• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

AMD CPU Guest Memory Vulnerabilities “Sinkclose”

sk3tch

Supreme [H]ardness
2FA
Joined
Sep 5, 2008
Messages
4,626
Last edited:
AMD Ryzen™ 3000 Series Desktop Processors (Formerly codenamed) “Matisse” -- No fix planned

AMD just threw Matisse users under the bus. Really not that old (2019).
Yeah….. no fixed planned for my EPYC’s either, supposedly there are software and security suite mitigations that can close the attack vectors though so I’m not worried, just upset.
 
Thanks for sharing this.
A bit of a silver-lining, from the article:
In a background statement to WIRED, AMD emphasized the difficulty of exploiting Sinkclose: To take advantage of the vulnerability, a hacker has to already possess access to a computer's kernel, the core of its operating system. AMD compares the Sinkhole technique to a method for accessing a bank's safe-deposit boxes after already bypassing its alarms, the guards, and vault door.
 
Thanks for sharing this.
A bit of a silver-lining, from the article:
Which was almost the case regarding Spectre and Meltdown. Both were essentially useless unless you had physical access to the host machine 'and' a user account.
 
AMD Ryzen™ 3000 Series Desktop Processors (Formerly codenamed) “Matisse” -- No fix planned

AMD just threw Matisse users under the bus. Really not that old (2019).
Don't really care TBH. I didn't update my board from the last similar one from like a year ago either. These types of attacks basically mean your computer is already owned anyways. It's not like my gaming PC is being used as a server or something.

Same reasons I never updated my 5820k system back in the day due to spectre. All those updates absolutely killed the performance of those chips for no good reason.
 
Thanks for sharing this.
A bit of a silver-lining, from the article:
I was just about to respond about it. It requires ring 0 access which ain't easy. You would have to be running an infected kernel or software that the kernel confirmed as requiring ring 0. Linus has been pretty aggressive on limiting ring 0 access for user space programs.
 
Which was almost the case regarding Spectre and Meltdown. Both were essentially useless unless you had physical access to the host machine 'and' a user account.
Meltdown of the Intel variety can be done over the HTTP protocol. You do not need physical access to the machine at all. That's why Meltdown was so problematic.
 
From the article the issue isn't that it is tough to exploit - in the traditional sense - yes - we are all good. The real area that is in danger are places like consoles where the user is intended to be "protected" from exploits to stop IP theft - i.e. pirated games.
 
Every system has vulnerabilities, the only difference is how long they take to find and how hard they are to exploit.

If something has an entrance something bad will find a way in.
 
No, this affects AM4 socket series Ryzen 5000 too. Check the AMD link for your CPU series.

PS Requires admin access to host OS.
 
No, this affects AM4 socket series Ryzen 5000 too. Check the AMD link for your CPU series.

PS Requires admin access to host OS.
Yeah, never said it didn't, but I specifically highlighted AM5 (since that's what I care about and figured most would - the links tell the rest of the story). I'll update it.
 
Meltdown of the Intel variety can be done over the HTTP protocol. You do not need physical access to the machine at all. That's why Meltdown was so problematic.
You needed an existing account to log into on the machine, so via HTTP or via console in front of the actual device, you essentially need some form of physical access to the machine in order to run the exploit - And even then, it's success was purely theoretical with the timing of the exploit needing to be extremely precise as data is overwritten in cache very quickly.
 
You needed an existing account to log into on the machine, so via HTTP or via console in front of the actual device, you essentially need some form of physical access to the machine in order to run the exploit - And even then, it's success was purely theoretical with the timing of the exploit needing to be extremely precise as data is overwritten in cache very quickly.
The part I would be worried about is say a flood of compromised USB-C cables ending up on Amazon's recommended list that run a few scrips at near-instant speeds when inserted into a machine that installs a lovely little bot that lets a remote attacker exploit the vulnerability from there.
 
You needed an existing account to log into on the machine, so via HTTP or via console in front of the actual device, you essentially need some form of physical access to the machine in order to run the exploit - And even then, it's success was purely theoretical with the timing of the exploit needing to be extremely precise as data is overwritten in cache very quickly.

"You need Physical Access" No, you don't. You need someone with an admin account to unknowingly install a compromised piece of software. Physical access is not required. It's not like installing software needs human bodyheat. I can install a piece of compromised software on a device in the Phillipines from a remote connection in the US. Definitely not "Physical Access".

How often do we install something we downloaded from Techpowerup or some 3rd party site and just say "Yes" to the UAC Prompt? Do we go through a weeks-long analysis and risk assessment when we want to update our MSI Afterburner? We have physical access to our machines, and we approve installations all the time.
 
"You need Physical Access" No, you don't. You need someone with an admin account to unknowingly install a compromised piece of software. Physical access is not required. It's not like installing software needs human bodyheat. I can install a piece of compromised software on a device in the Phillipines from a remote connection in the US. Definitely not "Physical Access".

How often do we install something we downloaded from Techpowerup or some 3rd party site and just say "Yes" to the UAC Prompt? Do we go through a weeks-long analysis and risk assessment when we want to update our MSI Afterburner? We have physical access to our machines, and we approve installations all the time.
Let’s not forget malicious hardware, it exists and it’s a problem.
 
Which was almost the case regarding Spectre and Meltdown. Both were essentially useless unless you had physical access to the host machine 'and' a user account.
https://en.wikipedia.org/wiki/Spectre_(security_vulnerability)

"While Spectre is simpler to exploit with a compiled language such as C or C++ by locally executing machine code, it can also be remotely exploited by code hosted on remote malicious web pages, for example interpreted languages like JavaScript, which run locally using a web browser. The scripted malware would then have access to all the memory mapped to the address space of the running browser.[61]"

Seems Spectre could be remotely executed from a webpage....
 
"You need Physical Access" No, you don't. You need someone with an admin account to unknowingly install a compromised piece of software. Physical access is not required. It's not like installing software needs human bodyheat. I can install a piece of compromised software on a device in the Phillipines from a remote connection in the US. Definitely not "Physical Access".
Yes, software that allows the attacker to gain physical access to an account, and software that is in no way simple to install under Linux. Even then, as stated, your odds of obtaining the needed keys are minimal considering the rate cache is refreshed.

The attacks in question theoretically targeted servers running multiple VM's with multiple user accounts, essentially servers in large data centers - Hardly scenarios where someone's gonna be plugging devices bought off Amazon into a server, definitely not a scenario where someone's downloading software from Techpowerup, and definitely not a scenario whereby the user is running MSI Afterburner.

If people are obtaining access via the above methods, you're pawned whether you're susceptible to Spectre and Meltdown or not. These theoretical attacks were not targeted at single user machines running a single account.

https://en.wikipedia.org/wiki/Spectre_(security_vulnerability)

"While Spectre is simpler to exploit with a compiled language such as C or C++ by locally executing machine code, it can also be remotely exploited by code hosted on remote malicious web pages, for example interpreted languages like JavaScript, which run locally using a web browser. The scripted malware would then have access to all the memory mapped to the address space of the running browser.[61]"

Seems Spectre could be remotely executed from a webpage....

I think you'll find all browsers have since been patched against such an attack since the vulnerability was discovered.
 
Last edited:
That doesn't make your statement valid

Of course it does. The theoretical attacks did not target single user/single account machines not running multiple VM's (so home users). The theoretical attacks targeted servers contained in secure data centers running multiple accounts and a number of VM's per server. The attack involved access to at least one compromised account on the local machine, which is no simple feat - And there is no evidence of a fly by wire browser based attack involving Spectre of Meltdown ever.

The reality is: Once way or another, you need physical access to an account on the actual device to pull off the attack - As stated, should someone gain access to an account on the actual device, you're already pwned, Spectre and Meltdown or not. Once Pwned, any further attack vector is effectively moot
 
Of course it does. The theoretical attacks did not target single user/single account machines not running multiple VM's (so home users). The theoretical attacks targeted servers contained in secure data centers running multiple accounts and a number of VM's per server. The attack involved access to at least one compromised account on the local machine, which is no simple feat - And there is no evidence of a fly by wire browser based attack involving Spectre of Meltdown ever.

The reality is: Once way or another, you need physical access to an account on the actual device to pull off the attack - As stated, should someone gain access to an account on the actual device, you're already pwned, Spectre and Meltdown or not. Once Pwned, any further attack vector is effectively moot
Spectre did not require this... until, as you say, it was patched.
 
You needed an existing account to log into on the machine, so via HTTP or via console in front of the actual device, you essentially need some form of physical access to the machine in order to run the exploit - And even then, it's success was purely theoretical with the timing of the exploit needing to be extremely precise as data is overwritten in cache very quickly.
Not hard to do when two individuals are running VMs on the same physical system while one hammers away at the other getting credentials literally bit by bit.
These exploits are not the same.

Let’s not forget malicious hardware, it exists and it’s a problem.
As of late all of this tends to be from China or Intel.
 
Spectre did not require this... until, as you say, it was patched.

Yes it did, in fact when researchers demonstrated the 'theoretical' attack they had unlimited access to the system in order to do so. Furthermore, there isn't any documented case of Spectre being actually used against any system in a practical and realistic scenario - Which includes theoretical fly by wire Javascript attacks that have only been demonstrated locally with full access to the system used by researchers undertaking the demonstration.
 

Attachments

  • Spectre proof of concept_mod.png
    Spectre proof of concept_mod.png
    164.1 KB · Views: 0
Last edited:
Not hard to do when two individuals are running VMs on the same physical system while one hammers away at the other getting credentials literally bit by bit.
These exploits are not the same.

I never stated the exploits were the same. If one malicious actor has access to a system at all, you're already pwned - Spectre or Meltdown effectively becomes somewhat moot. The attacks were purely theoretical and limited in scope and practical benefit.
 
I never stated the exploits were the same. If one malicious actor has access to a system at all, you're already pwned - Spectre or Meltdown effectively becomes somewhat moot. The attacks were purely theoretical and limited in scope and practical benefit.
Not necessarily, having access to one system is something, but getting leaked credentials via Spectre or Meltdown will give access to many systems.
For singular system access they are the same, but for multi-system access the Intel exploits were/are far worse.
 
- Which includes theoretical fly by wire Javascript attacks that have only been demonstrated locally with full access to the system used by researchers undertaking the demonstration.
No kidding, this was discovered by researchers and Intel/AMD allowed to patch the vulnerabilities before they were fully disclosed.

Spectre didn't need physical access. Just because the demo was easier to show proof of concept with physical access doesn't mean it was required.
 
Not necessarily, having access to one system is something, but getting leaked credentials via Spectre or Meltdown will give access to many systems.
For singular system access they are the same, but for multi-system access the Intel exploits were/are far worse.

Your odds of obtaining leaked keys were proven to be highly unlikely on a system researchers had full access to, your odds at successfully pulling off the attack remotely via fly by wire Javascript attacks diminish even more. The theoretical attacks were both limited and of little practical benefit. As stated, should a malicious attacker simply have access to a targeted system, you're already pwned - It's that simple.

Spectre didn't need physical access. Just because the demo was easier to show proof of concept with physical access doesn't mean it was required.

And yet this is something that has never been actually demonstrated or even observed in the form of a fly by wire attack, ever. As far as the actual attack is concerned, it's all purely theoretical. Your odds at pulling off such an attack via Javascript fly by wire attacks are exceptionally minimal even on an unpatched browser.

However, I digress. Best we get back to AMD discussion.
 
And yet this is something that has never been actually demonstrated or even observed in the form of a fly by wire attack, ever. As far as the actual attack is concerned, it's all purely theoretical. Your odds at pulling off such an attack via Javascript fly by wire attacks are exceptionally minimal even on an unpatched browser.
Did you not see the Google blog link I posted earlier? There's a real web site that's still live where you can be attacked by Spectre (with a pre-patch Chrome browser and certain CPUs). Nothing theoretical about it, and no physical access required.[/url]
 
Every time:
exploiting the bug would require hackers to already have obtained relatively deep access to an AMD-based PC
When will the fearmongering end?
 
Every time:

When will the fearmongering end?
I'm noticing a trend, wherever Intel has bad press, suddenly some researcher digs up something and tries to spin it on AMD.

Possibly coincidence, and I have no doubt this is a real vulnerability, that requires the appropriate level of attention. Does seem that the news is blowing this one up a touch.
 
I'm noticing a trend, wherever Intel has bad press, suddenly some researcher digs up something and tries to spin it on AMD.

Possibly coincidence, and I have no doubt this is a real vulnerability, that requires the appropriate level of attention. Does seem that the news is blowing this one up a touch.
No, but AMD and Intel still have to do the same things, and the more AMD servers that exist out there the more value there is in researching ways to exploit them.
When Intel was 90% of the server market and AMD made up less than the remaining 10% there wasn't a lot of reason to spend money researching vulnerabilities on anything but Intel.
But Now AMD is coming up on something like 40% of the HEDT and Server market, that's a big reason to look, so any time somebody finds an exploit for one, somebody else is going to go hmmm can we do a variation of that on the other.
So for every Intel vulnerability discovered somebody will try to replicate that exploit on AMD, and for every AMD exploit discovered somebody will try to replicate it on Intel.
It's as simple as that, not coincidental by any means it's deliberate and that is the security community doing what they do, trying to break shit and tell us before somebody else does and doesn't.
 
