Hacking on Medium
Ethical Hacker’s Handbook: Navigating the Digital Frontier Responsibly
https://cdn-images-1.medium.com/max/770/1*pKEV70g_PWZrdvWpDfXkIg.jpeg
Continue reading on Medium »
Ethical Hacker’s Handbook: Navigating the Digital Frontier Responsibly
https://cdn-images-1.medium.com/max/770/1*pKEV70g_PWZrdvWpDfXkIg.jpeg
Continue reading on Medium »
Medium
Ethical Hacker’s Handbook: Navigating the Digital Frontier Responsibly
“Ethical Hacker’s Handbook: Navigating the Digital Frontier Responsibly” is published by Triptipandey.
Hacking on Medium
How I secured Pakistan’s famous educational website.
https://cdn-images-1.medium.com/max/600/1*SvhJqJfL3fKppWst7IWRIQ.gif
Greetings, In this blog I want to share how I was able to secure an educational website that most of the high school students are familiar…
Continue reading on Medium »
How I secured Pakistan’s famous educational website.
https://cdn-images-1.medium.com/max/600/1*SvhJqJfL3fKppWst7IWRIQ.gif
Greetings, In this blog I want to share how I was able to secure an educational website that most of the high school students are familiar…
Continue reading on Medium »
Medium
How I secured Pakistan’s famous educational website.
Greetings, In this blog I want to share how I was able to secure an educational website that most of the high school students are familiar…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tips to Protect Family on Telegram Messenger
https://cdn-images-1.medium.com/max/600/1*23HIsj05lBu2m-OGRWj4PA.png
In the ever-evolving world of technology, messaging apps like Telegram have become increasingly popular for their secure and versatile…
Continue reading on Medium »
Tips to Protect Family on Telegram Messenger
https://cdn-images-1.medium.com/max/600/1*23HIsj05lBu2m-OGRWj4PA.png
In the ever-evolving world of technology, messaging apps like Telegram have become increasingly popular for their secure and versatile…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I was able to takeover 4000+ users account
https://cdn-images-1.medium.com/max/642/0*fbwXxV3Z1GYCIwgy
How I was able to takeover 4000+ users account
Continue reading on Medium »
How I was able to takeover 4000+ users account
https://cdn-images-1.medium.com/max/642/0*fbwXxV3Z1GYCIwgy
How I was able to takeover 4000+ users account
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Discover Hidden Web Directories with Dirhunt v0.6.0 — No Bruteforce Required!
Are you tired of brute forcing web directories to find hidden content? Look no further! In this video, we introduce Dirhunt v0.6.0, a…
Continue reading on Medium »
Discover Hidden Web Directories with Dirhunt v0.6.0 — No Bruteforce Required!
Are you tired of brute forcing web directories to find hidden content? Look no further! In this video, we introduce Dirhunt v0.6.0, a…
Continue reading on Medium »
How I was able to takeover 4000+ users account
How I was able to takeover 4000+ users accountContinue reading on Medium »
Read more...
How I was able to takeover 4000+ users accountContinue reading on Medium »
Read more...
Medium
How I was able to takeover 4000+ users account
How Hackers Are Stealing Millions Using CHATGPT
hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…Continue reading on Medium »
Read more...
hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…Continue reading on Medium »
Read more...
Medium
How Hackers Are Stealing Millions Using CHATGPT
hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…
SECRET Chat Leak EXPOSED Russian Hackers | Conti Explained
Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…Continue reading on Medium »
Read more...
Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…Continue reading on Medium »
Read more...
Medium
SECRET Chat Leak EXPOSED Russian Hackers | Conti Explained
Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…
Ethical Hacker in The World Explains The Dark Web
I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…Continue reading on Medium »
Read more...
I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…Continue reading on Medium »
Read more...
Medium
Ethical Hacker in The World Explains The Dark Web
I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…
How Hackers Are Stealing Millions Using CHATGPT
https://medium.com/@stylishcollection666/how-hackers-are-stealing-millions-using-chatgpt-e7cf889ffb85?source=rss------bug_bounty-5
https://medium.com/@stylishcollection666/how-hackers-are-stealing-millions-using-chatgpt-e7cf889ffb85?source=rss------bug_bounty-5
hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…Continue reading on Medium » (https://medium.com/@stylishcollection666/how-hackers-are-stealing-millions-using-chatgpt-e7cf889ffb85?source=rss------bug_bounty-5)
SECRET Chat Leak EXPOSED Russian Hackers | Conti Explained
https://medium.com/@stylishcollection666/secret-chat-leak-exposed-russian-hackers-conti-explained-7f4da6f4c0e?source=rss------bug_bounty-5
https://medium.com/@stylishcollection666/secret-chat-leak-exposed-russian-hackers-conti-explained-7f4da6f4c0e?source=rss------bug_bounty-5
Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…Continue reading on Medium » (https://medium.com/@stylishcollection666/secret-chat-leak-exposed-russian-hackers-conti-explained-7f4da6f4c0e?source=rss------bug_bounty-5)
Ethical Hacker in The World Explains The Dark Web
https://medium.com/@stylishcollection666/ethical-hacker-in-the-world-explains-the-dark-web-d8c11a42d48c?source=rss------bug_bounty-5
https://medium.com/@stylishcollection666/ethical-hacker-in-the-world-explains-the-dark-web-d8c11a42d48c?source=rss------bug_bounty-5
I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…Continue reading on Medium » (https://medium.com/@stylishcollection666/ethical-hacker-in-the-world-explains-the-dark-web-d8c11a42d48c?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data
Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Google’s renowned security researcher Tavis Ormandy has uncovered a significant vulnerability called Zenbleed affecting AMD Zen2 CPUs, posing a serious risk of data theft. The flaw, tracked as CVE-2023-20593, allows malicious actors to pilfer sensitive information, including passwords and encryption keys, at an alarming rate of 30KB/sec from each CPU core.
The root cause of this vulnerability lies in the improper handling of the ‘vzeroupper’ instruction during speculative execution, a widely-used performance-enhancing technique employed in modern processors.
Ormandy employed fuzzing and performance counters to identify specific hardware events, validating his findings using the “Oracle Serialization” approach. This method enabled the detection of inconsistencies between the execution of a randomly generated program and its serialized oracle, leading to the discovery of CVE-2023-20593 in Zen2 CPUs.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Zenbleed PoCWith an optimized exploit for the flaw, the researcher successfully demonstrated how sensitive data from various system operations, including those within virtual machines, isolated sandboxes, and containers, could be leaked.
“I found a variant that can leak about 30 kb per core, per second. This is fast enough to monitor encryption keys and passwords as users login!,” elaborated Ormandy in a technical write-up.
After notifying AMD about the flaw on May 15, 2023, the researcher has now published a proof-of-concept (PoC) exploit for CVE-2023-20593, impacting all operating systems running on Zen 2 CPUs.
First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! https://t.co/NVPWFpVopz pic.twitter.com/HgKwu9w8Av
— Tavis Ormandy (@taviso) July 24, 2023
The vulnerability affects numerous AMD CPUs built on the Zen 2 architecture, including Ryzen 3000 (“Matisse”), Ryzen 4000U/H (“Renoir”), Ryzen 5000U (“Lucienne”), Ryzen 7020, and high-end ThreadRipper 3000 and Epyc server (“Rome”) processors.
AMD has released an updated microcode to address the issue, and users are strongly advised to apply the fix or await BIOS upgrades from their computer vendors.
Trending: Unlocking Windows System Resource Utilization for Digital Forensics Analysis with SRUM Dump Trending: Digital Forensics Tool: ScrapPy
Ormandy suggests an alternative mitigation method involving setting the “chicken bit” to DE_CFG[9], though this may lead to a drop in CPU performance.
Detection of exploitation is challenging, as the improper usage of ‘vzeroupper’ does not require elevated privileges or special system calls, making the Zenbleed exploit stealthy and potentially hard to trace.
For regular users, the practical impact of Zenbleed is relatively low, as exploiting it requires local access to the target system and a high level of expertise. Nonetheless, maintaining up-to-date systems with the latest security patches and BIOS updates is crucial to mitigate potential risks.
