HomeSecurityNew Rowhammer technique bypasses DDR4 memory defenses

New Rowhammer technique bypasses DDR4 memory defenses

Researchers have developed a new fuzzing -based technique called " Blacksmith " that revives Rowhammer vulnerability attacks against modern DRAM devices, bypassing existing protection measures.

Rowhammer

See also: Rowhammer attacks: They even “hit” modern RAM!

The emergence of this new Blacksmith method demonstrates that today's DDR4 modules are vulnerable to exploitation, allowing a variety of attacks to be carried out.

Rowhammer is a security exploit that relies on the leakage of electrical charges between adjacent memory cells, allowing a malicious actor to flip 1s and 0s and change the contents in memory.

This powerful attack can bypass all software-based security mechanisms, leading to privilege escalation, memory corruption, and more.

It was first discovered in 2014 and within a year, two privilege escalation exploits were already available.

Gradually, this became a widespread problem and even Android tools were developed that exploited the Rowhammer vulnerability in smartphones to gain root access.

See also: Android malware MasterFred: Targets Netflix, Instagram & Twitter users

DDR4

The mitigations implemented to address this problem first appeared insufficient in March 2020, when academic researchers demonstrated that it was possible to circumvent them.

Manufacturers had implemented a set of mitigations called “Target Row Refresh” (TRR), which was mainly effective in keeping the then-new DDR4 safe from attacks.

The attack used against him was called "TRRespass" and was another fuzzing-based technique that successfully found exploitable Rowhammering patterns.

The newest DDR5 DRAM modules are already available in the market and their adoption will accelerate over the next two years.

See also: Ransomware cyberattack on Danaos and Greek shipping companies

In DDR5, Rowhammer may not be as big of a problem, as TRR is replaced by “refresh management,” a system that monitors activations in a bank and issues selective refreshes once a threshold is reached.

This means that scalable fuzzing on a DDR5 DRAM device would be much more difficult and potentially much less effective, but that remains to be seen.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS