3 ms·
Yes, but my point is I think the exploit would be extremely difficult, and any agent capable of doing it would not be too interested in making it available to a
by 3chelon 9y ago
Yes, but my point is I think the exploit would be extremely difficult, and any agent capable of doing it would not be too interested in making it available to anyone else. Perhaps I'm naive, but it feels like the kind of thing government agencies would keep in their own armouries.
- katastic 9y agoExcept many hackers run on reputation, and the hacker that releases an amazing new exploit to the masses of script kiddies, is praised for it. "Difficult" is just another word for "look how much greater I am than the competition when I pwn it."
- pjc50 9y agoOr you could just download it from github. https://github.com/paboldin/meltdown-exploit https://github.com/paboldin/meltdown-exploit
- 3chelon 9y agoPerhaps I'm reading the code wrong, but that seems to be a check if your CPU is vulnerable, rather than an exploit. It seems to me that in order to actually obtain any useful information using this method would require far more work. I'm happy to be corrected if that is not the case...
- bpizzi 9y agoPlayed with it a bit, to me it is really reading data of arbitrary size starting at any given memory address. Usage is ./meltdown [hexadrr] [size] Run.sh is first reading the adress where the value of linux_proc_banner is held, with a adequat sed on /proc/kallsyms, then running the meltdown binary to check that this adress has the value stored in /proc/version, which should be the case if the exploit is indeed working (which IS the case with my CPU and current kernel). Meltdown.c is below 300 lines, the actual exploit being maybe half of that. From here, it seems to me that you can extrapolate in reading any value anywhere in the memory.
- PakG1 9y agoThe way the NSA keeps their zero-day tools in a secure locked box so that they'll never be leaked into the wild and be used for things like WannaCry?
- 3chelon 9y agoFair point, but wasn't zero-day back in June when this was first reported to the chip makers?
- pixl97 9y agoThis >I think the exploit would be extremely difficult, and this >The idea nagged at Prescher, so when he got home he fired up his desktop computer and set about putting the theory into practice. At 2 a.m., a breakthrough: he’d strung together code that reinforced Fogh’s idea and suggested there was something seriously wrong. Don't seem to match up. It may be hard, but even a security researcher doesn't bust a hard to exploit hole open in a few hours overnight. I believe that this was an area where no one was looking and now that its out in the open it will be much easier for others to exploit.
- 3chelon 9y agoYes, but again, proving there's an exploit is different to implementing it and actually stealing someone's banking details (which is the media definition of a scary hack). And you say "even a security researcher"... surely they are the guys most likely to be able to perform the exploit, in real life?
- solarkraft 9y agoTo prove the vulnerability is exploitable I'd ideally do ahead and do it. Has this not been done?
- workthrowaway27 9y agoIt's one thing to exploit something locally. It's another to exploit it remotely. And if you have local access to a machine I'm sure there are much easier ways to get root access to it.
- matt4077 9y agoBefore being patched, this exploit would have worked at any of the cloud providers: Google Compute Engine, AWS, etc. You could have run it on thousands of virtual machines and sifted through all the data of other VMs running on the same hardware. Oh, and it works (/worked) on browsers.
- not_kurt_godel 9y ago