{"id":58,"date":"2018-01-11T01:54:06","date_gmt":"2018-01-11T01:54:06","guid":{"rendered":"http:\/\/192.168.0.9\/?p=58"},"modified":"2019-11-21T23:39:59","modified_gmt":"2019-11-22T05:39:59","slug":"spectre-meltdown","status":"publish","type":"post","link":"https:\/\/zewwy.ca\/index.php\/2018\/01\/11\/spectre-meltdown\/","title":{"rendered":"Spectre Meltdown"},"content":{"rendered":"<p>If you&#8217;re reading this then chances are more than likely you&#8217;re looking up information on the two biggest vulnerabilities to be announced since Heartbleed.<\/p>\n<p>Now there is just a ton of people talking about these vulnerabilities, I&#8217;m going to try and avoid all the real technical mumbo jumbo.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/ZeOlWvf.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/ZeOlWvf.png\" alt=\"\" width=\"920\" height=\"560\" \/><\/a><\/p>\n<p>First things first&#8230; are you affected?!<\/p>\n<p>*Shakes 8 ball* Most Likely.<\/p>\n<p>Now you might be wondering, &#8220;How can that be?!&#8221; Well first let&#8217;s talk about Meltdown. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Meltdown_(security_vulnerability)\">Meltdown<\/a> apparently affects Intel chips only. In short it&#8217;s a weakness in memory handling with the CPU. Do you have an Intel chip running your computer? chances are more than likely, running Windows? Well you&#8217;re in luck, Microsoft is making sure your OS is safe, but at what cost? Maybe a <a href=\"http:\/\/www.cbc.ca\/news\/technology\/microsoft-windows-spectre-meltdown-patch-performance-intel-1.4479355\">slower system than ever<\/a>&#8230; no AMD then? well OK you may be safe from Meltdown, but you&#8217;re still vulnerable to Spectre, and guess what? <a href=\"https:\/\/www.theverge.com\/2018\/1\/9\/16867068\/microsoft-meltdown-spectre-security-updates-amd-pcs-issues\">Microsoft isn&#8217;t able to help you get patched either<\/a>, well apparently if you happen to be running an old AMD chipset.<\/p>\n<p>Not sure how well Intel will do following this, but <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2018-01-08\/intel-ceo-krzanich-s-stock-sales-seen-warranting-sec-examination\">the odd shares sales by the CEO<\/a> def don&#8217;t look like good signs&#8230;<\/p>\n<p>Alright, now back to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Spectre_(security_vulnerability)\">Spectre<\/a>.<img loading=\"lazy\" decoding=\"async\" class=\"alignright\" src=\"https:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/2\/25\/Spectre_with_text.svg\/503px-Spectre_with_text.svg.png\" alt=\"\" width=\"165\" height=\"196\" \/><\/p>\n<p>Well to start off, to say it simply&#8230; never assume, it makes an ass of of you and me. Now you&#8217;ve probably heard this saying before, and you probably might be wondering why I&#8217;m even saying it. Well this vulnerability revolves around the CPU&#8217;s algorithm <a href=\"https:\/\/en.wikipedia.org\/wiki\/Speculative_execution\">(Speculative Execution)<\/a> to assume a result based on repetition of previous outcomes of the same operation.<\/p>\n<p>Crazy how these are totally physical based vulnerabilities (At the CPU chip) which affects them all going back super far.. how far back? Well i had to dig a lil deeper into the interwebs via google. (So they know what I&#8217;m all about lol). and discovered that the <a href=\"https:\/\/www.extremetech.com\/computing\/261792-what-is-speculative-execution\">Pentium Pro was the first<\/a>. Now I&#8217;m simply going on the authors words here, but finding sources from so long ago even today can be rather difficult so I&#8217;ll simply take his word for it. The blog is actually a great read and covers the aspect of the vulnerability very well. However he goes on to say it&#8217;s all about Meltdown, when it might be about Spectre?<\/p>\n<p>Either way&#8230; it&#8217;s a Spectre Meltdown.<\/p>\n<p>If anyone&#8217;s running a HP Spectre laptop with an Intel chipset, and it starts melting down. That be quiet the coincidence. \ud83d\ude1b<\/p>\n<p>Happy hacking! Start writing some javascript based if code to exploit these assuming chips \ud83d\ude09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you&#8217;re reading this then chances are more than likely you&#8217;re looking up information on the two biggest vulnerabilities to be announced since Heartbleed. Now there is just a ton of people talking about these vulnerabilities, I&#8217;m going to try and avoid all the real technical mumbo jumbo. First things first&#8230; are you affected?! *Shakes &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/zewwy.ca\/index.php\/2018\/01\/11\/spectre-meltdown\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Spectre Meltdown&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"sfsi_plus_gutenberg_text_before_share":"","sfsi_plus_gutenberg_show_text_before_share":"","sfsi_plus_gutenberg_icon_type":"","sfsi_plus_gutenberg_icon_alignemt":"","sfsi_plus_gutenburg_max_per_row":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-58","post","type-post","status-publish","format-standard","hentry","category-infosec"],"_links":{"self":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/58","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/comments?post=58"}],"version-history":[{"count":10,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/58\/revisions"}],"predecessor-version":[{"id":762,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/58\/revisions\/762"}],"wp:attachment":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/media?parent=58"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/categories?post=58"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/tags?post=58"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}