Metldown & Spectre CPU Vulnerabilities
Page 1 of 5 Goto page 1, 2, 3, 4, 5  Next
StrEagle




Posts: 14059
Location: Balkans
PostPosted: Fri, 5th Jan 2018 11:58    Post subject: Metldown & Spectre CPU Vulnerabilities
Let's consolidate all data in 1 thread

https://techreport.com/news/33026/researchers-reveal-meltdown-and-spectre-cpu-exploits

here's a temporary fix for Chrome:

1. Open Chrome current stable version 64bit
2. open the following url address:
chrome://flags#enable-site-per-process
3. press Enable
4. restart Chrome
5. profit?

p.s: Chrome 64, due to be released on January 23, will contain mitigations to protect against exploitation.

sause:
https://support.google.com/faqs/answer/7622138#chrome

edit:
3E74 wrote:
Dang it, so much stuff....
Ill put em all in one Post...

Spectre - Meltdown Tools and Checks..


Jave script Test if youre vulnerable (this tests only Browser, if ur safe there, doesnt mean the system is also fine.)
http://xlab.tencent.com/special/spectre/spectre_check.html

Tool to check if the update fixed it..
https://ionescu007.github.io/SpecuCheck/


power shell- script from MS to Check if you are good to go:
https://support.microsoft.com/en-us/help/4073119/protect-against-speculative-execution-side-channel-vulnerabilities-in


And, SpectrePoC
Proof of concept code for the Spectre CPU exploit.
With what you can also check if your machine is vulnerable..
https://github.com/crozone/SpectrePoC

german video with more info on this one:





All in one place Smile

edit:

heres an more easy way to check instead of using the powershell.
https://gallery.technet.microsoft.com/scriptcenter/Speculation-Control-e36f0050/view/Discussions#content

Quote:

I converted the module to a standard ps1 script then to an EXE using PS2EXE. Nothing fancy, but hopefully it helps people as it's simpler to run. Compiled with the -runtime20 option.

https://1drv.ms/u/s!AvUMCaElfVkvmmz0hK1SRwHTLG21


New version including the multiple CPU fix

https://1drv.ms/u/s!AvUMCaElfVkvmm8zssuJ8CijHw__


And a zipped version of the same script (usually easier to download)

https://1drv.ms/u/s!AvUMCaElfVkvmnIkcJbDb8_kbBnO


Lutzifer wrote:
and yes, mine is only average


Last edited by StrEagle on Wed, 10th Jan 2018 13:04; edited 1 time in total
Back to top
Mr.Tinkles




Posts: 12378
Location: Reino de Suecia
PostPosted: Fri, 5th Jan 2018 12:55    Post subject:
This only affects Intel and ARM, right? AMD is safe when it comes to meltdown?


Back to top
Nalo
nothing



Posts: 13439

PostPosted: Fri, 5th Jan 2018 13:29    Post subject:
⁢⁢


Last edited by Nalo on Wed, 3rd Jul 2024 05:57; edited 2 times in total
Back to top
Mr.Tinkles




Posts: 12378
Location: Reino de Suecia
PostPosted: Fri, 5th Jan 2018 14:17    Post subject:
Ahh, gotcha. So AMD users should still do the chrome fix.


Back to top
paxsali
Banned



Posts: 18352

PostPosted: Fri, 5th Jan 2018 17:54    Post subject:
⁢⁢


Last edited by paxsali on Thu, 4th Jul 2024 23:30; edited 2 times in total
Back to top
Nalo
nothing



Posts: 13439

PostPosted: Fri, 5th Jan 2018 20:17    Post subject:
⁢⁢


Last edited by Nalo on Wed, 3rd Jul 2024 05:57; edited 2 times in total
Back to top
xDBS




Posts: 1937
Location: USA / Japan
PostPosted: Fri, 5th Jan 2018 20:25    Post subject:
@Paxsali thanks for posting the video


PC Specs: A Maganavox' Odyssey
Tweaked to play Frogger, Lemmings & GTA4

----------------------------------------------------------
Back to top
paxsali
Banned



Posts: 18352

PostPosted: Fri, 5th Jan 2018 20:27    Post subject:
⁢⁢


Last edited by paxsali on Thu, 4th Jul 2024 23:30; edited 2 times in total
Back to top
paxsali
Banned



Posts: 18352

PostPosted: Fri, 5th Jan 2018 20:27    Post subject:
⁢⁢


Last edited by paxsali on Thu, 4th Jul 2024 23:30; edited 2 times in total
Back to top
Nalo
nothing



Posts: 13439

PostPosted: Fri, 5th Jan 2018 21:42    Post subject:
⁢⁢


Last edited by Nalo on Wed, 3rd Jul 2024 05:57; edited 2 times in total
Back to top
paxsali
Banned



Posts: 18352

PostPosted: Fri, 5th Jan 2018 21:44    Post subject:
⁢⁢


Last edited by paxsali on Thu, 4th Jul 2024 23:30; edited 2 times in total
Back to top
Nalo
nothing



