A Dirty Little History - Bypassing Spectre Hardware Defenses to Leak Kernel Data
Offered By: Black Hat via YouTube
Course Description
Overview
Explore a 33-minute Black Hat conference talk that delves into the evolution of Spectre attacks and their ability to bypass hardware defenses. Learn about Branch Target Injection (BTI) and how it exploits misprediction in indirect branches to execute attacker-controlled instructions. Discover the researchers' findings on bypassing Spectre mitigations in modern CPUs, including their reverse engineering efforts and the discovery of a new Spectre variant. Gain insights into the practical implications through a live demonstration and understand the vendor responses to these vulnerabilities. Suitable for cybersecurity professionals and those interested in advanced hardware security topics.
Syllabus
Introduction
Project Overview
Spectrum
Indirect Branch
Branch History Injection
Reverse Engineering
Recap
Cisco Table Handler
Finding a Spectre Gadget
Spectra Variant 2
Live Demo
Vendor Response
Conclusion
Taught by
Black Hat
Related Courses
Ethical Hacking in 15 Hours - 2023 Edition - Learn to HackCyber Mentor via YouTube Contextomy - Let's Debug Together
nullcon via YouTube macOS Security Features Bypasses by Example
nullcon via YouTube Exploiting Android Messengers with WebRTC
nullcon via YouTube XNU Heap Exploitation - From Kernel Bug to Kernel Control
nullcon via YouTube