| Thread Tools |
30th July 2018, 12:25 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 148,678
| New Spectre attack allows a network hack Sceptre's impact got a little more dangerous When Sceptre first was released there was a movement among Intel fans to say that there was nothing to worry because a hacker had to be sitting on your machine and know your password to do any damage. Now according to Ars Technica the problem is getting much worse. Boffins from Graz University of Technology, including one of the original Meltdown discoverers, Daniel Gruss, have described NetSpectre: a fully remote attack based on Spectre. With NetSpectre, an attacker can remotely read the memory of a victim system without running any code on that system. This makes it possible to stage a network attack on a Sceptre vulnerablity. Dubbed NetSpectre the attack uses the same principles as Spectre but works a lot harder to exploit them. With a malicious JavaScript, for example, exploitation is fairly straightforward. The JavaScript developer has relatively fine control over the instructions the processor executes and can both perform speculative execution and measure differences in cache performance quite easily. With remote execution, that's a lot harder: the code to perform a vulnerable speculative execution (the "leak gadget") and the code to disclose the differences in microarchitectural state over the network (the "transmit gadget") have to both already exist somewhere on the remote system, such that a remote attacker can reliably call them. The researchers found that both of these parts could be found in networked applications. For the networked attack, rather than measuring cache performance, the attack measures the time taken to respond to network requests. The disturbance to the microarchitectural state is such that it can cause a measurably different response time to the request. https://fudzilla.com/news/pc-hardwar...a-network-hack |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Another Spectre class attack spotted | Stefan Mileschin | WebNews | 0 | 26th July 2018 08:44 |
AMD sued over Spectre exploits | Stefan Mileschin | WebNews | 0 | 13th February 2018 19:14 |
HP Spectre Laptop Review | Stefan Mileschin | WebNews | 0 | 6th July 2016 14:01 |
BBC under hack attack | Stefan Mileschin | WebNews | 0 | 1st January 2016 15:50 |
Piracy app Popcorn Time vulnerable to hack attack | Stefan Mileschin | WebNews | 0 | 6th August 2015 14:48 |
SIM card maker Gemalto investigates spy agencies' hack attack | Stefan Mileschin | WebNews | 0 | 22nd February 2015 14:38 |
War Z down after hack-attack | Stefan Mileschin | WebNews | 0 | 3rd April 2013 09:10 |
HP Envy 14 Spectre @ ocaholic | Stefan Mileschin | WebNews | 0 | 8th June 2012 07:38 |
BitFenix Spectre Pro Fan Review @ OCC | Stefan Mileschin | WebNews | 0 | 7th June 2012 08:04 |
network problems between linux pc and windows network | kr15t0f | Hardware/Software Problems, Bugs | 11 | 30th April 2007 17:26 |
Thread Tools | |
| |