same thread, different exploit. https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
This kind of thing is why I hope I can avoid the x86 from now on -- the x86 is a combination of lots of vulns + security through obscurity that's an absolute fun time for attackers. On Thu, Aug 13, 2026 at 9:18 AM ron minnich <[email protected]> wrote: > one last note, if you get interested, search for > SMM exploit > if you love UEFI word salad, you'll like what you see! > > Be aware that the total number of bugs probably is far larger than the > number disclosed. Both "threat actors" and vendors have an interest in > not disclosing exploits. > > It's interesting how many bugs come from the people who make our systems. > A lot of it comes from the mind-numbing complexity of it all. One very > smart group of people I know wrote an SMM callout bug (look that up too) > that lived in their UEFI firmware for 15 years. > > On Thu, Aug 13, 2026 at 8:39 AM Jiji Freya Daniel Maslowski via 9fans < > [email protected]> wrote: > >> SMM is a processor mode, entered via SMIs, as Dan Cross explains. >> >> The BMC on server boards, or co-processor (Intel ME, AMD ASP/formerly >> PSP), as well as other similar designs on other boards, are meant to offer >> out-of-band management by virtue of being separate processing units - >> connected to the main processing units' reset lines, possibly the same >> memory bus(es) and other peripherals (e.g., network adapters). That is how >> they make it possible to offer KVM, serial over network, attach virtual >> disks, perform resets, etc. >> >> On Thu, 13 Aug 2026, 10:16 Ethan Azariah, <[email protected]> wrote: >> >>> On Wed, Aug 12, 2026, at 9:15 PM, Lyndon Nerenberg (VE7TFX/VE6BBM) wrote: >>> > Ethan Azariah writes: >>> > >>> >> SMM is for when a node in your supercomputer goes down, right at the >>> far en= >>> >> d of the building. You can use SMM to reboot it rather than walking >>> over th= >>> >> ere. Why it's enabled in consumer machines, I don't want to know.=20 >>> > >>> > I think you are confusing SMM with IPMI. >>> >>> /search, read--/ I think you're right. Could SMM function as an IPMI >>> baseboard management controller and interface? >> *9fans <https://9fans.topicbox.com/latest>* / 9fans / see discussions >> <https://9fans.topicbox.com/groups/9fans> + participants >> <https://9fans.topicbox.com/groups/9fans/members> + delivery options >> <https://9fans.topicbox.com/groups/9fans/subscription> Permalink >> <https://9fans.topicbox.com/groups/9fans/T496d301e510c8cf1-Mf688aa8a9691dfe2c5c9ac10> >> ------------------------------------------ 9fans: 9fans Permalink: https://9fans.topicbox.com/groups/9fans/T496d301e510c8cf1-Mb57efb59106b6014345a02b1 Delivery options: https://9fans.topicbox.com/groups/9fans/subscription
