Re: [情报] Ryzen 与 EPYC 芯片 被发现有安全缺陷

楼主: kuarcis   2018-03-14 09:26:00
四类漏洞的使用前提
masterkey:
网页提供的白皮书第9页
https://i.imgur.com/mInI29z.png
ryzenfall:
网页提供的白皮书第12页
https://i.imgur.com/HxNMair.png
fallout:
网页提供的白皮书第14页
https://i.imgur.com/f6DfKtZ.png
chimera:
网页提供的白皮书第18页
https://i.imgur.com/M36VKio.png
理论上搭配别的漏洞是满可怕的啦
但是这样这些漏洞就需要combo技搭配
那上次那两个漏洞呢?
这里有个meltdown的学术报告
https://arxiv.org/abs/1801.01207
我截个重点给大家看好了
https://i.imgur.com/yddilkg.png
"The attack is independent of the operating system, and it does not rely on
any software vulnerabilities."
大guy4john,大家该干嘛干嘛去吧
※ 引述《b155073 ()》之铭言:
: 来源:https://amdflaws.com/
: 根据网站漏洞分为
: RYZENFALL
: FALLOUT
: CHIMERA
: MASTERKEY
: 主要有缺陷的部分有AMD Secure Processor
: 还有祥硕所设计的AMD Ryzen Chipset
: 其中文中特别标明
: AMD’s outsource partner, ASMedia, is a subsidiary of ASUSTeK Computer, a
: company with poor security track record that has been penalized by the
: Federal Trade Commission for neglecting security vulnerabilities, and must
: now undergo independent security audits for the next 20 years.
: 白皮书有提到
: The Ryzen chipset, a core system component that AMD outsourced to a Taiwanese
: chip
: manufacturer, ASMedia, is currently being shipped with exploitable
: manufacturer backdoors inside.
: These backdoors could allow attackers to inject malicious code into the chip.
: 祥硕恶名昭彰阿... 藏了后门在芯片组内
: 在zen+即将上场时被揭露漏洞
: 希望新的芯片组x470 b450会修复
作者: justlovegirl (织梦精灵)   2018-03-14 10:29:00
有点无言....
作者: TaiwanisChin (台湾就是中国)   2018-03-14 13:55:00
WinRAR.rar整个戳中我笑穴XDD

Links booklink

Contact Us: admin [ a t ] ucptt.com