Looking for someone here smarter than me on AMI Uefi's

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • M3038
    New Member
    • Jun 2022
    • 5
    • United states

    #1

    Looking for someone here smarter than me on AMI Uefi's

    Hello,

    So, first off thanks for having me. I've been a ways off in the distance observer for quite some time now and figured i'd give this a shot.

    So, sparing everyone the gory details i'm in a situation where.. the best way to put it is, my machines are not managed by me. Not a corporation, or place of business either. Think bad guys.

    These bad guys have either completely imaged and overwritten a bad guy image to my device(s) and over the course of the past few days and weeks i'm inching closer to smoking these chuckleheads out. Just today i finally gained the initiative with the discovery of "manufacturer mode".

    Recently i've been sequestered into using just ISO and DVD's to get an OS running, as USB drives tended to be fraile and easily manipulatable in this context. And with that have founded OpenSUSE as being rock solid and essentially fits my bill for the environment. And OpenSUSE reports that my TPM is nonexistent, my firmware is incorrect, and my manufacturing mode is unlocked (amongst many other things).

    Now looking into manufacturing mode it's generally accepted that Alt + (choose whatever F key here) are the open sesame to either locking or unlocking manufacturing bios. Now, to give a little bit more context when i say my devices are managed by some one other than me what i really mean is someone has access to and regularly exercises root privelages over me. They have this privilege across all levels of a machine. From the second i start any of them can even see them configuring them if you have the right equipment. This extends to all operating systems and all scenarios. I'll cut the details here and get down to my question.

    I need to find the open sesame or an alternative way into the AMI bios. This is with the serial ports (all of them) seemingly disabled and also with any attempt at flashing the bios nothing but kabuki theater. The only thing that seems to have any effect is just pure tempo, i.e wearing it out.

    These jokers like to live in
    memory and subvolumes of my installed operating systems and essentially let themselves in at any time. But anything to do with virtual machines or memory fundamentally is that it is effected by entropy. The problem is the next day they literally just reflash the system back to their likint and i'm back at square one.

    As i said today i did get s little momentum though. Finding that obnoxiously pressing Alt + F1 and F2 threw off the boot sequence, and then subsequently had me booting to their instance (albeit encrypted, with a one shot chance). I was able to cause some havoc with their config files and delete some modules but that was it; but it was enough to at least bloody a nose as now i can see literally all their little rat tunnels. But, i have no way of capitalizing.

    I have tried:
    • The entire suite of AMI flash utilities and debuggers
      Flashing via the bios
      Via the OS using a slew of different tools and utilities including flashrom and have even gone as far as building a cool little fleet of arduino's. Nothing has worked.


    So, how do i regain soverienty back over my own machines? I'm mainly looking for an administrator login secret back door so to speak. Anyone have any insight??

    Thanks in advance!
  • diif
    Badcaps Legend
    • Feb 2014
    • 6978
    • England

    #2
    Re: Looking for someone here smarter than me on AMI Uefi's

    What makes you think it's compromised?

    Comment

    • M3038
      New Member
      • Jun 2022
      • 5
      • United states

      #3
      Re: Looking for someone here smarter than me on AMI Uefi's

      Originally posted by diif
      What makes you think it's compromised?
      Six months of torment up to and including my phone number repeatedly disappearing from my tmobile account, the chuckleheads showing up, flashing new firmware on my router (almost a daily occurrence) and then running multiple virtual LAN and bridge connections. Or maybe it could be the fact that every. Single. Device. I've owned over the past six months ends up inoperable, sometimes within hours. Mainly by what is described above.

      This has been my nightmare dude. And there's always someone who wants to argue the merits of my own experience instead of answer the question at hand. I'll preemptively tell you what i tell everyone else who barks up that tree: come fine out. Either via Zoom, or another virtual way or you can feel free to remote in and stop by. Every day's more interesting than the last so there's plenty to see.

      Comment

      • diif
        Badcaps Legend
        • Feb 2014
        • 6978
        • England

        #4
        Re: Looking for someone here smarter than me on AMI Uefi's

        What device is it ? What's your network set up ?

