PortSmash - New vulnerability on multi-threaded CPU
PortSmash is a dangerous side channel vulnerability, exploiting active streams simultaneously to steal the key and determine what the processor is doing. Currently, this vulnerability has been confirmed on the Kaby Lake and Skylake chiP but it is also possible to work on AMD's ultra-high-end processors.
SMT (Simultaneous multi-threading) creates two logical cores on each physical core, but these two cores can see what the other thread is doing.
Malware exploiting the PortSmash vulnerability will operate on a parallel logical core to target the target process and legitimize it. It will then record all data leaking from the legal process - usually the operating time - and then reconstruct what the other core is doing. It is supposed to steal a lot of information, most effectively evaluating cryptographic keys because of how the processor calculates them.
A similar flaw using SMT as a weakness is TLBleed, announced in June. It can identify a 356-bit encryption key for more than 17 seconds, using only 2 milliseconds of data. PortSmash may (or may not) be slower, but the possibility is that it will be more flexible.
'PortSmash is very flexible and there are few prerequisites, it does not need to know about cache connections (connecting from main memory to cache), machine learning techniques or reverse engineering. PortSmash also doesn't need root access, 'said Billy Bob Brumley, a researcher with PortSmash.
Brumley and his team consisted of four other researchers from universities in Cuba and Finland saying that the server architecture would be most affected. 'I think remote login scenarios are the biggest threat.' For example, when malicious users log into the website, they can use PortSmash to discover the encryption key used by the website and then hack the server to steal the data.
PortSmash can steal encryption keys
However, there is no need to panic. OpenSSL, a widely used encrypted library on the Internet (more than 60%) has just released a patch to prevent access via this direct method. They also said the general patch will soon be released, but security researchers say the hardware or BIOS also needs to take action.
They announced the vulnerability to Intel on October 1, but Intel did not agree, saying that encrypted libraries such as OpenSSL must prevent these security flaws themselves. AMD is considering its role in this regard.
On GitHub, there is also PoC if you want to try using PortSmash, it can steal the private key P-384 OpenSSL from TLS server running OpenSSl software which has not been upgraded to version 1.1.1
See more:
- Updating Windows 10 in the future will help the machine run faster by patching Specter
- Foreshadow - the fifth most serious security hole in the CPU in 2018
- Serious security vulnerability on Intel chips
You should read it
- Apple releases iOS 14.4.2, iOS 12.5.2, and watchOS 7.3.3 updates that patch the critical zero-day vulnerability
- Microsoft urgently patched zero-day vulnerability after 2 years of refusing to acknowledge it
- Critical Vulnerability Discovered in 3 WordPress Plugins, Affects 84,000 Websites
- Discovered a new zero-day vulnerability on macOS that allows attackers to run commands remotely
- Detecting zero-day vulnerability in the Dropbox 10 Windows app, users pay attention!
- Detected a serious BIOS vulnerability, affecting many Intel processors
- 'Printer Catastrophe' Vulnerability Threatens All Versions of Windows
- Detecting a new Linux vulnerability allows hackers to gain control of the VPN connection
May be interested
- Detected a serious zero-day vulnerability in Microsoft Office, click the document file and it will stickthe newly discovered vulnerability is called follina and currently there is no official patch from microsoft.
- 5 Multi-Factor Authentication Vulnerabilities and how to fix themmulti-factor authentication (mfa) elevates cybersecurity standards by requiring users to prove their identity in multiple ways before accessing the network.
- 'Printer Catastrophe' Vulnerability Threatens All Versions of Windowsalthough microsoft releases patches for windows vulnerabilities on a monthly basis, there are still security issues that remain. recently, the us cybersecurity and infrastructure agency (cisa) reported a critical vulnerability in the windows print spooler system.
- What is VENOM Vulnerability? How can you protect yourself?the venom vulnerability affects all major cpu vendors, including intel, amd, and arm. venom allows malicious actors to read the contents of a computer's memory and potentially execute code remotely.
- Log4Shell zero-day vulnerability discovered, the new nightmare of enterpriseshow to exploit a critical zero-day vulnerability in the java-based apache log4j logging library has just been posted on the internet. this leaves users and businesses as well as organizations vulnerable to remote code execution attacks.
- Detects a vulnerability that threatens all Windows computers shipped from 2012 up to nowsecurity researchers have found a vulnerability in the microsoft windows platform binary table (wpbt). this vulnerability can be exploited by hackers to install rootkits on all windows computers shipped from 2012 to the present.
- How to download files faster with Persepoliswhen downloading large files, it is worth using a download manager like persepolis. with multi-threaded support, persepolis allows you to download files at the maximum speed that the connection allows.
- Warning of dangerous Spring4Shell vulnerability, there are signs of scanning and exploitingspring has just released an urgent update to patch the spring4shell remote code execution zero-day vulnerability. information about this vulnerability was leaked on the internet before the patch was released.
- AMD Ryzen 5 3600X Review: Great multi-threaded support, overclockablethe ryzen 5 3600x lacks integrated graphics, but in return it is multithreaded and overclockable, two features that some intel competitors lack. this is a great option for a gaming pc.
- Steps to fix PrintNightmare vulnerability on Windows 10if you've been following recent windows security news, you may have heard of printnightmare. this is a vulnerability that allows hackers to exploit your system and run malicious code on it.