/?pid=netcat-vulnerability-exploits-ddio-on-intel-xeon-processors-to-steal-d-21141

Updated:08:37 AM EDT Apr 20


this is ggmania.com subsite NetCAT Vulnerability Exploits DDIO on Intel Xeon Processors to Steal D - TechAmok

NetCAT Vulnerability Exploits DDIO on Intel Xeon Processors to Steal D - [security]
09:33 AM EDT - Sep,11 2019 - post a comment

DDIO, or Direct Data I/O, is an Intel-exclusive performance enhancement that allows NICs to directly access a processor's L3 cache, completely bypassing the a server's RAM, to increase NIC performance and lower latencies. Cybersecurity researchers from the Vrije Universiteit Amsterdam and ETH Zurich, in a research paper published on Tuesday, have discovered a critical vulnerability with DDIO that allows compromised servers in a network to steal data from every other machine on its local network. This include the ability to obtain keystrokes and other sensitive data flowing through the memory of vulnerable servers. This effect is compounded in data centers that have not just DDIO, but also RDMA (remote direct memory access) enabled, in which a single server can compromise an entire network. RDMA is a key ingredient in shoring up performance in HPCs and supercomputing environments. Intel in its initial response asked customers to disable DDIO and RDMA on machines with access to untrusted networks, while it works on patches.

The NetCAT vulnerability spells big trouble for web hosting providers. If a hacker leases a server in a data-center with RDMA and DDIO enabled, they can compromise other customers' servers and steal their data. "While NetCAT is powerful even with only minimal assumptions, we believe that we have merely scratched the surface of possibilities for network-based cache attacks, and we expect similar attacks based on NetCAT in the future," the paper reads. We hope that our efforts caution processor vendors against exposing microarchitectural elements to peripherals without a thorough security design to prevent abuse." The team also published a video briefing the nature of NetCAT. AMD EPYC processors don't support DDIO.


Short overview of recent news articles

Backing Up My NAS To My... Parents' House? (Apr,20 2024 )

NEW Ryzen APU BEATS RTX 40 GPUs! (Apr,20 2024 )

(Live) Black Tape Project - All New Raw and Uncut - LA Fashion Week (Apr,20 2024 )

NVIDIA Geforce 552.22 WHQL Driver (Apr,19 2024 )

You Deserve this much OLED - AORUS CO49DQ (Apr,19 2024 )

Unreal Engine 5.4 looks ULTRA PHOTOREALISTIC (Apr,19 2024 )

Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit (Apr,18 2024 )

I Will Build You a PC Right Now! (Apr,18 2024 )

These games carry REAL security risks! BEWARE! (Apr,17 2024 )

Visible First to Offer Annual Payment Plan, with Discount up to 26% (Apr,17 2024 )

Is Coding Still Worth Learning in 2024? (Apr,17 2024 )

All New Atlas - Boston Dynamics (Apr,17 2024 )

The NEW Chip Inside Your Phone! (NPUs) (Apr,16 2024 )

XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel! (Apr,16 2024 )

The Most 2024 Laptop - Razer Blade 14 Review (Apr,15 2024 )

NEVER install these programs on your PC... EVER!!! (Apr,15 2024 )

Use Live Translate on Galaxy S24 series to translate a call's (Apr,14 2024 )

I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam? (Apr,14 2024 )

Samsung Galaxy Ring - This Just Got Interesting (Apr,13 2024 )

Piracy Is Over Party - WAN Show April 12, 2024 (Apr,13 2024 )

Conan O'Brien Needs a Doctor While Eating Spicy Wings (Apr,13 2024 )

Beatbox Jcob recreats every sound (Apr,13 2024 )

Intel is Gunning for NVIDIA (Apr,13 2024 )

Building a Budget DIY Home Surveillance System (Apr,13 2024 )

Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop (Apr,12 2024 )

DARK MATTER Trailer (2024) New Sci-Fi Movies 4K (Apr,11 2024 )

How to Build a PC, the last guide you'll ever need! (2024 Update) (Apr,11 2024 )

Intel 300 CPU Review - The Pentium Replacement is Finally Here... (Apr,10 2024 )

Wubuntu, the Dubious Linux Windows (Apr,10 2024 )

A Lite Version Of Windows 11 To Be Released This Year (Apr,09 2024 )

This $150 Smartphone might be All You Need (Apr,09 2024 )

I Can't Believe These are Real - Reacting to Ridiculous PCs on (Apr,09 2024 )

A new video shows AirPower prototype charging an Apple Watch (Apr,08 2024 )

Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved (Apr,08 2024 )

20 COOL GADGETS YOU SHOULD SEE (Apr,08 2024 )

New HTTP/2 vulnerability leaves servers in danger of devastating DoS (Apr,08 2024 )

3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance? (Apr,07 2024 )

The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024 (Apr,06 2024 )

Top NEW RELEASES on Netflix in APRIL 2024 (Apr,06 2024 )

Magician vs Slow-Mo Camera (Skill Challenge) (Apr,05 2024 )

Re-Ranking All Current GPUs From Worst to Best (2024 Update) (Apr,05 2024 )

Ripple to ISSUE STABLE COIN utilizing XRP AUTO-Bridging Function (Apr,04 2024 )

HW News - Intel Battlemage Appears, Open Source GPU, Xbox Handheld (Apr,04 2024 )

Vivo X Fold 3 Pro Hands-On: The New Best Foldable Hardware (Apr,03 2024 )

OPNSense: Protect Your Home LAN With a Transparent Filtering Bridge (Apr,02 2024 )

Ultimate Guide to Virtualization: Run MacOS, Linux, and Windows all (Mar,31 2024 )

This MIGHT be the best NAS on the market (Mar,31 2024 )

What do Zen 5, Arc Battlemage and NVIDIA RTX 50 GPUs Have In Common? (Mar,31 2024 )

They FIXED the Dual Chamber Problem! (Mar,31 2024 )

Paying for Cloud Storage is Stupid (Mar,30 2024 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs