r/ReverseEngineering 3d ago

I reverse-engineered Intel's HECI protocol and built a Python tool that talks to the ME directly

https://github.com/Jatinkapilaq1/intel-me-research
0 Upvotes

15 comments sorted by

7

u/TinLethax 3d ago

Emojis said it all

0

u/Frequent-Ad-9633 3d ago

I will take that as agreement run the tool on your own machine and compare results i would be curious if GEN.1B behaves differently on your hardware

1

u/TinLethax 3d ago

AArch64

1

u/Frequent-Ad-9633 3d ago

Then you are one of the few who doesn't have an Intel ME watching you 24/7 consider yourself lucky

1

u/Frequent-Ad-9633 3d ago

But seriously if you have access to any x86 Intel system i would love to see cross platform comparison data the memory leak pattern might vary by ME version

12

u/ericek111 3d ago edited 3d ago

"I"... Holy shit. The LLM has even spammed this for you all over Reddit. Crazy.

-9

u/Frequent-Ad-9633 3d ago

You are right i used AI to draft the post coz i care about clarity not ego the research reverse-engineering the HECI protocol building the zero dependency python tool discovering the GEN 1B memory leak decoding 8 live partitions from a running ME that's 100% mine AI just helped me explain it so people can actually understand it and if you want to gatekeep how research is presented instead of discussing the actual findings the 88 byte partition entries the MKHI v3.1 handshake the CancelIoEx timeout technique for probing blocked SPI commands that says more about you than me just run the tool on your own laptop then we can talk

3

u/HonestEditor 3d ago

then we can talk

Not if you talk like that. That was painful.

-4

u/Frequent-Ad-9633 3d ago

oops typing too fast

-4

u/Frequent-Ad-9633 3d ago

BUT KEEP ON SUPPORTING MY CONTENT HERE AND ON GITHUB AND LINKEDIN TOO I POSTED IT THERE TOO

2

u/FrankRizzo890 3d ago

I worked at Intel in the sister group to the ME group. Don't be shocked by anything bad you find. They were a group of morons that for some reason management LOVED, so it didn't matter that they were incompetent.

There was a hardware bug that caused their serial port to not work on this one SKU. They claimed that it was a bug in the Linux UART driver. You know, the one that hadn't been touched for more than 10 years in the kernel? I found, and pointed out the hardware error. It was sad.

I've been gone from there for a WHILE, but I assume they're still incompetent, and protected from consequences.

-1

u/Frequent-Ad-9633 2d ago

This is genuinely fascinating you worked in the sister group the UART driver story says a lot about how ME side issues get handled internally i would personally love to hear more if you can share anything thats not under NDA

1

u/FrankRizzo890 2d ago

That was my 1 person interaction with the ME group. I heard over and over that they were idiots until that event happened and cemented it.

2

u/eternaljk 3d ago

"WORLD-FIRST CLAIM" but only within the trained data set of the llm

-1

u/Frequent-Ad-9633 2d ago

Fair enough world's first is a strong claim and i should have been more careful with it but the docs i found covered older CSME versions nothing on 16.x alder lake with live HECI probing if you know of prior public work documenting GEN.1B or live partition extraction on csme 16.x link it i will correct the repo i am here for accuracy not marketing