Last month, Victor and Herbert gave a lecture about buffer overflows and return-oriented programming on Dutch national TV.
All posts by Cristiano Giuffrida
Drammer in the news
Drammer was presented at CCS 2016 3 weeks ago. Our work shows that the Rowhammer hardware vulnerability is prevalent on mobile devices and that attackers can exploit it in a deterministic manner (a la Flip Feng Shui).
Press, Vendor Coverage & Discussion
After initial coverage in the form of two written articles by Ars Technica and WIRED, and a podcast from Security Now!, Drammer was quickly picked up by the mainstream press. International items include: Daily Mail, PCWorld, Softpedia, Slashdot, Tech Times, The Register, Fossbytes, The Inquirer, Digital Journal, Hack Read, SC Magazine, Threatpost, BetaNews, Gamenguide, TechTarget, BleepingComputer, NDTV, On the Wire, and InvestorPlace.
Other local items popped up in Argentina (Segu-info), Austria (Der Standard), Belgium (DeMorgen), China (Freebuff, Sohu, EEPW), Czech Republic (Svět Androida), Denmark (Version2), France (Silicon, Le Monde Informatique, Informanews), Germany (Der Spiegel, Golem.de, Pro-Linux, Crn.de, JAXenter, Computer Bild , t3n Magazine, Netzwelt.de), Hungary (HWSW), Italy (Repubblica.it, Punto Informatico, Gadgetblog.it, Tutto Android), Mexico (PCWorld Mexico), The Netherlands (NU.nl, Tweakers.net, Crimesite), Norway (Digi.no), Poland (eGospodarka, Softonet, PCLab.pl, Dobreprogramy, PC Format, Telix.pl), Russia (Хакер, Securitylab.ru), Slovakia (Živé.sk), Spain (López Dóriga, CSO, El Android libre), Switzerland (Neue Zürcher Zeitung), Taiwan (iThome), Turkey (Teknokulis, CHIP, Webtekno), and Ukraine (KO).
Bruce Schneier linked to our project page and we made it to the front page of The Hacker News. Shortly after, Drammer prompted Rowhammer mitigation efforts on LWN and was discussed by Linus Torvalds on Alan Cox’ Google Plus post. We caused a spike in Google queries for Rowhammer, approaching its popularity from 2015, when Google’s Project Zero released the Rowhammer-based exploit.
The Drammer paper (pdf) was accessed over 25k times, while our github repository received 913 unique views and 83 unique clones.
Drammer made an appearance on Dutch national television in an episode of De Universiteit van Nederland (“The University of The Netherlands”).
Drammer: Flip Feng Shui goes mobile
Our Drammer paper and information page are finally online. Flip Feng Shui (aka deterministic Rowhammer) attacks coming to an Android device near you!
4 papers accepted at NDSS
This year, VUSec had 4 papers accepted at NDSS ’17: AnC (a new side-channel-based ASLR bypass), SafeInit (efficient protection against uninitialized reads), a new evolutionary fuzzer (AFL on steroids), and Marx (uncovering class hierarchies in C++ programs, with @thorstenholz’s group at @ruhrunibochum).
2 papers accepted at EuroS&P
This year, VUSec had 2 papers accepted at EuroS&P ’17: Nucleus (compiler-agnostic function detection) and CodeArmor (how to efficiently re-randomize code every few microseconds).
VUSec at Black Hat Europe
VUSec has two presentations accepted at Black Hat Europe this year: (i) Flip Feng Shui (Rowhammer+dedup for reliable bit flip exploitation) and (ii) clang’s SafeStack bypass based on our thread spraying and allocation oracles work on information hiding.
Flip Feng Shui in the news
Flip Feng Shui was presented at USENIX Security 2016 2 weeks ago. This novel attack technique combines a hardware vulnerability with a physical memory massaging primitive to mount a reliable attacks anywhere in the software stack. In particular, we demonstrate practical cross-VM attacks on OpenSSH and GnuPG using Rowhammer and KSM.
Impact
Given its practical impact, the Dutch National Cybersecurity Centre took the lead in disclosing Flip Feng Shui. They initiated disclosure to their counterparts in several other countries, as well as to application vendors, OS vendors, hypervisor vendors, and cloud providers. Prior to our talk at USENIX Security, the details of this technique were kept private.
Press & Vendor Coverage
The press has also picked up on this and there is quite some coverage. Arstechnica has a thorough piece on this work. Steve Gibson described Flip Feng Shui as “the most incredibly righteous and sublime hack… ever” in one of the Security Now! podcasts. WIRED also has the right idea: Forget Software—Now Hackers Are Exploiting Physics. Bruce Schneier posted a news item on his blog and there are podcasts by Risky Business (http://risky.biz/RB422 @ 31:40). Other international news items include: The Register, Infoworld, Slashdot, The Stack, Softpedia, Science Daily, and CORDIS.
Other local items popped up in China (Tech.qq.com, Sohu), Finland (Viestintävirasto), France (Silicon), Germany (Deutschlandfunk), Italy (Repubblica.it, HostingTalk), The Netherlands (Security.nl, Computable, Tweakers.net), Poland (Sekurak), Russia (Securitylab.ru), Spain (WWWhat’s new), Ukraine (KO).
The NCSC published a press release with fact sheet and FAQ. Prominent cloud providers posted news items, some of which disabled memory deduplication as a result.
The Dutch TV show “De Kennis van Nu” (roughly: “The knowledge of today”) had an item on Flip Feng Shui and Rowhammer, with Ben and Kaveh acting all hacker-like. (Dutch only)
#rowhammer #openssh #cloud-attack #apt-get Ben currently presenting Flip Feng Shui at Usenix Security 2017 in Austin,TX
Dedup Est Machina wins the Pwnie Award at Black Hat USA
Our Dedup Est Machina S&P paper (abusing memory deduplication and Rowhammer to own Microsoft Edge on Windows 10 without software vulnerabilities) won the Pwnie Award for Most Innovative Research at Black Hat USA.
Article (in Dutch) about this in De Volkskrant.
2 papers accepted at CCS
This year, VUSec had 2 papers accepted at CCS: Drammer (Deterministic Rowhammer attacks) and TypeSan (a practical type confusion detector).