No, but AMD and Intel still have to do the same things, and the more AMD servers that exist out there the more value there is in researching ways to exploit them.
When Intel was 90% of the server market and AMD made up less than the remaining 10% there wasn't a lot of reason to spend money researching vulnerabilities on anything but Intel.
But Now AMD is coming up on something like 40% of the HEDT and Server market, that's a big reason to look, so any time somebody finds an exploit for one, somebody else is going to go hmmm can we do a variation of that on the other.
So for every Intel vulnerability discovered somebody will try to replicate that exploit on AMD, and for every AMD exploit discovered somebody will try to replicate it on Intel.
It's as simple as that, not coincidental by any means it's deliberate and that is the security community doing what they do, trying to break shit and tell us before somebody else does and doesn't.
Yeah I get all that, wouldn't expect anything less. But the media seems to go overboard on something AMD related wherever Intel is struggling with an issue.
 
As I said in the other thread on this, we have a lot of games running kernel-level anticheat (recently, League of Legends). I'm not sure if a compromised kernel is as hard to get these days as it might sound. This is why I refuse to play any games with kernel level anticheat, full stop. It gets hacked and malware gets distributed with it, welcome to literally bricked computer that you can't do anything about.
 
Yeah I get all that, wouldn't expect anything less. But the media seems to go overboard on something AMD related wherever Intel is struggling with an issue.
Which is true but people get bored to the same story over and over, if it doesn’t get shaken up people loose interest and the clicks don’t come in. No clicks no money, so you have to shake it up.
You have to sensationalize things for the algorithms to get into the feeds for the viewerships and the interactions.
Blame Google, it’s their Algorithm.
 
Which is true but people get bored to the same story over and over, if it doesn’t get shaken up people loose interest and the clicks don’t come in. No clicks no money, so you have to shake it up.
You have to sensationalize things for the algorithms to get into the feeds for the viewerships and the interactions.
Blame Google, it’s their Algorithm.
But this is the same story over and over again since meltdown/spectre. Pretending each new vulnerability heralds the end of the world, but when you read the small print, it is the same old nothing burger. You either need the machine to already be compromised to exploit the new "vulnerability" or worse it can only be exploited with physical access.

It is literally the story of the boy who cried wolf. And when an actual serious issue arises people will just wave it off as another one of those fearmongering stories.

If it was up to me, I'd only classify things as vulnerabilities if they provide a new attack vector that can be used to breach a system with no other prerequisites.
 
But this is the same story over and over again since meltdown/spectre. Pretending each new vulnerability heralds the end of the world, but when you read the small print, it is the same old nothing burger. You either need the machine to already be compromised to exploit the new "vulnerability" or worse it can only be exploited with physical access.

It is literally the story of the boy who cried wolf. And when an actual serious issue arises people will just wave it off as another one of those fearmongering stories.

If it was up to me, I'd only classify things as vulnerabilities if they provide a new attack vector that can be used to breach a system with no other prerequisites.
Physical access is not as hard as it once was.
It doesn’t need to be a person at the keyboard, an infected USB key can do it too, modern keyboards that let you have macros on them count. There are lots of ways to run a script file locally on a machine that will do the job.
Modify a few dozen USB key to run a series of keyboard commands when inserted into a machine and drop them around the targeted area. An employee is bound to find one, and if somebody plugs that into a company asset in they are.

Or just leave them around coffee shops, or other places where people gather and work.

KVM over IP counts as local, so vulnerabilities in something like iDRAC would do.

Hell windows RDP counts as physical.

Sadly physical access no longer requires you to be physically at the machine.

And it’s never a single vulnerability that brings you down it’s a combination of them. And the people exploiting them are good, they get the smallest bit of access and they can often spend weeks exploring your network and infrastructure before they pull the trigger on what they are doing.
 
Last edited:
Physical access is not as hard as it once was.
It doesn’t need to be a person at the keyboard, an infected USB key can do it too, modern keyboards that let you have macros on them count. There are lots of ways to run a script file locally on a machine that will do the job.
Modify a few dozen USB key to run a series of keyboard commands when inserted into a machine and drop them around the targeted area. An employee is bound to find one, and if somebody plugs that into a company asset in they are.

Or just leave them around coffee shops, or other places where people gather and work.

KVM over IP counts as local, so vulnerabilities in something like iDRAC would do.

Hell windows RDP counts as physical.

Sadly physical access no longer requires you to be physically at the machine.

And it’s never a single vulnerability that brings you down it’s a combination of them. And the people exploiting them are good, they get the smallest bit of access and they can often spend weeks exploring your network and infrastructure before they pull the trigger on what they are doing.
UAC was a good idea. But it seems to have been botched, universally panned, and disabled everywhere but enterprise. Seems that this would intercept all of the "not a person at the keyboard" attacks.
 
Back
Top