Spaghettifying DRAM (github.com)

424 points by matt_d 7 hours ago

MattSteelblade 7 hours ago

I cannot wait for the accompanying Black Hat talk. Christopher Domas is one of my absolute favorite all-time hackers. He does such a fantastic job of explaining his work. Some of my favorite talks of his:

- Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc

- The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk

- Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g

nerdsniper 4 hours ago

My introduction to his work was "The future of RE Dynamic Binary Visualization"[0] which completely blew me away. It still feels futuristic today, 13 years later. Novel UI/UX paradigms like this are slow to find widespread adoption, even when they're so clearly demonstrated to be such an ideal fit for their purpose.

0: https://www.youtube.com/watch?v=4bM3Gut1hIk&pp=ygURY2hyaXN0b...

superkuh 4 hours ago

I love digraphs. I learned about them from that talk's associated paper... but only about 2 years ago. I've been dumping my system and GPU RAM raw and visualizing via digraphs and it's amazing how such a simple algorithm operating on arbitrary bytes leads to such distinct and consistent image.

anthk 4 hours ago

TBH with the DDD debugger you had a graph with the C structures right away.

3abiton 2 minutes ago

Alright, a new series to binge now.

Hasz 7 hours ago

If this is the same dude I am thinking of, his wife is also the CISO of Mozilla and do security research together, afair they have a whole book on x86 reverse engineering.

Very cool!

Intermernet 4 hours ago

x86 Software Reverse‐Engineering, Cracking, and Counter‐Measures By Stephanie Domas and Christopher Domas

https://onlinelibrary.wiley.com/doi/book/10.1002/97813942771...

saagarjha 20 minutes ago

> He does such a fantastic job of explaining his work.

He did a fantastic job of explaining his work.

dgellow 11 minutes ago

What do you mean? Did he pass away?

saagarjha 7 minutes ago

ChocMontePy 3 hours ago

I saw a recent video and I was shocked that he had hair:

https://www.youtube.com/watch?v=iOq8O_phwbA

He looks so different.

jambalaya8 6 hours ago

His stuff is something else.

weinzierl 4 hours ago

When I started with computers, DRAM was understandable by a teenager: RAS, CAS, read, done.

Ok, the necessary refresh was always a little pain, but still something manageable.

Nowadays, I feel you need three PhD's to even bring up a micro with DRAM and don't get me started on the proprietary binary blobs necessary just for DRAM access. No wonder PSRAM is a thing.

The corollary is that it shouldn't be too surprising that this gigantic attack surface provides many opportunities. (Of course that doesn't mean it is easy to find them, hat tip to Christopher Domas, just that I expect there to be many more).

WhiteDawn 5 hours ago

This is all great to get full unfettered access to your own system, as life should be.

I’m sure Xbox and PlayStation security groups are a little nervous right now though. Getting ring-0 on those machines is near impossible, but once you do then everything else becomes wide open

ammar2 3 hours ago

Not sure if it opens up that much on them as far as their security processors go. Modern consoles already treat DRAM as completely untrusted (an attacker could just sit on the DRAM bus and sniff/issue requests there).

The Xbox One for example encrypts all the DRAM it uses after it gets out of the main CPU die. See this part of Tony Chen's presentation https://youtu.be/U7VwtOrwceo?t=956

Also see this bit on the Apple Secure Enclave in the "Memory Protection Engine" section which also explains how they encrypt stuff stored in DRAM: https://support.apple.com/guide/security/the-secure-enclave-...

PunchyHamster 3 hours ago

wouldn't request after DRAM controller be unencrypted ? Would need to have different key per memory type and even then you could do some damage as realistically it won't have number of keys equal to running processes

crote 2 hours ago

ransom_rs 5 hours ago

Seems like this should get us a newer PS4 jailbreak?

ChocolateGod an hour ago

Xbox One runs everything under HyperV, so any user created code likely doesn't have the hardware access to use this exploit.

gmueckl 6 hours ago

OK, so this works on AMD Jaguar according to the README. That's a architecture from 2013. There's notes about Zen 3 having a different base address for the memory controller registers, but that's it. What newer CPUs does attack actually work on?

zerohp 2 hours ago

CPU designers have been aware of this attack vector for a while, so many (maybe all) have controls to lock these registers. They are written and locked by vendor firmware before it hands off to the operating system.

You would have first break the firmware or locks before an attack like this on a modern CPU

devttyeu 5 hours ago

Zen has completely different memory controller IP (UMC), that's configured at boot by AGESA/PSP. I doubt this exploit applies to modern Zen CPUs, however AMD are the only ones who could really confirm this.

CartwheelLinux 6 hours ago

That information is intentionally left out

tecleandor 3 hours ago

It's on the second paragraph, titled "Target".

> Developed and tested on AMD Family 16h CPUs, the last generation whose datasheets document the DRAM controller's translation registers

gmueckl 5 hours ago

Then publishing it in this incomplete state is just pointless fearmongering and will just make others fill in this information within the next couple of days. And the good guys likely won't be the first ones to do that.

dzdt 7 hours ago

So on an affected system, ring 0 root has access to pretty much everything that was hidden in negative ring territory. The page is pretty quiet about what other processor families might be similar beyond this specific AMD16h (an older AMD low-power family)?

m1el 6 hours ago

from the GH page: > Developed and tested on AMD Family 16h CPUs, the last generation whose datasheets document the DRAM controller's translation registers — and show that they can't be locked. 17h and beyond simply leave this information out.

embedding-shape 6 hours ago

As long as you know the controller's translation registers, it's applicable? Not tested on later one's merely because the information wasn't readily available it seems.

> Developed and tested on AMD Family 16h CPUs, the last generation whose datasheets document the DRAM controller's translation registers — and show that they can't be locked. 17h and beyond simply leave this information out.

zahlman 5 hours ago

This is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?

creshal 4 hours ago

Reaching into ring -2 or the TPM allows privilege escalations past traditional "root permissions" and lets attackers defeat the sort of tamper protection that's designed to make escalations to local root manageable. Wipe-resistant malware, falsified cryptographic attestations, all sorts of fun.

jandrese 4 hours ago

This is more about getting at the code that device manufacturers attempt to hide from the end user. Platform keys, secure enclaves, etc...

odo1242 5 hours ago

Yep, I believe so

ziofill 4 hours ago

But it supercharges what can be done once you get root, no?

MayeulC an hour ago

UltraSane 4 hours ago

odo1242 4 hours ago

raver1975 4 hours ago

I spaghettify my memory every time I write C code.

matheusmoreira 2 hours ago

So what's inside Intel ME, AMD PSP and associaded firmwares? Don't leave us hanging here...

randyrand 2 hours ago

I’m confused. Why is this remapping option exposed to userspace?

devttyeu 6 hours ago

The big question is whether this can break out of KVM and whether it can be microrode patched / patched in any other way.

And whether it's really real in the first place.

vsrinivas 41 minutes ago

1) Don't give your guests access to the DCT control registers.

2) On 15h - no obvious way. I don't know the other families.

3) Yes -- this can be verified easily. Pick up the AMD 15h BKDG, look up BankSwizzleMode. It's documented. The one oversight is that this bit is not under the Dram Controller's lock bit.

summa_tech 6 hours ago

One hopes that a hypervisor would not expose hardware control registers directly in the first place, except ones deliberately designed for virtualization support.

Otherwise, the guest is running effectively at the same privilege level as the hypervisor (that's useful sometimes, but probably not intended in most applications).

devttyeu 6 hours ago

Yeah, just started looking at this with my team (we run a cloud with VM instance offering on AMD so this very much caught our eye)

So far seems this is about right:

1. You need platform register access, so seems can't KVM-escape with just this

2. Big question is what about breaking Confidential SEV-SNP guests from the host?

devttyeu 6 hours ago

bri3d 3 hours ago

quotemstr 6 hours ago

This hack is 99% giving people the control over their own computers they should already have had. Guy is a Robin Hood.

MSFT_Edging 5 hours ago

When Chris Domas left Battelle for Intel years back, shortly after hardware-fuzzing a bank of thin-clients to discover undocumented x86 instructions, I was convinced Intel was basically keeping him on the payroll to shut him up.

dooglius 6 hours ago

I don't understand the threat model being attacked here. If you had physical DRAM access you could do all of this anyway right? And I would assume that an unprivileged user would not have write access to the DRAM controller registers?

fulafel 5 hours ago

This doesn't require physical DRAM access, it's all software.

With ring-0 access, this lets you poke "even things walled off and invisible to ring-0 or the CPU itself" including things that the security processor tries hard to wall off.

VorpalWay 5 hours ago

Which arguably is a good thing. As a owner of the system I really should have complete control over it. But currently there is software I have no control over running at even higher privilege levels.

The only modern silicon that gives me full control over what code is running is some (or most?) microcontrollers.

And this isn't just a question of FOSS principle. Especially SMM is problematic by unpredictably taking CPU cycles away from your workload. This can mess up hard realtime workloads, such as found in CNC controllers. If you are running something like LinuxCNC this something you need to measure to figure out if a given computer is suitable for that job.

eptcyka 2 hours ago

StilesCrisis an hour ago

nullc an hour ago

You're missing that modern CPUs substantially lock the users out of control of their own computer and include things like hidden additional network connected processors that run their own full on operating systems. ... and may well be used to surveil or remotely access your computers the the behest of powers unknown.

But they still use system dram, so this approach allows looking into those parts of your own computer from which you're normally blocked. At least on some hardware...

quotemstr 6 hours ago

Even physical DRAM access would be thwarted by transparent total memory encryption, so this hack is still something else.

Retr0id 3 hours ago

It's not fully mitigated by encryption, you can still do a lot of damage without being able to observe plaintexts. For example, you could "rewind" a ciphertext block to an earlier value, and induce a UAF-like condition in the software it belongs to.

rzhikharevich 2 hours ago

semiquaver 3 hours ago

Where did this guy come from? Suddenly I’m seeing new amazing hardware exploits from them every day!

https://news.ycombinator.com/from?site=github.com/xoreaxeaxe...

nullc an hour ago

This is a great starting point to go looking for PSP / SMM backdoors.

ecshafer 4 hours ago

This is so cool. Outside of a cool demo, and maybe some black hat type stuff, this is surely dangerous, a bad idea, and shouldn't be done in prod. But pure hacker ethos at its heart.

ipdashc 6 hours ago

I really hate to be that guy, but man, as someone who was and is a big Christopher Domas fan (and is way dumber than him, I mean, this stuff is seriously over my head)... it's been really disappointing to see him LLM'ing all the READMEs recently. They used to be a joy to read through, but now the Claudeisms made it such a slog I could barely get through a few paragraphs. I'm glad he's using the new tools to get even more cool stuff done, but I wish he'd have gone for a human writeup at the end.

deepburner 21 minutes ago

I came to the comments to complain about how unreadable it was, saw that it was the movfuscator guy, went back to check if I somehow made a mistake but no, if anything that writeup is one of the egregious ones I've seen recently. What a shame, I really liked his talks.

hypfer 2 hours ago

Maybe this is to keep script kiddies away?

Like.. having no readme or a super technical one doesn't work anymore in the age of LLMs, but having one that hurts to read might?

Because people trying to get an LLM to translate it just get more LLM output. So you actually _have_ to put in manual effort to rip out what the fuck it wants to tell you.

That would be clever.

saagarjha 22 minutes ago

Script kiddies are just going to paste this into Claude and have it explain it to them.

mentalpagefault 4 hours ago

Disappointing indeed. Us security folk have already earned a poor reputation for ineffective technical communication, and LLMs are even worse, not better. This is especially disappointing in this case because we know xoreaxeaxeax is one of the few who are actually capable of effectively communicating beautifully cursed low-level hackery, but is now choosing to outsource the most impactful part of his work (since most people will only read the abstract, I mean, README) to an LLM. I'll still take new projects with sloppy READMEs over the previous years of radio silence, but I really wish xoreaxeaxeax would recognize the value in spending the time to write a single page of text in his own voice.

BugsJustFindMe 6 hours ago

I find vague gestures like this almost more annoying than the idea of someone using AI to write.

> the Claudeisms

This is hand-waving. Please be more specific.

> made it such a slog

On the flip-side, I didn't find it a slog at all. What if you're wrong?

austinthetaco 6 hours ago

I'm not the person you are replying to, but the readme is very clearly written by an AI, and it sounds nothing like his older work. Sometimes it's just super clear to people something is written with AI without you getting some sort of singular "gotcha" word or indicator. It's just writing patterns that would be hard to clearly establish rules for here in an HN comment, but it's incredibly obvious when you learn to spot it.

gnyman 5 hours ago

pdw an hour ago

boxed 5 hours ago

jchw 5 hours ago

"What if you're wrong?"

I'd just like to address this real quick because some people seem to think this is just a "hunch" that has some probability of being false; there is absolutely nothing more certain on planet Earth than the LLM involvement in this writing. It is difficult to come up with things that are certain enough to compare this to to convey the lack of doubt that exists.

I am not going to make fun of you for not being able to tell, although I do find it surprising that people seem to struggle in both directions with telling AI and human writing apart (are our brains really that different?) - I just want it to be clear that some of us can pick up Claudisms within just a couple of sentences with no effort. A Claude-generated sentence, in isolation, may not ring any alarm bells. A few of them in a row, however, that's a load-bearing smoking gun right there.

We can certainly argue to what extent undisclosed LLM involvement is an issue or not, though frankly I don't like reading LLM writeups so I would greatly prefer if people would stop using LLMs for public facing documents. But, it is at least worth making this much clear: we can tell.

jonathrg 5 hours ago

vetrom 4 hours ago

ipdashc 5 hours ago

> Please be more specific.

The em dashes are the most obvious stereotypical tell, but that doesn't really matter that much (I actually like them and occasionally used them pre-AI). It's hard to put a finger on, but the most annoying LLMism to me is the overdramatic, staccato, almost "epic" way they talk. It feels like a 2009 lens flare effect over everything, it sounds like a stereotypical hacker in a CSI show.

> the last generation whose datasheets document the DRAM controller's translation registers — and show that they can't be locked

> When your code dereferences *p, it appears to access the DRAM at p. It does not — p is a virtual address

> Physical addresses are really more of a suggestion.

> That's the exploit. All of it.

The worst part is that this stuff is genuinely cool and deserves to be dramatic. And I like stereotypical, campy hacker speak! But LLMs are, IDK... bad at it? Or maybe it just becomes a bore to read the same. Exact. Dramatic. Voice. From literally everyone. After you've heard it enough times.

None of this is against Mr. Domas. He seems like a cool person, with a cool voice, and I want to read his voice, not Claude's.

> What if you're wrong?

I definitely could be! Apologies if I am. But with all the em dashes and such, and having read his previous work, I felt confident enough to mention it. And as the sibling comment says, it really is something you just learn to spot over time.

cgyvbunji 5 hours ago

xorcist 4 hours ago

fulafel 7 hours ago

Fascinating. So what is the DCT swizzling functionality designed for in the hardware originally?

Retr0id 6 hours ago

Without any swizzling, certain common access patterns can end up with subpar performance, for example walking the columns of a 2d array with a certain stride - if it ends up directing every access to the same bank on the same channel, the throughput is much lower than if the load was evenly distributed across multiple banks/channels.

Swizzling "randomizes" bank/rank/channel distribution, which makes unlucky access patterns less likely. (Something I'd like to research is microbenchmarking different access patterns to infer the swizzle pattern and defeat physical ASLR)

Retr0id 4 hours ago

Late edit: It also makes it harder to exploit rowhammer etc., if the precise swizzling method is unknown.

__alexander 2 hours ago

So nice to see Christopher Domas posting code again.

aecsocket 7 hours ago

Holy shit, Christopher Domas is back. I remember watching his Defcon talks on x86 shenanigans[^1][^2] and being amazed at what he's been able to discover. Then he got whisked away by Intel and now drops this. I'm excited.

[^1]: https://www.youtube.com/watch?v=XH0F9r0siTI

[^2]: https://www.youtube.com/watch?v=jmTwlEh8L7g

vient 6 hours ago

He also released another research just a few days ago https://news.ycombinator.com/item?id=49245491

Retr0id 7 hours ago

Holy crap. This is like a software-reachable version of the dynamic memory aliasing hardware attack demonstrated by https://batteringram.eu/

pocksuppet 4 hours ago

Oh that's a clever attack. The RAM bus was often thought of as off-limits because of the speed and signal integrity requirements. They bypassed those.

mschuster91 7 hours ago

The researcher behind this is obviously highly knowledgeable in reverse engineering CPUs to the tune it reminds me of the dwarves digging in Moria...

But why on earth do they have to use AI to write their writeups?!

russdill 6 hours ago

Seriously. Got tired of reading the same idea over and over reworded endlessly.

dcrazy 6 hours ago

I got suspicious but decided it wasn’t AI. The “Foo is the bar.” sentence construct is coherent with the overall “through the looking glass” tenor.

jchw 6 hours ago

Nah, it's not just that, literally all the stuff they've posted this year is obvious LLM writing, none of the stuff from previous years is. To get this close to LLM writing style without actually using an LLM, you would pretty much have to be purposefully trying.

But I have a new favorite way of demonstrating this:

https://github.com/search?q=owner%3Axoreaxeaxeax+load-bearin...

Guess how many of these are from before 2025.

menaerus 5 hours ago

nnevatie 3 hours ago

This is quite excellent.

quotemstr 6 hours ago

This is the level of access the rightful owner of a computer should have to his own system.

He should also be able to fuse away this access forever, to be fair. But out of the box, when I get a new laptop, I should be able to read and write every byte of DRAM.

anthk 4 hours ago

On IntelME/AMD PSP:

https://jxself.org/titanic.shtml

He did it well. On "security", the author loves more to own his code/adata than anything. as did the PDP10/ITS hackers.

titularcomment 2 hours ago

Is ARM truly more user-friendly in this regard? And I dont see no genuine alternative than arm64

pocksuppet 5 hours ago

This is probably very interesting, but does it really have to be explained with a solid wall of AI slop writing?

UltraSane 6 hours ago

Opus refuses to discuss this at all. Make of that what you will.

rustcleaner 5 hours ago

Guardrails are a product-quality smell. Boycott guardrailed models. Punish guardrailed model providers with reduced revenue and bankruptcy. "I'm sorry Dave" must become a subscription-cancelling response or the nannying will never stop!

devttyeu 6 hours ago

Well, K3 has no problem, Sol is also fine-ish

HanClinto 6 hours ago

Likewise -- also had zero issues going over this with Sol. Seemed to give solid advice for how to test it -- use an expendable bare-metal AMD family 16h test system w/ usual standard checks that apply.

> Run `platform_check` first and do not use `SKITTER_FORCE=1` casually. Start with the read-only `dram_state` and `dram_carveouts`, then `dram_dump --dry-run`. Avoid `dram_poke` until maps have been freshly collected and calibrated. Do not bypass fingerprint checks, calibration, fencing, or verification.

Claude's (apparently externally-mandated?) lobotomization continues to be concerning. :-/

FabHK 6 hours ago

Could someone ELI5 please? Context, achievement, scope, consequences?

dmitrygr 2 hours ago

I got you, bro:

The hardware DRAM controller maps "physical addresses" approximately to: {DRAM slot number, chip number in slot, bank number in chip, row number in bank, byte number in row} via a complex map for various irrelevant reasons. All permission checks are before this mapping. So if you change the mapping, you can access shit you should not be able to, like TPM and SMM memory. OP found a way to change the mapping.

Permik 5 hours ago

Skitter creek bath salts... Or SCBS Guess there'll be a talk called Secure Computing BullShit in the next Blackhat conf! I'll be eagerly waiting for it! :)