Don’t insert unfamiliar memory cards into your laptop: how SD Express resurrected DMA attacks

Positive Technologies experts reported that attackers can use SD Express memory cards to directly access system memory and hack the target device if they have physical access to it. This is possible thanks to the architectural features of new user devices that connect to the computer and have direct access to its memory through the DMA (Direct Memory Access) mechanism.

Image source: pexels.com

The SD Express standard, developed by the SD Association, combines the SD format with PCIe and NVMe protocols, allowing data transfer speeds of up to 985 MB/s for an SD memory card. To improve performance, which is necessary for working with large media files, PCIe Bus Mastering has been introduced into the standard, allowing SD cards to directly access system memory (DMA). Although this feature is designed to bypass processor bottlenecks to improve speed, it does not provide adequate protection against unauthorized memory access.

It has been determined that if an attacker has physical access to the target device, an attacker can use the DMA mechanism used in SD Express to increase data transfer rates to carry out sophisticated attacks on devices that support this standard. The company’s specialists showed how modified SD Express memory cards can bypass protection mechanisms such as the system IOMMU. This poses a serious threat to laptops, game consoles and other multimedia devices that support the SD Express standard.

Currently, support for the SD Express standard is mainly implemented in high-performance laptops in the premium segment. To attack such devices, attackers can use a specially modified device that looks like a memory card and is compatible with the target hardware interface to gain access to the PCIe bus. As a result, they can read and edit data in the device’s memory, inject malicious code, extract encryption keys and passwords, bypass operating system authentication, and disable security tools.

The company called the type of attacks through the DMA mechanism in SD Express DaMAgeCard. It is noted that in the coming years the standard will strengthen in the market, and its support will be implemented not only in premium laptops, but also in other consumer devices, including computers, video cameras, etc. In this case, DaMAgeCard attacks can become a convenient entry point for attackers, allowing them to attack devices without opening them.

Note that it is possible to protect against DaMAgeCard and similar DMA-based attacks. First, you need to avoid using unfamiliar SD cards. Second, the system can be configured to allow direct memory access only to trusted devices. Experts also recommend regularly checking connected devices, regularly updating firmware, implementing verification of SD Express cards using cryptographic signatures, and activating IOMMU on all PCIe-enabled devices.

admin

Share
Published by
admin

Recent Posts

Former top manager of Intel headed the second largest Chinese chip manufacturer

Hua Hong Semiconductor, China's second-largest chip maker, has made a strategic leadership reshuffle with the…

11 minutes ago

“Nothing can be cooler than this”: the creators of Phantom Blade Zero amazed gamers with new gameplay

On the occasion of the approaching Lunar New Year, developers from the Chinese studio S-Game…

11 minutes ago

Microsoft has joined the CISPE cloud alliance, which has been fighting it for years

Microsoft has become a new member of the CISPE association, which unites mainly small cloud…

2 hours ago

Nvidia said that GeForce RTX 5000 video cards will not have connectors that melt

At the recent GeForce Editors Day press event in South Korea, Nvidia said that the…

2 hours ago

GeForce RTX 5000 video cards will be in short supply and this will not last long, Nvidia partners warned

Nvidia's GeForce RTX 5000 family of graphics cards, introduced at the beginning of the month,…

3 hours ago