@InfPCTechStacki
iAccount based inJapan
About this account
- Account based in
- Japan
- Connected via
- Japan App Store
Account-level information from X, not a live location or the device used for a specific post.
Security Researcher, UEFI, Kernel, Hypervisor, SMM (RT is mainly for me to read them later...)
Ring Minus Security
Joined April 2019
- Tweets1.1K
- Following226
- Followers438
- Likes330
CODE BLUE 2026 (Technical)にて発表します
既存の UEFI マルウェアの多くは Windows VBS 等のハイパーバイザーセキュリティが有効な現代の PC では動作できない中、動作できる手法とその対策について話します
codeblue.jp/en/program/time-…
#codeblue_jp #codeblue2026
発表1カ月前である今年 10月に VBS の HVCI 機能がデフォルトで有効となります
HVCI は UEFI マルウェアの妨害にも(偶然)繋がっていたのですが、この攻撃でバイパスできてしまうという発表です
この攻撃を検知するための重要な観点も合わせて発表します
gigazine.net/news/20260903-e…
MachineHunter retweeted
BIOS 自作 について定期的に書いてるが、再現環境作るの大変だと思うので、実際どうやってるか動画作りました youtu.be/u557BsjcRXw?si=f9JS… @YouTubeより
MachineHunter retweeted
深夜テンションで書き上げた
最近のCPUはいろいろ難しい
note.com/tarori98/n/n6c3dcd7…
MachineHunter retweeted
Missed DEFCON 34?
Here you go with all slides and content:
media.defcon.org/DEF%20CON%2…
MachineHunter retweeted
How CPU Power Delivery Works?
youtu.be/Nw7zImgnMRs
Near the CPU socket, you will normally find one or two eight-pin CPU power connectors.
These connectors receive 12-volt power from the computer’s power supply.
However, the CPU cores operate at much lower voltages and require extremely precise power regulation.
The 12-volt input cannot be sent directly to the processor.
The components surrounding the CPU socket form the voltage regulator module, commonly called the VRM.
A VRM usually includes:
A PWM controller
Power stages or MOSFETs
Inductors
Capacitors
Monitoring and protection circuits
The VRM converts the incoming 12-volt supply into the lower voltages required by the CPU.
It also supplies very large amounts of current while keeping the output voltage stable.
You can think of the VRM as a dedicated power conversion station for the processor.
When the CPU is idle, the power delivery system reduces its output.
When the CPU enters a heavy workload, the VRM must rapidly increase current while minimizing voltage fluctuations.
Modern high-performance processors can draw a great deal of current. For this reason, motherboards often use multiphase VRM designs.
Instead of forcing a single power stage to handle the entire load, multiple phases share the work. This can reduce stress on individual components, improve efficiency, distribute heat, and help maintain voltage stability.
However, the advertised number of power phases does not tell the whole story.
Motherboard quality also depends on:
Power stage current ratings
Controller design
VRM cooling
PCB quality
Thermal performance
Firmware tuning
Real-world testing
The MSI MEG Z790 GODLIKE MAX uses a high-end power delivery design intended for powerful processors and demanding workloads.
Most users do not need such an extreme VRM.
A motherboard only needs to provide stable and adequate power for the processor that will actually be installed.
MachineHunter retweeted
Embedded Systems & SoC Course
Added the first three lecture here: youtube.com/playlist?list=PL…
Will add more tomorrow :)
MachineHunter retweeted
Secure Boot is designed to keep attackers out.
This training shows you how attackers get in. 👀
Learn to identify weaknesses in Secure Boot implementations with @pulsoid at Hardwear.io Netherlands 2026.
🎟️ Register now: hardwear.io/trainings/nl-202…
#HardwearNL2026
MachineHunter retweeted
Paper
Firmware as the Next Frontier for Computing Security: Challenges and Opportunities [IEEE Security & Privacy 2026]
ieeexplore.ieee.org/abstract…
タイトルが刺激的。購入した。
一般的な解説だがAIによるFirmware Engineeringは興味がある。
MachineHunter retweeted
プリント基板設計をAIにやらせてみた。
ClaudeとEasyEDAを使うと回路図書き、部品選定、レイアウトまで自動でやってくれました。
キーボードを設計してもらいましたが2時間位で設計完了 → PCBA発注となりました。
MachineHunter retweeted
global.fujitsu/ja-jp/technol…
> お客様の環境や要件に合わせた性能評価、およびアプリケーションの動作検証を行っていただけるよう、2026年夏頃より検証機によるトライアルをご提供開始予定です。
!!!
MachineHunter retweeted
Want to learn more about #UEFI technology?
Recordings and presentation slides from previous #UEFIForum events covering post-quantum cryptography, #BIOS innovation and more are available on our website.
Explore the UEFI Presentations and Videos page: bit.ly/4gYxz3R
MachineHunter retweeted
DellのBIOSパスワードがXOR暗号で保存され、短いパスワードでは暗号化に使った鍵まで保存値の中に漏洩しているため、物理アクセスだけで元のパスワードを即時復元できるとの研究報告です。
32バイトの保存フィールドに対し鍵が20バイトしかなく、パスワードが12文字以下の場合、未使用のヌルパディングから鍵全体がそのまま読み取れます。ハッシュ化ではなく可逆なXOR暗号であること自体が根本的な問題で、CVE-2026-40639としてDellが公表しています。
CVSS基本値はDell側の5.7に対し発見者側は6.1で、相違はAttack-Complexity(攻撃の複雑さ)の1点(DellはHigh、発見者側はLow)のみです。
【要点の整理】
・Dell公式の分類は「パスワードの弱いエンコード方式」(Weak Encoding for Password)で、物理アクセス前提・事前権限不要のCVSSベクトル。Dellはパスワードの長さ次第で復元できるかが変わる点をAttack Complexity=Highの根拠に挙げるが、発見者側は12文字以下で確定的としてLowを主張。
・パスワードは32バイトのフィールドに20バイトの鍵を繰り返し当てるXOR暗号化で、先頭1文字は平文のまま保存。12文字以下ではヌルパディングから鍵全体が漏洩し即時復元可能。鍵は先頭1バイトと端末固有のシード値から導出され1台あたり最大256通りで、旧パスワードが消去されずフラッシュに残るため短い旧パスワード経由でも復元される構造。
・Dell勧告(DSA-2026-197)の修正対象はEdge Gateway、Embedded PC、Latitude、OptiPlex、Precisionの特定モデルで、7月13日に最終版へ改訂。研究者が実機確認した4モデル(Latitude E7250、Wyse 5070、Latitude 7490、XPS 15 9560)はいずれも含まれておらず、うちE7250とXPS 15 9560はEOL(サポート終了)で修正対象外。残りは7月末修正を目指すとの報告。Dellは対応表が全モデルを網羅したものではなく今後更新される可能性があると注記しており、新世代モデルはSHA-256ベースの保存方式に移行済み。
・BIOSパスワード復元によりSecure Boot無効化やブート順序変更が可能になり、BitLocker等のディスク暗号化への攻撃の足がかりになり得るとの分析。ただしTPMの紐付け方式やPCRの測定対象によって実際の影響は異なるとの留保。
公式勧告の対象表と、発見者が実機で確認した4モデルは範囲が一致していない状況です。
詳細は以下を参照:
Dellのセキュリティ勧告:
dell.com/support/kbdoc/en-us…
発見側の技術分析:
blog.amberwolf.com/blog/2026…
(※可能な範囲でファクトチェックは実施済なものの、元記事の精度依存や速報・要約の性質上漏れもありうるため、正確な情報は一次情報を直接参照のこと)
MachineHunter retweeted
gm, go watch sl0p.foo/s/qkaiser - Making Broadcom Wi-Fi Firmware Boot in QEMU - ThreadX Reverse Engineering
MachineHunter retweeted
日本と NVIDIA は、フィジカル AI を対象とした世界初となる国家 AI インフラを構築します。経済産業省の支援の下、Noetra と連携した NVIDIA Vera Rubin AI ファクトリーが、製造、ロボティクス、ヘルスケアをはじめとする産業を強力に牽引します。日本の次の産業革命が、今ここから始まります。
MachineHunter retweeted
We wrote up how we hunt U-Boot vulnerabilities at scale.
Once extracted from a firmware image, U-Boot is a bare-metal blob with no symbols or metadata, and it ships in 1,500+ build configurations. Our blog covers rebuilding that raw blob into an analysable synthetic ELF and writing reliable VulHunt rules to tell vulnerable and patched versions apart.
Check the technical details: binarly.io/blog/hunting-u-bo…
MachineHunter retweeted
#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at welivesecurity.com/en/eset-r… @smolar_m 1/5
MachineHunter retweeted
【Ring-101 開始】
初学者向けに、OSより下のレイヤーのセキュリティを X のポストで短く紹介する「Ring-101」を開始します。
毎月第2・4水曜日に投稿予定です。
初回は今月第4水曜日です。興味のある方はぜひフォローしてください。
#RingMinus
MachineHunter retweeted
ハイパーバイザーやHVCI(Hypervisor-protected-Code-Integrity、仮想化ベースのコード整合性保護)の内部を、実装・脆弱性エクスプロイト・学習教材の3軸で追えるリソース群がGitHub上で公開されています。HVCIバイパスのCVEやSMM(System-Management-Mode)権限昇格のエクスプロイトまで含まれており、Windowsプラットフォーム防御の仕組みを攻撃側の視点から理解するための資料として読めます。
【要点の整理】
・ハイパーバイザー実装が複数公開されている構成。Intel/AMD両対応の最小実装「barevisor」(Rust、2026年5月更新)、AMD向け教育用「SimpleSvm」とフック機能を加えた「SimpleSvmHook」、EPT(Extended-Page-Tables)を使ったステルスフックでカーネルAPIを監視する「DdiMon」、UEFI上で動作しOSの起動まで対応する研究用「MiniVisorPkg」、Intel-VT-rp(EPTベースのフックに対抗するハードウェア防御)の実装デモ「Hello-VT-rp」など。
・脆弱性研究として、HVCIバイパスのCVE-2024-21305(HVCI環境下でのカーネルメモリ読み書きを実証するRecon-2024デモも別途公開)、Hyper-Vの権限昇格CVE-2023-36427、ASUS製BIOSのカーネル→SMM権限昇格CVE-2021-26943(SmmExploit)のレポートとエクスプロイトが公開されている構成。SMM上でコードを動かす入門教材「HelloSmm」も別途存在。
・UEFI/ファームウェア関連として、DMAリマッピングのプログラミングデモ「HelloIommuPkg」、UEFI変数アクセスの監視「UefiVarMonitor」、Windows-Platform-Binary-Table構築ツール「WPBT-Builder」、UEFIランタイムドライバーのダンプ「kraft_dinner」が公開されている構成。
・学習教材として、1日完結のハイパーバイザー開発コース「Hypervisor-101-in-Rust」、Global-Cybersecurity-Camp-2026ベトナム向け教材「Hypervisors-for-Hackers」、Hyper-V解析用のWinDbg拡張「hvext」が公開。ほかに学習用脆弱ドライバー再実装「capcom」(Rust)とそのエクスプロイト「ExploitCapcom」、IDA用IoControlCodeデコーダー「WinIoCtlDecoder」とVTable名付与ツール「DumpVTable」、リバースエンジニアリング用Pythonスクリプト集も含まれる構成。有料の4日間トレーニング(OffensiveCon・Recon・Hexaconで実績)も別途提供されている。
EDR回避・メモリフォレンジック・Windowsプラットフォーム防御が交差する領域の基盤技術を、実装とCVEの両面から追える資料群です。
詳細は以下を参照:
tandasat.github.io/
github.com/tandasat
(※可能な範囲でファクトチェックは実施済なものの、元記事の精度依存や速報・要約の性質上漏れもありうるため、正確な情報は一次情報を直接参照のこと)