Click here to Skip to main content
15,895,011 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: Desktop Application Development Pin
Munchies_Matt3-May-17 3:20
Munchies_Matt3-May-17 3:20 
NewsThe alarming state of secure coding neglect Pin
Kent Sharkey2-May-17 8:23
staffKent Sharkey2-May-17 8:23 
GeneralRe: The alarming state of secure coding neglect Pin
raddevus2-May-17 8:48
mvaraddevus2-May-17 8:48 
GeneralRe: The alarming state of secure coding neglect Pin
Rick York2-May-17 9:36
mveRick York2-May-17 9:36 
GeneralRe: The alarming state of secure coding neglect Pin
Mark_Wallace2-May-17 10:12
Mark_Wallace2-May-17 10:12 
NewsIntel patches remote code-execution bug that lurked in chips for 10 years Pin
Kent Sharkey2-May-17 8:21
staffKent Sharkey2-May-17 8:21 
GeneralRe: Intel patches remote code-execution bug that lurked in chips for 10 years Pin
Rick York2-May-17 9:38
mveRick York2-May-17 9:38 
GeneralRe: Intel patches remote code-execution bug that lurked in chips for 10 years Pin
Randor 5-May-17 20:21
professional Randor 5-May-17 20:21 
Hi Rick,

Not sure why you felt the need to downplay this security issue. I refrained from replying initially... and decided to wait until this thread left the front page.

If you have a recent Intel processor[^]... there is a second ARC SoC[^] on the chip running the ThreadX operating system[^].

As it turns out... all you need to do is pass a NULL hash in the HTTP authentication header[^] to gain complete control of any machine on the network managed via AMT.

Let me put this into perspective... Microsoft[^], Google and thousands of other companies are utilizing Intel AMT[^] on some employee devices... including R&D software engineers. Someone could walk into the guest lobby... connect to the guest WiFi and potentially connect to any AMT enabled device on the network and clone the hard drives. AMT enabled devices listen on port 16992 and this port is generally whitelisted to allow system administrators access to employee machines on all networks.


Best Wishes,
-David Delaune

modified 6-May-17 2:33am.

NewsThe IT worker bucket list: 40 things tech pros wish for Pin
Kent Sharkey2-May-17 8:16
staffKent Sharkey2-May-17 8:16 
NewsMinecraft: Education Edition is getting a Code Builder tool to help teach coding skills Pin
Kent Sharkey2-May-17 6:58
staffKent Sharkey2-May-17 6:58 
NewsWindows 10 S is Microsoft's answer to Chrome OS Pin
Kent Sharkey2-May-17 6:56
staffKent Sharkey2-May-17 6:56 
GeneralRe: Windows 10 S is Microsoft's answer to Chrome OS Pin
Afzaal Ahmad Zeeshan2-May-17 7:33
professionalAfzaal Ahmad Zeeshan2-May-17 7:33 
GeneralRe: Windows 10 S is Microsoft's answer to Chrome OS Pin
Mark_Wallace2-May-17 10:06
Mark_Wallace2-May-17 10:06 
GeneralWindows RT 2.0 is Microsoft's answer to Chrome OS Pin
David O'Neil2-May-17 7:48
professionalDavid O'Neil2-May-17 7:48 
GeneralRe: Windows 10 S is Microsoft's answer to Chrome OS Pin
Mark_Wallace2-May-17 10:30
Mark_Wallace2-May-17 10:30 
GeneralRe: Windows 10 S is Microsoft's answer to Chrome OS Pin
James_Parsons2-May-17 11:01
James_Parsons2-May-17 11:01 
GeneralRe: Windows 10 S is Microsoft's answer to Chrome OS Pin
Dan Neely3-May-17 2:24
Dan Neely3-May-17 2:24 
NewsOn Phone Numbers and Identity Pin
Kent Sharkey1-May-17 12:13
staffKent Sharkey1-May-17 12:13 
QuestionRe: On Phone Numbers and Identity Pin
Peter_in_27801-May-17 15:09
professionalPeter_in_27801-May-17 15:09 
AnswerRe: On Phone Numbers and Identity Pin
Kent Sharkey1-May-17 15:34
staffKent Sharkey1-May-17 15:34 
Newswhat our Silicon Masters learned from the Dark Lords of Psyche-Irrational ? Pin
BillWoodruff1-May-17 11:47
professionalBillWoodruff1-May-17 11:47 
GeneralRe: what our Silicon Masters learned from the Dark Lords of Psyche-Irrational ? Pin
Mark_Wallace2-May-17 5:28
Mark_Wallace2-May-17 5:28 
NewsStudy finds gender bias in open-source programming Pin
Kent Sharkey1-May-17 11:19
staffKent Sharkey1-May-17 11:19 
GeneralRe: Study finds gender bias in open-source programming Pin
Tony Foo1-May-17 17:16
professionalTony Foo1-May-17 17:16 
GeneralRe: Study finds gender bias in open-source programming Pin
Sander Rossel1-May-17 21:38
professionalSander Rossel1-May-17 21:38 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.