Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
4 changes: 3 additions & 1 deletion .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -54,8 +54,10 @@ repos:
- id: bes-conventions-check
args: ["--auto-fix=yes", "--errors-only"]
- id: bes-actionscript-lint-schclass
args: ["--strict"]
# args: ["--strict"]
- id: bes-actionscript-validate-prefetch
args: ["--disable", "E401"]

- id: bes-actionscript-validate-script

# A local fork https://github.com/mxab/pre-commit-trivy.git
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
<?xml version="1.0" encoding="UTF-8"?>
<!--
BigFix Task Export

Title : CVE-2017-5689 - Detection - Deploy the Intel SCS System Discovery Utility 11.1
ID : 24272
Author : yumengyin
Domain : BESC
Imported : 2017-05-11T23:42:23
Source : bigfixm1_main @ BES-Root
-->
<BES xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="BES.xsd">
<Task>
<Title>CVE-2017-5689 - Detection - Deploy the Intel SCS System Discovery Utility 11.1</Title>
<Description><![CDATA[<P>This Fixlet will deploy the Intel scs-system-discovery-utility to the endpoint. This utility will inventory the system and drop information that can be used to detect vulnerable firmware associated with INTEL-SA-00075.<BR></P>
<P>For more information about this vulnerability, please review the following documentation.<BR><A href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr">* INTEL-SA-00075 Security Advisory</A><BR><BR><A href="https://downloadcenter.intel.com/download/26755">* INTEL-SA-00075 Detection Guide</A></P>
<P><STRONG><FONT color=#222222><FONT style="BACKGROUND-COLOR: #f6f9ff"><FONT face=Arial>Note:<SPAN class=Apple-converted-space>&nbsp;</SPAN></FONT></FONT></FONT></STRONG><SPAN style="FONT-SIZE: 13px; FONT-FAMILY: Arial, sans-serif, Verdana; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: normal; COLOR: rgb(34,34,34); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(246,249,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial">The task is released in<SPAN class=Apple-converted-space>&nbsp;</SPAN></SPAN><A style="FONT-SIZE: 13px; TEXT-DECORATION: underline; FONT-FAMILY: Arial, sans-serif, Verdana; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: normal; COLOR: rgb(34,34,34); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(246,249,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px" href="https://bigfix.me/">https://bigfix.me/</A><SPAN style="FONT-SIZE: 13px; FONT-FAMILY: Arial, sans-serif, Verdana; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: normal; COLOR: rgb(34,34,34); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(246,249,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial">, which is not an official release channel of IBM BigFix. We highly suggest testing the content before deploying to production. Use of the content is done at the user's own risk and the user will be solely responsible for any damage to any computer system or loss of data that results from use of the content.</SPAN></P>]]></Description>
<Relevance>name of operating system starts with &quot;Win&quot;</Relevance>
<Relevance>Not exist process &quot;SCSDiscovery.exe&quot;</Relevance>
<Relevance>Not(exists key &quot;HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\SystemDiscovery\GeneralInfo&quot; whose (exists value &quot;LastTimeUpdated&quot; of it) of registry )</Relevance>
<Relevance><![CDATA[NOT (exists key "HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\SystemDiscovery\GeneralInfo" whose (exists value "SCSVersion" whose ( (it as string as version) >= "11.1") of it) of registry )]]></Relevance>
<Category>Workaround</Category>
<Source>Intel</Source>
<SourceID>INTEL-SA-00075</SourceID>
<SourceReleaseDate>2017-05-01</SourceReleaseDate>
<SourceSeverity>Critical</SourceSeverity>
<CVENames>CVE-2017-5689</CVENames>
<MIMEField>
<Name>x-fixlet-source</Name>
<Value>Software Distribution Wizard</Value>
</MIMEField>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
<Value>Fri, 12 May 2017 05:24:49 +0000</Value>
</MIMEField>
<Domain>BESC</Domain>
<DefaultAction ID="Action1">
<Description>
<PreLink>Click </PreLink>
<Link>here </Link>
<PostLink>to initiate the deployment process.</PostLink>
</Description>
<ActionScript MIMEType="application/x-Fixlet-Windows-Shell"><![CDATA[// download Intel-SA-00075 Unprovisioning Tool
prefetch Intel_SCS_Discovery_11.1.0.75.zip sha1:b8c6881b5c4e8c403f03a67329c90cf5ea9f1569 size:2838200 https://downloadmirror.intel.com/26691/eng/Intel_SCS_Discovery_11.1.0.75.zip sha256:c6342d4dd4338d2c80b852fd816850411ff65515fec01962785ac4e577ff17f5

