Web Hack List

Collected research

ASLR on the Line: Practical Cache Attacks on the MMU

Page-table walks by the memory management unit leave the page tables themselves in the shared last-level cache, so an EVICT+TIME attack on those cache lines reveals which entries a victim used and derandomizes its virtual addresses. It needs only ordinary memory accesses, so plain JavaScript broke code and heap ASLR in two browsers in about 150 seconds, on Intel, ARM and AMD alike.

Record

Researcher
Ben Gras, Kaveh Razavi, Erik Bosman, Herbert Bos and Cristiano Giuffrida
Published by
NDSS Symposium
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ben Gras, Kaveh Razavi, Erik Bosman, Herbert Bos and Cristiano Giuffrida, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .