![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Meltdown and Spectre exploits
https://meltdownattack.com/
2 exploits in intel/amd/arm cpus. Most linux distributions already have patches (albiet that slow down the system a bit). I wouldn't want to be a VPS provider right now ![]()
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,592
|
As far as I know meltdown works only on Intel.. the second one - spectre is for all three.
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Correct. I'm surprised no one is talking about this on here - it's literally the largest security hole ever.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
|
ha jokes on INTEL , i use AMD,
who knows, how many reputable apps have already stolen shotloads of data., and this day data = money.,
__________________
SSD Cloud Server, VPS Server, Simple Cloud Hosting | DigitalOcean
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
BACON BACON BACON
Industry Role:
Join Date: Nov 2002
Location: Poems everybody, the laddie fancies himself a poet
Posts: 35,457
|
Fix yet?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,592
|
Nah first the Intel CEO had to sell some of his stocks before it hit the news
![]() https://www.cnbc.com/2018/01/04/inte...ity-flaws.html Intel CEO Brian Krzanich sold off a large chunk of his stake in the company after the chipmaker was made aware of serious security flaws, according to multiple reports
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
So Sanctions!!11
Industry Role:
Join Date: Sep 2015
Location: Russia
Posts: 10,841
|
And how fix it?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Meltdown via software patches that slow down cpu 5-30%. Spectre supposidely unfixable.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Make STACK$
Industry Role:
Join Date: Nov 2006
Location: sexy time
Posts: 14,418
|
Sell them stocks..
__________________
Compound interest. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Sep 2015
Posts: 1,045
|
How do computer get the aids? Not remotely attack like heart bleed? Not by visiting website?
Maybe have to put exploit on executable? Put code with a bejewdled game then bad guy gives computer aids and reads your password?
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
frc
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,664
|
Quote:
![]()
__________________
Crazy fast VPS for $10 a month. Try with $20 free credit |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Spectre is executable via javascript.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: Sep 2015
Posts: 1,045
|
Hmm, Note just Node.js problem? Look like possible to escape browser sandbox? Ignore Same Orgy Policy on websites.
https://www.react-etc.net/entry/expl...via-javascript
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
I was wondering the other day if a major crypto exchange I use is "in the cloud", and if so, what that may mean for security.
My mild concern becomes more serious after learning of these new attack vectors, considering that it may be possible for another customer to access arbitrary memory on the same host. To steal funds from a Bitcoin address all you need is a 32 byte private key. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
You don't even need to know if any given 32 byte string is a Bitcoin key. You can just import it and let the client figure out if it owns any funds. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
This only applies to someone that?s running bitcoin on a vps/cloud server which is less then 1% of users
Quote:
__________________
Need WebHosting ? Email me for some great deals [email protected] |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
Consider also that even a dedicated server could be attacked via another vector. A process which is running chrooted/jailed, such as a coin daemon, could be examined by an exploit in another part of the server. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
Yes it?s possible but there have always been exploits un known out there I have a system that has kept me and my customers safe for along time that I won?t be posting here 🙃
Quote:
__________________
Need WebHosting ? Email me for some great deals [email protected] |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Quote:
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
This page has a good technical-but-not-excessively-technical explanation of how the attacks work. It's on the Raspberry Pi site but it's not really Pi specific.
https://www.raspberrypi.org/blog/why...e-or-meltdown/ |
![]() |
![]() ![]() ![]() ![]() ![]() |