HomeSecurityGreek researchers identify Intel weakness

Greek researchers identified a weakness in Intel

Intel

Greek researchers identified a weakness in Intel

Four Columbia University boffins have said they can spy on keystrokes and mouse clicks from a web browser tab by hijacking Intel processor caches.

The exploit is very effective on computers running the latest Intel processors, such as Core i7 processors, and works flawlessly in browsers . So you can imagine that we are talking about 80 percent of the systems in circulation.

Yossef Oren, Simha Sethumadhavan and Greeks Vasileios Kemerlis and Angelos Keromitis have discovered an attack that can be carried out with JavaScript served by a malicious ad network. It works by studying the time it takes to access data stored in the last-level cache (the L3 cache is used by all cores in a PC). From this, they discover the user's activity.

The research has been requested by many major companies such as: Google, Microsoft, Mozilla and Apple to upgrade their browsers and stop the attack.

Dr. Oren stated:

 "It's a low-cost attack that could probably be used for a short period of time by bad guys (you know the ones that bombard you with pop-up ads). They could add this JavaScript to their pop-ups."

The team's paper, released in PDF format, titled The Spy in the Sandbox – Practical Cache Attacks in JavaScript, states that victims do not need to install any additional software, simply visit a page containing malicious JS.

Once the malicious JavaScript code starts running, it brings the cache to a known state, and waits for the user to press a key. It then uses a high-resolution browser timer to record the time it takes to move through a block of memory. With this information, the attacker can map the pattern of memory accesses for each keystroke and mouse movement, which can later be reproduced.

With an Intel Core i7 processor on a Mac OS X 10.10.2 machine and Firefox 35.0.1 browser, JS was able to map half of the L3 cache in a minute, and about a quarter in about 30 seconds.

The research is academic in nature, and not particularly practical, but it challenges the assumption that most attacks should be in close proximity to their victims, and execute arbitrary native code.

The team estimates that the attack works on any modern Intel processor running an HTML5 browser. AMD chips cannot be attacked due to the design of the cache.

 

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS