Holy shit, this exploit is incredible: abusing a series of obscure CPU features to ROP all the way into ring -2: https://github.com/xoreaxeaxeax/sinkhole …
-
-
Replying to @FioraAeterna
@FioraAeterna Yes but once you start messing with CPU specific features the exploit will be limited to those specific CPU's.1 reply 0 retweets 0 likes -
Replying to @daviangel
@daviangel Not this one. It's generic to almost all Intel CPUs.3 replies 0 retweets 0 likes -
Replying to @FioraAeterna
@FioraAeterna@daviangel It's fixed in Sandy Bridge. I don't even own any vulnerable systems any more. Cute though.1 reply 1 retweet 0 likes -
Replying to @marcan42
@FioraAeterna@daviangel The thing is, it does not work from a VM, and needs root from an OS. There are many other root->FW/SMM exploits.1 reply 0 retweets 0 likes
@FioraAeterna @daviangel So although it's an awesome exploit, personally, as far as I'm concerned, on x86 root means all F/W bets are off.
11:59 AM - 8 Aug 2015
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.