in Geneva Reveals More than 40 Scientific and Technological Innovation Achievements from Hong Kong // Tech Giant Discharges Workers Following Disruptive Protest // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field // Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // Petrochemical Storm Clouds Gather Over Saudi Arabia // Emirates Offer Support as Wildfires Ravage Greece // AI Race Heats Up: Meta Unveils Powerful New Llama // Keung To Trams Return! “KeungShow HKFanClub” Sponsor Free Tram Rides for All on 30 April to Celebrate Keung To’s 25th Birthday //