        Comment

        • M3038
          New Member
          • Jun 2022
          • 5
          • United states

          #5
          Re: Looking for someone here smarter than me on AMI Uefi's

          Originally posted by diif
          What device is it ? What's your network set up ?
          The one i'm writing about specifically is an MSI Z690 Unify. I have an additional two other MSI boards. So one rock three birds.

          As per the network *currently* it's simplified down to a Netgear CM500 modem, R6900 router, and a TP Link ER605. We've already burned out two modems and dumped two other routers trying to dump whoever/whatever this is. Isp is Comcast with DHCP. I have noIP enabled on both routers as well as VPN's and the TPLink actually has a pretty cool suite of attack countermeasures as well. Pretty neat to watch over wireshark.

          Thank you for taking my sharp response last night on the chin, it has been a long few days/nights. I appreciate you letting it glance off.

          Edit: since you brought it up; the router is the 50 yard line or the DMZ. We're constantly going back and forth over it. I finally, after three months of trying was able to pull the debug logs and oh boy. Let's just say i'm getting a further crash course in UDP, bridges, vlan, and tor.

          Comment

          Related Topics

          Collapse

          • Robin21
            LA-L051P Changing ME Region
            by Robin21
            Hallo,

            I've replaced Intel CPU SRKH5 with burned PCH on the LA-L051P with SRKH4 (i7-11370H to i7-11375H) and now I see that this was the easy part.


            Now I need to replace ME Region using this from the donor board - 15.0.47.2473 and need help from smarter people than me.




            The only ME in version 15.0.47.2473 I've found has 3,125,248 byes, which is strange size.



            Using HxD and selecting 465000, selection ends in the middle of code to check the size of extracted ME. It doesn't seem to be right.

            ...
            02-13-2025, 03:22 AM
          • malekservis
            Philips 58PUS8536/12 Backlight ok, no image
            by malekservis
            Hello,
            the TV turns on fine, seems to be working, but shows no image outside of a thick white vertical line as it turns on that also disappears almost instantly, and then it's just backlight. I've tried unplugging either side, but still can't get an image. I suspect it's a panel issue, but thought i'd ask some smarter people to confirm. I haven't found any weird readings, but then again i'm just randomly poking around with a multimeter.

            Any information would be appreciated....
            08-07-2024, 07:48 AM
          • kokodin
            memory mod for amd radeon r7 260x
            by kokodin
            Hello, for almost a year i been trying to make something that seems impossible, or my testing software is lying to me and it works only i can't see that.
            I been trying to mod a memory on radeon hd7790 or 260x from 2 to 4 gb, but it doesn't seems to be as simple as i first thought.
            In theory 2 workstation graphic cards using the same graphical processor have 4gb of memory firepro w4300 has 4 256x32b layout and W5100 has 8x 128x16b layout all use gddr5 memory and internals of the bioses seems to be very similar so i was trying to wing it , but so far it seems either tserver can't show...
            03-28-2024, 03:48 PM
          • Xabi
            Pioneer PD-F1007 CD player not reading
            by Xabi
            Hi guys, I need some help with a CD player. It is a pioneer PD-F1007


            The issue is that it doesn't play any disks. The disk gets loaded, spins up, but it doesn't actually plays. Just keeps spinning until I stop it.

            If I put in the CD the wrong way, it will eject it quite quickly, so the unit at least understands that a CD is in and if it's in the correct orientation, tries to read it, but for some reason it can't.

            I started with cleaning the lens to be sure, but ofc that didn't help. Also the laser is ligthing up at least, so it's not totally...
            06-19-2023, 03:15 PM
          • l0lhaxz1
            QN65QN90A - Mainboard MLCC failed - now bootloop
            by l0lhaxz1
            Hi

            I have a QN65QN90A which was purchased around launch I guess making it about 1.5-2 years old... had been working fine until a few days ago, simply went black and would no longer turn on (at all). No standby light and no typical PSU relay click etc. Absolutely dead.

            Pulled it apart without doing much research first, suspecting the power supply as it had a faint buzz (I guess due to the forthcoming found short), investigated PSU for some time and concluded there was no fault that I could spot with the board removed.

            Came to learn after a bit more research...
            02-06-2023, 08:59 AM
          • Loading...
          • No more items.
          Working...