// - This unzip is a compiled verion of unzip v5.52
prefetch unzip.exe sha1:84debf12767785cd9b43811022407de7413beb6f size:204800 http://software.bigfix.com/download/redist/unzip-6.0.exe sha256:2122557d350fd1c59fb0ef32125330bde673e9331eb9371b454c2ad2d82091ac

// Add unzip.exe to the client utility cache
if {exists file (pathname of client folder of current site & "\__Download\unzip.exe")}
utility __Download\unzip.exe
endif

//Unprovisioning clients
waithidden __Download\unzip.exe -o "{pathname of client folder of current site}\__Download\Intel_SCS_Discovery_11.1.0.75.zip " -d "{pathname of client folder of current site}\__Download"

continue if {not exists running application whose ((it = "sdsdiscovery.exe") of (name of it as lowercase))}

waithidden __Download\Intel_SCS_Discovery_11.1.0.75\SCSDiscovery.exe SystemDiscovery /nofile


//Client Setting keeps track of assessment
setting "_AVP_IntelSCS_Accessed"="{now}" on "{parameter "action issue date" of action}" for client

]]></ActionScript>
<SuccessCriteria Option="RunToCompletion"></SuccessCriteria>
</DefaultAction>
</Task>
</BES>
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
<?xml version="1.0" encoding="UTF-8"?>
<!--
BigFix Task Export

Title : CVE-2017-5689 - Mitigation - Unprovision clients and remove LMS
ID : 24328
Author : yumengyin
Domain : BESC
Imported : 2017-05-15T19:35:31
Source : bigfixm1_main @ BES-Root
-->
<BES xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="BES.xsd">
<Task>
<Title>CVE-2017-5689 - Mitigation - Unprovision clients and remove LMS</Title>
<Description><![CDATA[<P>This Fixlet will detect and mitigate the security vulnerability INTEL-SA-00075 on Intel's manageability SKU systems that are vulnerable to a known privilege escalation issue. This Fixlet requires another fixlet action to become relevant. Fixlet created in alignment with <A href="https://downloadcenter.intel.com/download/26755">INTEL-SA-00075 Detection Guide</A></P>
<P>There is an escalation of privilege vulnerability in Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 that can allow an unprivileged attacker to gain control of the manageability features provided by these products.&nbsp; This vulnerability does not exist on Intel-based consumer PCs. </P>
<P>For more information about this vulnerability, please review the following documentation.<BR><A href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr">* INTEL-SA-00075 Security Advisory</A></P>
<P><BR><A href="https://downloadcenter.intel.com/download/26754">* INTEL-SA-00075 Mitigation Guide</A></P>
<P><STRONG><FONT color=#222222><FONT style="BACKGROUND-COLOR: #f6f9ff"><FONT face=Arial>Note:<SPAN class=Apple-converted-space>&nbsp;</SPAN></FONT></FONT></FONT></STRONG><SPAN style="FONT-SIZE: 13px; FONT-FAMILY: Arial, sans-serif, Verdana; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: normal; COLOR: rgb(34,34,34); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(246,249,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial">The task is released in<SPAN class=Apple-converted-space>&nbsp;</SPAN></SPAN><A style="FONT-SIZE: 13px; TEXT-DECORATION: underline; FONT-FAMILY: Arial, sans-serif, Verdana; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: normal; COLOR: rgb(34,34,34); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(246,249,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px" href="https://bigfix.me/">https://bigfix.me/</A><SPAN style="FONT-SIZE: 13px; FONT-FAMILY: Arial, sans-serif, Verdana; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: normal; COLOR: rgb(34,34,34); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(246,249,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial">, which is not an official release channel of IBM BigFix. We highly suggest testing the content before deploying to production. Use of the content is done at the user's own risk and the user will be solely responsible for any damage to any computer system or loss of data that results from use of the content.</SPAN></P>]]></Description>
<Relevance>name of operating system starts with &quot;Win&quot;</Relevance>
<Relevance>(exists key &quot;HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\SystemDiscovery\ManageabilityInfo&quot; whose ((exists value &quot;AMTSKU&quot; whose (((it as string) = &quot;Intel(R) Full AMT Manageability&quot;) OR ((it as string) = &quot;Intel(R) Standard Manageability&quot;) OR ((it as string) = &quot;Intel(R) Small Business Advantage(SBA)&quot;)) of it)) of registry)</Relevance>
<Relevance><![CDATA[((((value "FWVersion" of key "HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\SystemDiscovery\ManageabilityInfo" of registry) as string) as version) >= "6.0") AND ((((value "FWVersion" of key "HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\SystemDiscovery\ManageabilityInfo" of registry) as string) as version) <= "11.6")]]></Relevance>
<Relevance><![CDATA[(((following text of last "." of ((value "FWVersion" of key "HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\SystemDiscovery\ManageabilityInfo" of registry) as string)) as integer) < 3000)]]></Relevance>
<Relevance>exist setting &quot;_AVP_IntelSCS_Accessed&quot; whose (exist value of it ) of client</Relevance>
<Relevance>exists key &quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LMS&quot; whose (exists value &quot;ImagePath&quot; whose (it as string contains &quot;LMS\LMS.exe&quot;) of it) of native registry</Relevance>
<Category>Workaround</Category>
<Source>Intel</Source>
<SourceID>INTEL-SA-00075</SourceID>
<SourceReleaseDate>2017-05-01</SourceReleaseDate>
<SourceSeverity>Critical</SourceSeverity>
<CVENames>CVE-2017-5689</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
<Value>Tue, 16 May 2017 02:34:01 +0000</Value>
</MIMEField>
<Domain>BESC</Domain>
<DefaultAction ID="Action1">
<Description>
<PreLink>Click </PreLink>
<Link>here</Link>
<PostLink> to deploy this action.</PostLink>
</Description>
<ActionScript MIMEType="application/x-Fixlet-Windows-Shell"><![CDATA[// download Intel-SA-00075 Unprovisioning Tool
prefetch INTEL-SA-00075_UnprovisioningTool_1.0.0.0025.zip sha1:dac876ddbf4521d73277f696360af5016047329f size:23707636 https://downloadmirror.intel.com/26781/eng/INTEL-SA-00075_UnprovisioningTool_1.0.0.0025.zip

// - This unzip is a compiled verion of unzip v5.52
prefetch unzip.exe sha1:84debf12767785cd9b43811022407de7413beb6f size:204800 http://software.bigfix.com/download/redist/unzip-6.0.exe sha256:2122557d350fd1c59fb0ef32125330bde673e9331eb9371b454c2ad2d82091ac

// Add unzip.exe to the client utility cache
if {exists file (pathname of client folder of current site & "\__Download\unzip.exe")}
utility __Download\unzip.exe
endif

//Unprovisioning clients
waithidden __Download\unzip.exe -o "{pathname of client folder of current site}\__Download\INTEL-SA-00075_UnprovisioningTool_1.0.0.0025.zip" -d "{pathname of client folder of current site}\__Download"
waithidden msiexec.exe /i __Download\unprovisionToolInstaller.msi /qn

//Get path of file LMS.exe
continue if {exists key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LMS" whose (exists value "ImagePath" whose (it as string contains "LMS\LMS.exe") of it) of native registry}
parameter "LMSpath" = "{following text of first "%22" of first match (regex "%22(.*LMS.exe)") of (value "ImagePath" of it as string ) of key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LMS" of native registry}"

//Disable LMS
waithidden cmd.exe /C sc config LMS start=disabled
//Remove LMS
waithidden cmd.exe /C sc delete LMS
//Delete LMS.exe
continue if {(exists file (parameter "LMSpath" of action)) and ((parameter "LMSpath" of action) ends with "LMS.exe" )}
waithidden cmd.exe /c del /f "{parameter "LMSpath"}"

action requires restart]]></ActionScript>
</DefaultAction>
</Task>
</BES>
Loading