5 ms·
One question- do these vulnerabilities , including spectre and meltdown only help in stealing information or can they also hijack your computer to do arbitrary
by systemdtrigger 7y ago
One question- do these vulnerabilities , including spectre and meltdown only help in stealing information or can they also hijack your computer to do arbitrary things?
- chii 7y agodepends on the information you steal. If you steal passwords, then you can use said password to hijack whatever the passwords are protecting. If you steal private keys, you may be able to use said keys to impersonate the victim (like via ssh into their remote machines). But if you're asking if speculative vulns could directly lead to remote code execution, then no (since you already have given the attacker a measure of control, as they are able to execute code already).
- rocqua 7y agoIt can be used to defeat ASLR, which is a way to make exploiting code harder. However, defeating ASLR just makes it easier to deploy an exploit against a program, but you still need the exploit. It doesn't immediately give code exec, but generally it wouldn't be very hard to turn arbitrary memory read capabilities into privilege escalation. As long as you know what the system is running.
- systemdtrigger 7y agoSo the sense I'm making is- that most of thesr attacks need to be supervised and need you to be a target in particular?
- deleted 7y ago[deleted]
- mrob 7y agoThe attacker needs some way to execute code on your machine. The code doesn't need any special permissions, although attacks are more difficult (but not impossible) if it doesn't have access to high resolution timing information. You can be a target by visiting a webpage with JavaScript enabled.
- paulddraper 7y agoTo exploit these vulnerabilities, you already need (unprivileged, sandboxed) RCE. These vulnerabilities "only" steal information; however that information could of course be leveraged into privilege escalation or anything else.
- GrayShade 7y ago> To exploit these vulnerabilities, you already need (unprivileged, sandboxed) RCE. Such as running JavaScript code served by an ad network.
- paulddraper 7y agoCorrect. Point being, running arbitary (unprivileged, sandboxed) code is a prerequisite; an attacker can already max your CPU, mine crypto, etc.
- gpm 7y agoThis isn't true unfortunately. Being able to cause manipulate the control flow of code that already exists on the computer can be sufficient. See netspectre for an example that worked on real google cloud vms and local wired networks. http://www.misc0110.net/web/files/netspectre.pdf http://www.misc0110.net/web/files/netspectre.pdf
- paulddraper 7y agoWow, that is impressive. Yes in theory you could do that, but to actually exploit in practice I would have guessed couldn't be done.
- icedchai 7y agoDon't get too excited. From the paper: "In the Google cloud, we leak around 3 bits per hour from another virtual machine." This is, of course, under ideal conditions.
- 7y ago
- deleted 7y ago[deleted]