LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-11-2015, 11:21 AM   #1
metaschima
Senior Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 1,982

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Rowhammer DRAM-based privilege escalation exploit


This is a very interesting new exploit discovered by Google:
https://threatpost.com/rowhammer-har...ops-pcs/111532
Quote:
Now, it is hardware’s turn in the spotlight, as researchers have published details of a new method for exploiting a problem with some DRAM memory devices that can allow attackers to get low-level access to target machines.

The problem is being called “rowhammer”, as it’s a method for repeatedly hammering on rows of cells of memory in DRAM devices to induce cells to flip from one state to another. Using a new technique to exploit the rowhammer issue, researchers at Google were able to produce these bit flips in cells and gain kernel-level privileges. Security researchers say the technique is some of the more important work done on exploitation in recent years and could affect a huge number of laptops and desktop machines.
Other articles:
http://googleprojectzero.blogspot.co...g-to-gain.html
http://arstechnica.com/security/2015...dram-weakness/

Proof of concept, READ THE WARNINGS:
https://github.com/google/rowhammer-test
Backup your data, and do NOT run this on a production machine.

I've run it for 2000 iterations and no exploit. This doesn't mean that my RAM is secure tho. Again, read all the warnings.

EDIT:
For a safer alternative program, use memtest86 v6.0.0. It has a hammer test.

Last edited by metaschima; 03-12-2015 at 09:50 AM. Reason: Added safer alternative test
 
Old 03-11-2015, 12:12 PM   #2
veerain
Senior Member
 
Registered: Mar 2005
Location: Earth bound to Helios
Distribution: Custom
Posts: 2,524

Rep: Reputation: 319Reputation: 319Reputation: 319Reputation: 319
It happens with specific ram modules only.
 
Old 03-11-2015, 12:20 PM   #3
metaschima
Senior Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 1,982

Original Poster
Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Quote:
Originally Posted by veerain View Post
It happens with specific ram modules only.
From Google's tests about 50% of RAM modules tested.

I've stopped at 2200 iterations, no exploit. My RAM is:
Corsair Dominator Platinum 8GB (2x4GB) DDR3 1600 MHz (PC3 12800) Desktop Memory (CMD8GX3M2A1600C8)
 
Old 03-11-2015, 05:15 PM   #4
metaschima
Senior Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 1,982

Original Poster
Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Memtest86 v6.0.0 has a hammer test, but it only boots on UEFI systems. My RAM also passes that. The RAM on my Atom system also passes with:
Transcend TK483PCW3 2GB DDR3-1333
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Intel CPUs affected by VM privilege escalation exploit LXer Syndicated Linux News 0 06-13-2012 09:40 AM
postfix local privilege escalation... trist007 Linux - Security 4 03-30-2011 02:55 PM
Privilege Escalation - Getting 'root' privilege Rahil Parikh Linux - Security 2 12-02-2010 01:04 AM
Intel CPU Privilege Escalation Exploit H_TeXMeX_H Linux - Security 4 04-22-2009 03:57 PM
Linux Privilege Escalation The.Hammer.911 Linux - Security 1 05-10-2007 06:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration