3 ms·
Perhaps I'm reading the code wrong, but that seems to be a check if your CPU is vulnerable, rather than an exploit. It seems to me that in order to actually obt
by 3chelon 9y ago
Perhaps I'm reading the code wrong, but that seems to be a check if your CPU is vulnerable, rather than an exploit. It seems to me that in order to actually obtain any useful information using this method would require far more work. I'm happy to be corrected if that is not the case...
- bpizzi 9y agoPlayed with it a bit, to me it is really reading data of arbitrary size starting at any given memory address. Usage is ./meltdown [hexadrr] [size] Run.sh is first reading the adress where the value of linux_proc_banner is held, with a adequat sed on /proc/kallsyms, then running the meltdown binary to check that this adress has the value stored in /proc/version, which should be the case if the exploit is indeed working (which IS the case with my CPU and current kernel). Meltdown.c is below 300 lines, the actual exploit being maybe half of that. From here, it seems to me that you can extrapolate in reading any value anywhere in the memory.