Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-04-2018, 04:53 AM   #1
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Meltdown and Spectre exploits

https://meltdownattack.com/
2 exploits in intel/amd/arm cpus. Most linux distributions already have patches (albiet that slow down the system a bit).

I wouldn't want to be a VPS provider right now
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-04-2018, 05:44 AM   #2
Paul&John
Confirmed User
 
Paul&John's Avatar
 
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,592
As far as I know meltdown works only on Intel.. the second one - spectre is for all three.
__________________
Use coupon 'pauljohn' for a $1 discount at already super cheap NameSilo!
Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here
Paul&John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-04-2018, 08:17 AM   #3
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Correct. I'm surprised no one is talking about this on here - it's literally the largest security hole ever.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-04-2018, 08:37 AM   #4
freecartoonporn
Confirmed User
 
freecartoonporn's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
ha jokes on INTEL , i use AMD,

who knows, how many reputable apps have already stolen shotloads of data., and this day data = money.,
freecartoonporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-04-2018, 08:21 PM   #5
Phoenix
BACON BACON BACON
 
Industry Role:
Join Date: Nov 2002
Location: Poems everybody, the laddie fancies himself a poet
Posts: 35,457
Fix yet?
__________________
Skype Phoenixskype1
Telegram PhoenixBrad
https://quantads.io
Phoenix is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 08:29 AM   #6
Paul&John
Confirmed User
 
Paul&John's Avatar
 
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,592
Quote:
Originally Posted by Phoenix View Post
Fix yet?
Nah first the Intel CEO had to sell some of his stocks before it hit the news

https://www.cnbc.com/2018/01/04/inte...ity-flaws.html
Intel CEO Brian Krzanich sold off a large chunk of his stake in the company after the chipmaker was made aware of serious security flaws, according to multiple reports
__________________
Use coupon 'pauljohn' for a $1 discount at already super cheap NameSilo!
Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here
Paul&John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 08:42 AM   #7
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
Quote:
Originally Posted by freecartoonporn View Post
ha jokes on INTEL , i use AMD,
"2 exploits in intel/amd/arm cpus"
Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 09:55 AM   #8
Sarn
So Sanctions!!11
 
Sarn's Avatar
 
Industry Role:
Join Date: Sep 2015
Location: Russia
Posts: 10,841
And how fix it?
Sarn is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 11:04 AM   #9
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by Sarn View Post
And how fix it?
Meltdown via software patches that slow down cpu 5-30%. Spectre supposidely unfixable.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 11:17 AM   #10
GAMEFINEST
Make STACK$
 
GAMEFINEST's Avatar
 
Industry Role:
Join Date: Nov 2006
Location: sexy time
Posts: 14,418
Sell them stocks..
__________________
Compound interest.
GAMEFINEST is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 12:50 PM   #11
deonbell
Confirmed User
 
deonbell's Avatar
 
Industry Role:
Join Date: Sep 2015
Posts: 1,045
How do computer get the aids? Not remotely attack like heart bleed? Not by visiting website?

Maybe have to put exploit on executable? Put code with a bejewdled game then bad guy gives computer aids and reads your password?
deonbell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 01:05 PM   #12
shake
frc
 
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,664
Quote:
Originally Posted by k0nr4d View Post
https://meltdownattack.com/
2 exploits in intel/amd/arm cpus. Most linux distributions already have patches (albiet that slow down the system a bit).

I wouldn't want to be a VPS provider right now
Pretty crazy right. It won't really effect home users much but it's going to be a big problem at the server level.
__________________
Crazy fast VPS for $10 a month. Try with $20 free credit
shake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 01:15 PM   #13
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by deonbell View Post
How do computer get the aids? Not remotely attack like heart bleed? Not by visiting website?

Maybe have to put exploit on executable? Put code with a bejewdled game then bad guy gives computer aids and reads your password?
Spectre is executable via javascript.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 03:35 PM   #14
deonbell
Confirmed User
 
deonbell's Avatar
 
Industry Role:
Join Date: Sep 2015
Posts: 1,045
Quote:
Originally Posted by k0nr4d View Post
Spectre is executable via javascript.
Hmm, Note just Node.js problem? Look like possible to escape browser sandbox? Ignore Same Orgy Policy on websites.

https://www.react-etc.net/entry/expl...via-javascript
deonbell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 04:29 PM   #15
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
I was wondering the other day if a major crypto exchange I use is "in the cloud", and if so, what that may mean for security.

My mild concern becomes more serious after learning of these new attack vectors, considering that it may be possible for another customer to access arbitrary memory on the same host. To steal funds from a Bitcoin address all you need is a 32 byte private key.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-05-2018, 11:51 PM   #16
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by rowan View Post
To steal funds from a Bitcoin address all you need is a 32 byte private key.
To elaborate further: that is really all you need to steal someone's Bitcoin balance. You don't need to be able to control the victim's computer/VPS in any way, nor do you need access to the file system. You just need to grab those 32 bytes of private key (for each address) from the victim's (running) Bitcoin client, then import them into your own wallet. The victim no longer has control of the funds once you move them to your own address.

You don't even need to know if any given 32 byte string is a Bitcoin key. You can just import it and let the client figure out if it owns any funds.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-06-2018, 12:01 AM   #17
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
This only applies to someone that?s running bitcoin on a vps/cloud server which is less then 1% of users

Quote:
Originally Posted by rowan View Post
To elaborate further: that is really all you need to steal someone's Bitcoin balance. You don't need to be able to control the victim's computer/VPS in any way, nor do you need access to the file system. You just need to grab those 32 bytes of private key (for each address) from the victim's (running) Bitcoin client, then import them into your own wallet. The victim no longer has control of the funds once you move them to your own address.

You don't even need to know if any given 32 byte string is a Bitcoin key. You can just import it and let the client figure out if it owns any funds.
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-06-2018, 12:07 AM   #18
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by sandman! View Post
This only applies to someone that?s running bitcoin on a vps/cloud server which is less then 1% of users
How many exchanges do you think run on bare metal? I bet a lot of them rely heavily on cloud instances in order to scale.

Consider also that even a dedicated server could be attacked via another vector. A process which is running chrooted/jailed, such as a coin daemon, could be examined by an exploit in another part of the server.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-06-2018, 12:09 AM   #19
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
Yes it?s possible but there have always been exploits un known out there I have a system that has kept me and my customers safe for along time that I won?t be posting here 🙃

Quote:
Originally Posted by rowan View Post
How many exchanges do you think run on bare metal? I bet a lot of them rely heavily on cloud instances in order to scale.

Consider also that even a dedicated server could be attacked via another vector. A process which is running chrooted/jailed, such as a coin daemon, could be examined by an exploit in another part of the server.
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-06-2018, 12:21 AM   #20
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by rowan View Post
How many exchanges do you think run on bare metal? I bet a lot of them rely heavily on cloud instances in order to scale.

Consider also that even a dedicated server could be attacked via another vector. A process which is running chrooted/jailed, such as a coin daemon, could be examined by an exploit in another part of the server.
I think most of them are running on bare metal, with CDN's in front. Bittrex is behind cloudflare. Cloudflare would be vulnerable, and it acts like a proxy for requests between you and bittrex. Besides that, this could be used to steal google authenticator tokens for the two-factor logins on sites.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-06-2018, 12:23 PM   #21
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
This page has a good technical-but-not-excessively-technical explanation of how the attacks work. It's on the Raspberry Pi site but it's not really Pi specific.

https://www.raspberrypi.org/blog/why...e-or-meltdown/
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
exploits, bit, system, thumbsup, provider, vps, slow, intel/amd/arm, spectre, cpus, patches, albiet, linux, distributions, meltdown



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.