3 ms·
I challenge you to name another readily available "read arbitrary RAM from userspace"[1] vulnerability. [1] Not even including "potentially exploitable from Ja
by anyfoo 1y ago
I challenge you to name another readily available "read arbitrary RAM from userspace"[1] vulnerability.
[1] Not even including "potentially exploitable from JavaScript", which Spectre was. It's sufficient if you name one where an ordinary userspace program can do it.
- genewitch 1y agoCan't you trivially do this with 4 lines of C?
- Akronymus 1y agoOnly if you already have the ability to read arbitrary RAM. So running in kernel/hypervisor mode. The exploit is being able to do it from usermode through an api (browser/js) that normally forbids that. Userspace can only access its own memory, rather than the whole systems.
- anyfoo 1y agoUserspace processes can only read their own memory, or what has been shared with them.
- genewitch 1y agoso how do programs like Cheat Engine and WeMod work, on windows? they don't request an administrator password, and i can tamper with any processes' memory i've tried, including firefox.exe and the like. https://cheatengine.org/ https://cheatengine.org/ https://www.wemod.com/ https://www.wemod.com/