Trending: WormGPT: Unleashing the Dark Side of Generative AI for Cybercrime
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sh[...]
Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data
Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Google’s renowned security researcher Tavis Ormandy has uncovered a significant vulnerability called Zenbleed affecting AMD Zen2 CPUs, posing a serious risk of data theft. The flaw, tracked as CVE-2023-20593, allows malicious actors to pilfer sensitive information, including passwords and encryption keys, at an alarming rate of 30KB/sec from each CPU core.
The root cause of this vulnerability lies in the improper handling of the ‘vzeroupper’ instruction during speculative execution, a widely-used performance-enhancing technique employed in modern processors.
Ormandy employed fuzzing and performance counters to identify specific hardware events, validating his findings using the “Oracle Serialization” approach. This method enabled the detection of inconsistencies between the execution of a randomly generated program and its serialized oracle, leading to the discovery of CVE-2023-20593 in Zen2 CPUs.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Zenbleed PoCWith an optimized exploit for the flaw, the researcher successfully demonstrated how sensitive data from various system operations, including those within virtual machines, isolated sandboxes, and containers, could be leaked.
“I found a variant that can leak about 30 kb per core, per second. This is fast enough to monitor encryption keys and passwords as users login!,” elaborated Ormandy in a technical write-up.
After notifying AMD about the flaw on May 15, 2023, the researcher has now published a proof-of-concept (PoC) exploit for CVE-2023-20593, impacting all operating systems running on Zen 2 CPUs.
First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! https://t.co/NVPWFpVopz pic.twitter.com/HgKwu9w8Av
— Tavis Ormandy (@taviso) July 24, 2023
The vulnerability affects numerous AMD CPUs built on the Zen 2 architecture, including Ryzen 3000 (“Matisse”), Ryzen 4000U/H (“Renoir”), Ryzen 5000U (“Lucienne”), Ryzen 7020, and high-end ThreadRipper 3000 and Epyc server (“Rome”) processors.
AMD has released an updated microcode to address the issue, and users are strongly advised to apply the fix or await BIOS upgrades from their computer vendors.
Trending: Unlocking Windows System Resource Utilization for Digital Forensics Analysis with SRUM Dump Trending: Digital Forensics Tool: ScrapPy
Ormandy suggests an alternative mitigation method involving setting the “chicken bit” to DE_CFG[9], though this may lead to a drop in CPU performance.
Detection of exploitation is challenging, as the improper usage of ‘vzeroupper’ does not require elevated privileges or special system calls, making the Zenbleed exploit stealthy and potentially hard to trace.
For regular users, the practical impact of Zenbleed is relatively low, as exploiting it requires local access to the target system and a high level of expertise. Nonetheless, maintaining up-to-date systems with the latest security patches and BIOS updates is crucial to mitigate potential risks.
Trending: WormGPT: Unleashing the Dark Side of Generative AI for Cybercrime
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sh[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-c…
aring?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Copy-of-Images-for-the-News-posts-300x150.png HotRat Malware -The Sneaky Trojan Lurking in Cracked SoftwareJuly 24, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-12-300x150.png New P2PInfect Malware, Self-Spreading Worm Targets Redis Instances on Internet-Exposed SystemsJuly 21, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-11-300x150.png DeliveryCheck: Turla’s New Cyberweapon Strikes Microsoft Exchange Servers and Defense SectorJuly 20, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-10-300x150.png WormGPT: Unleashing the Dark Side of Generative AI for CybercrimeJuly 19, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data first appeared on Black Hat Ethical Hacking.
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Copy-of-Images-for-the-News-posts-300x150.png HotRat Malware -The Sneaky Trojan Lurking in Cracked SoftwareJuly 24, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-12-300x150.png New P2PInfect Malware, Self-Spreading Worm Targets Redis Instances on Internet-Exposed SystemsJuly 21, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-11-300x150.png DeliveryCheck: Turla’s New Cyberweapon Strikes Microsoft Exchange Servers and Defense SectorJuly 20, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-10-300x150.png WormGPT: Unleashing the Dark Side of Generative AI for CybercrimeJuly 19, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data first appeared on Black Hat Ethical Hacking.