Posts: 13439

PostPosted: Fri, 5th Jan 2018 22:40    Post subject:
⁢⁢


Last edited by Nalo on Wed, 3rd Jul 2024 05:57; edited 2 times in total
Back to top
Nalo
nothing



Posts: 13439

PostPosted: Fri, 5th Jan 2018 22:40    Post subject:
⁢⁢


Last edited by Nalo on Wed, 3rd Jul 2024 05:57; edited 2 times in total
Back to top
Janz




Posts: 13997

PostPosted: Fri, 5th Jan 2018 23:21    Post subject:
Back to top
Nalo
nothing



Posts: 13439

PostPosted: Sat, 6th Jan 2018 18:27    Post subject:
⁢⁢


Last edited by Nalo on Wed, 3rd Jul 2024 05:57; edited 2 times in total
Back to top
FusionDexterity




Posts: 1834

PostPosted: Sat, 6th Jan 2018 18:28    Post subject:
Project FEAR
Back to top
Przepraszam
VIP Member



Posts: 14398
Location: Poland. New York.
PostPosted: Sat, 6th Jan 2018 19:31    Post subject:
Nalo wrote:
I read the fixes for meltdown really screwup cpu performance :/


Combination of Microsoft fix AND microcode updates...
Shit looks really bad.


Back to top
3E74




Posts: 2559
Location: feels wrong
PostPosted: Sun, 7th Jan 2018 14:42    Post subject:
heres a tool, with wich you can check if the update fixed it..

https://ionescu007.github.io/SpecuCheck/


i guess im fine?


..:: Life - A sexually transmitted disease which always ends in death. There is currently no known cure::.. Troll Dad


Last edited by 3E74 on Sun, 7th Jan 2018 22:18; edited 1 time in total
Back to top
todd72173




Posts: 2402

PostPosted: Sun, 7th Jan 2018 16:06    Post subject:
Ran the intel exe. All my rigs show,. Guess because they are using Intel Pentium G32xx chips (not pro chips)
Status: This system is not vulnerable.


RYZEN 5 2600|RADEON 570| |ASRock X370 Killer|DDR4@2800Mhz||Corsair SPEC-05 Case|AOC G2590FX 24.5''144hz 1ms|
Back to top
freiwald




Posts: 6967

PostPosted: Sun, 7th Jan 2018 20:16    Post subject:
3E74 wrote:
heres a tool, with wich you can check if the update fixed it..

https://ionescu007.github.io/SpecuCheck/


i guess im fine?


heres another tool from intel:
https://downloadcenter.intel.com/download/27150?v=t


Quote:

Mitigations for CVE-2017-5754 [rogue data cache load]
-------------------------------------------------------
[-] Kernel VA Shadowing Enabled: yes
├───> with User Pages Marked Global: no
├───> with PCID Support: yes
└───> with INVPCID Support: yes

Your system either does not have the appropriate patch, or it may not support the information class required.


got all updates installed. intel tool says everything fine. the other tool only shows the small text above and not as much as on your picture. what to do now?!
Back to top
scaramonga




Posts: 9800

PostPosted: Sun, 7th Jan 2018 20:43    Post subject:
Hmmm!

Strange?, I never patched anything, and I have updates disabled Confused


Back to top
kalato




Posts: 1489
Location: Finland and UK
PostPosted: Sun, 7th Jan 2018 21:24    Post subject:
Quote:
This system is not vulnerable.


Intel i7 5820K here.


I like bum.
Back to top
freiwald




Posts: 6967

PostPosted: Sun, 7th Jan 2018 21:31    Post subject:
are you guys sure that the intel tool is for meltdown/spectre?
there was a intel ME security issue last month. isn't the tool just for that?
Back to top
3E74




Posts: 2559
Location: feels wrong
PostPosted: Sun, 7th Jan 2018 22:09    Post subject:
there was a intel ME security issue last month. isn't the tool just for that?

sorry, my bad. yes its the wrong intel tool.
f.v,ng links are hard to find from intel

its supposed to be this one:
http://www.malavida.com/en/soft/intels-meltdown-and-spectre-detection-tool/

Confused

i dont know, forget the intel tool, take the specthing or the power shell- script as mentioned here.

https://support.microsoft.com/en-us/help/4073119/protect-against-speculative-execution-side-channel-vulnerabilities-in


..:: Life - A sexually transmitted disease which always ends in death. There is currently no known cure::.. Troll Dad
Back to top
scaramonga




Posts: 9800

PostPosted: Sun, 7th Jan 2018 22:21    Post subject:
A major performance hit for the Fortnite servers .The CPU usage increased by 150% after the patch. That means they lost 60% performance.




