transientfail icon indicating copy to clipboard operation
transientfail copied to clipboard

Website and PoC collection for transient execution attacks

Results 13 transientfail issues
Sort by recently updated
recently updated
newest added

POC just support x86 How to change code to support ARMv8?

https://www.vusec.net/projects/crosstalk/

Unlike on x86, alignment checks on ARMv8-A can cause one of three different exceptions: a program counter alignment fault, a stack pointer alignment fault, or a data abort exception (for...

ext

Browser: Chrome 80.0.3987.132 OS: Windows 1909 Uncaught Error: missing: 9 at e (index.js:formatted:3765) at Object.n.generateNestedData (index.js:formatted:1149) at Object.refresh (index.js:formatted:925) at toggleMeltdownSpectre (filter.js:57) at filter (filter.js:107) at (index):406 Reproduce 1. Open...

Described [here](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00330.html) and [here](https://software.intel.com/security-software-guidance/insights/deep-dive-snoop-assisted-l1-data-sampling); "Snoopy" seems to be a special type of Foreshadow/L1TF; not sure how this would fit into the classification tree? It doesn't seem that snoops are a...

ext

Described [here](https://businessresources.bitdefender.com/hubfs/noindex/Bitdefender-WhitePaper-INTEL-CPUs.pdf?utm_campaign=swapgs&utm_source=web&adobe_mc=MCMID%3D77118601880064029731700614210949073821%7CMCORGID%3D0E920C0F53DA9E9B0A490D45%2540AdobeOrg%7CTS%3D1571064432) and [here](https://software.intel.com/security-software-guidance/insights/deep-dive-intel-analysis-speculative-behavior-swapgs-and-segment-registers), this actually also includes an interesting sub-instance of MD-GP. The paper and deep-dive are not very clear on the exact interaction with #GP faults, but afaik...

ext

We should incorporate https://lviattack.eu/ into the tree. Either as an addition to the MD subtree or a separate branch? Given the symmetry with existing MD-type attacks, Id argue for extending...

ext

would be a nice feature to have a "timeline" feature where you can drag a slider to see how the transient exec landscape and each of the attack nodes in...

website

It would be good to have a permanent link to the current filter settings to be able to share it.

website