same thread, different exploit.

https://github.com/xoreaxeaxeax/skitter-creek-bath-salts

This kind of thing is why I hope I can avoid the x86 from now on -- the x86
is a combination of lots of vulns + security through obscurity that's an
absolute fun time for attackers.

On Thu, Aug 13, 2026 at 9:18 AM ron minnich <[email protected]> wrote:

> one last note, if you get interested, search for
> SMM exploit
> if you love UEFI word salad, you'll like what you see!
>
> Be aware that the total number of bugs probably is far larger than the
> number disclosed. Both "threat actors" and vendors have an interest in
> not disclosing exploits.
>
> It's interesting how many bugs come from the people who make our systems.
> A lot of it comes from the mind-numbing complexity of it all. One very
> smart group of people I know wrote an SMM callout bug (look that up too)
> that lived in their UEFI firmware for 15 years.
>
> On Thu, Aug 13, 2026 at 8:39 AM Jiji Freya Daniel Maslowski via 9fans <
> [email protected]> wrote:
>
>> SMM is a processor mode, entered via SMIs, as Dan Cross explains.
>>
>> The BMC on server boards, or co-processor (Intel ME, AMD ASP/formerly
>> PSP), as well as other similar designs on other boards, are meant to offer
>> out-of-band management by virtue of being separate processing units -
>> connected to the main processing units' reset lines, possibly the same
>> memory bus(es) and other peripherals (e.g., network adapters). That is how
>> they make it possible to offer KVM, serial over network, attach virtual
>> disks, perform resets, etc.
>>
>> On Thu, 13 Aug 2026, 10:16 Ethan Azariah, <[email protected]> wrote:
>>
>>> On Wed, Aug 12, 2026, at 9:15 PM, Lyndon Nerenberg (VE7TFX/VE6BBM) wrote:
>>> > Ethan Azariah writes:
>>> >
>>> >> SMM is for when a node in your supercomputer goes down, right at the
>>> far en=
>>> >> d of the building. You can use SMM to reboot it rather than walking
>>> over th=
>>> >> ere. Why it's enabled in consumer machines, I don't want to know.=20
>>> >
>>> > I think you are confusing SMM with IPMI.
>>> 
>>> /search, read--/ I think you're right. Could SMM function as an IPMI
>>> baseboard management controller and interface?
>> *9fans <https://9fans.topicbox.com/latest>* / 9fans / see discussions
>> <https://9fans.topicbox.com/groups/9fans> + participants
>> <https://9fans.topicbox.com/groups/9fans/members> + delivery options
>> <https://9fans.topicbox.com/groups/9fans/subscription> Permalink
>> <https://9fans.topicbox.com/groups/9fans/T496d301e510c8cf1-Mf688aa8a9691dfe2c5c9ac10>
>>

------------------------------------------
9fans: 9fans
Permalink: 
https://9fans.topicbox.com/groups/9fans/T496d301e510c8cf1-Mb57efb59106b6014345a02b1
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

Reply via email to