More here:
https://www.epicgames.com/fortnite/forums/news/announcements/132642-epic-services-stability-update
Back to top
3E74




Posts: 2559
Location: feels wrong
PostPosted: Sun, 7th Jan 2018 22:23    Post subject:
freiwald wrote:
3E74 wrote:
heres a tool, with wich you can check if the update fixed it..

https://ionescu007.github.io/SpecuCheck/


i guess im fine?


heres another tool from intel:
https://downloadcenter.intel.com/download/27150?v=t


Quote:

Mitigations for CVE-2017-5754 [rogue data cache load]
-------------------------------------------------------
[-] Kernel VA Shadowing Enabled: yes
├───> with User Pages Marked Global: no
├───> with PCID Support: yes
└───> with INVPCID Support: yes

Your system either does not have the appropriate patch, or it may not support the information class required.


got all updates installed. intel tool says everything fine. the other tool only shows the small text above and not as much as on your picture. what to do now?!



heres what it says:

To run SpecuCheck, simply execute it on the command-line:

c:\SpecuCheck.exe

Which will result in an informational screen indicating which features/mitigations are enabled. If you see the text:

Your system either does not have the appropriate patch, or it may not support the information class required

This indicates that your system is not currently patched to mitigate against these vulnerabilities.

https://ionescu007.github.io/SpecuCheck/


also, intel knew this since 2012?
https://twitter.com/TheSimha/status/949361495468642304


if you want to test a bit with the exploit. have fun:

SpectrePoC
Proof of concept code for the Spectre CPU exploit.

https://github.com/crozone/SpectrePoC

german video with more info on this one:


..:: Life - A sexually transmitted disease which always ends in death. There is currently no known cure::.. Troll Dad
Back to top
3E74




Posts: 2559
Location: feels wrong
PostPosted: Mon, 8th Jan 2018 14:47    Post subject:
Intel released a list of the affected CPU´s

Quote:

Affected products:

For non-Intel based systems please contact your system manufacturer or microprocessor vendor (AMD, ARM, Qualcomm, etc.) for updates.

The following Intel-based platforms are impacted by this issue. Intel may modify this list at a later time. Please check with your system vendor or equipment manufacturer for more information regarding updates for your system.

Intel® Core™ i3 processor (45nm and 32nm)
Intel® Core™ i5 processor (45nm and 32nm)
Intel® Core™ i7 processor (45nm and 32nm)
Intel® Core™ M processor family (45nm and 32nm)
2nd generation Intel® Core™ processors
3rd generation Intel® Core™ processors
4th generation Intel® Core™ processors
5th generation Intel® Core™ processors
6th generation Intel® Core™ processors
7th generation Intel® Core™ processors
8th generation Intel® Core™ processors
Intel® Core™ X-series Processor Family for Intel® X99 platforms
Intel® Core™ X-series Processor Family for Intel® X299 platforms
Intel® Xeon® processor 3400 series
Intel® Xeon® processor 3600 series
Intel® Xeon® processor 5500 series
Intel® Xeon® processor 5600 series
Intel® Xeon® processor 6500 series
Intel® Xeon® processor 7500 series
Intel® Xeon® Processor E3 Family
Intel® Xeon® Processor E3 v2 Family
Intel® Xeon® Processor E3 v3 Family
Intel® Xeon® Processor E3 v4 Family
Intel® Xeon® Processor E3 v5 Family
Intel® Xeon® Processor E3 v6 Family
Intel® Xeon® Processor E5 Family
Intel® Xeon® Processor E5 v2 Family
Intel® Xeon® Processor E5 v3 Family
Intel® Xeon® Processor E5 v4 Family
Intel® Xeon® Processor E7 Family
Intel® Xeon® Processor E7 v2 Family
Intel® Xeon® Processor E7 v3 Family
Intel® Xeon® Processor E7 v4 Family
Intel® Xeon® Processor Scalable Family
Intel® Xeon Phi™ Processor 3200, 5200, 7200 Series
Intel® Atom™ Processor C Series
Intel® Atom™ Processor E Series
Intel® Atom™ Processor A Series
Intel® Atom™ Processor x3 Series
Intel® Atom™ Processor Z Series
Intel® Celeron® Processor J Series
Intel® Celeron® Processor N Series
Intel® Pentium® Processor J Series
Intel® Pentium® Processor N Series


Mr. Green Very Happy Well, my CPU is too old, aint affected, haha...Thats why in the one test it sayd, Disabled due to hardware support..

Good old Q9550...


..:: Life - A sexually transmitted disease which always ends in death. There is currently no known cure::.. Troll Dad
Back to top
StrEagle




Posts: 14059
Location: Balkans
PostPosted: Mon, 8th Jan 2018 15:39    Post subject:
Back to top
scaramonga




Posts: 9800

PostPosted: Tue, 9th Jan 2018 02:47    Post subject:
Anyone stupid enough to put Win10 patch on yet? lol Laughing
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Tue, 9th Jan 2018 04:08    Post subject:
Why? Apparently the performance impact for the average user is negligible while getting rid of the security vulnerabilities.


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
Page 1 of 5 All times are GMT + 1 Hour
NFOHump.com Forum Index - Hardware Zone Goto page 1, 2, 3, 4, 5  Next
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group