A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server) Every Android device is susceptible to a hardware vulnerability called RAMpage, Electronics & Gadgets : Today Indya

Latest News

Every Android device is susceptible to a hardware vulnerability called RAMpage
Saturday, June 30, 2018 IST
Every Android device is susceptible to a hardware vulnerability called RAMpage

We have consistently seen various vectors of attack rear their head when it comes to Android smartphones. We’ve seen Shattered Trust, Cloak and Dagger, and Rowhammer, just to name a few. RAMpage is the latest one on the block, and while it is a hardware vulnerability, it doesn’t necessarily need physical access to your device to exploit. How it works is relatively simple.

 
 

When a CPU reads or writes a row of bits in the RAM module present on the device, the neighboring rows are slightly affected due to a tiny electric discharge. This isn’t usually a problem as we know RAM does this and that’s why it’s periodically refreshed to make sure nothing goes wrong. But what if we start “hammering” the same “row”? What if we continuously read or write to the same row in order to disrupt neighboring rows? This can cause a bit-flip in a memory row that we shouldn’t own or have access to at all. That’s what Rowhammer is, and it’s being used as part of a larger vulnerability called RAMpage. The CVE is CVE-2018-9442 and it affects devices shipped with LPDDR2, LPDDR3, or LPDDR4 RAM. We’ve already covered Rowhammer in greater depth here.
 
The Team Behind RAMpage
 
Vrije Universiteit Amsterdam
 
TU Wien
 
EURECOM
 
*Harikrishnan Padmanabha Pillai, MSc.
IBM
 
*Prof. Dr. Giovanni Vigna
UC Santa Barbara
 
UC Santa Barbara
 
*Prof. Dr. Herbert Bos
Vrije Universiteit Amsterdam
 
Vrije Universiteit Amsterdam
 
What is RAMpage?
 
RAMpage isn’t exactly new, so to say. RAMpage is a hardware vulnerability which implements Rowhammer and other, smaller exploits. RAMpage can be used to gain root access on a device, but the researchers managed to get it to do a whole lot more as well. It could be used to bypass JavaScript sandboxes and even perform an attack running on another virtual machine on the same computer on x86 devices. ARM-based devices are also vulnerable, and that’s where our Android phones come in. DRAMMER stands for “Deterministic Rowhammer Attacks on Mobile Devices,” and it was able to be used against a number of Android phones in the past to gain root access.

 
 

How does RAMpage work?
 
RAMpage works primarily by abusing Android’s memory management system – the Android ION memory allocator. ION was introduced with Android 4.0 back at the end of 2011 and simply gives applications the memory they require to run. However, breaking this down means that you can access all memory on the device from within any application – an extremely dangerous situation. What was once protected memory no longer is once ION is broken down, and any malicious applications looking for data leakage could sift through this memory. While it’s hard to protect against DRAMMER (and, incidentally, Rowhammer) because it’s a hardware vulnerability, building safeguards around Android ION will mitigate most of the damage that can be done. The researchers call it GuardION and have released it open-source on GitHub.
 
What is GuardION?
 
GuardION is the proposed mitigation method put forward by those who discovered RAMpage. It simply sets up buffer rows around potentially exploitable software in RAM, such as Android ION. It’s a simple method, but it’s better for a few reasons. The first being that you obviously can’t replace the RAM module in every Android device released. The second is that, even in newer devices, hardware fixes will be harder on the battery as they will constantly have to refresh the memory. Hence protecting memory with software is easier. The researchers showed that GuardION has negligible memory overhead, better performance than Google’s attempts at preventing the exploit and prevents all known DMA (Direct Memory Access) attacks. However, while the researchers are in contact with Google, the company has determined that GuardION presents too large of a performance overhead for it to be incorporated into AOSP. GuardION doesn’t fix the hardware vulnerability, instead, it simply accounts for it and reduces the amount of damage it can do.
 
Am I vulnerable to RAMpage?
 
While chances are if you own an Android phone released since 2012 you are vulnerable, you can still install the DRAMMER test application from their official website below to see for yourself. While all of this seems scary, there is no public exploit available yet. While you should still be careful out there, there is currently no reason to worry as the exploit is not in the public domain. The researchers do not intend to release it at this point in time either. You can check out the original research paper below.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Pocophone F1 to be the fastest handset in its class, Snapdragon 845 confirmed

Two days ago Xiaomi teased the arrival of its new

Recently posted . 22K views . 4 min read
 

 Article
The Top 5 Best USB/PD Phone Charger in India 2023

View Top 5 Mobile Chargers in India as on 08 Feb 2023. This rundown is compiled according t...

Recently posted . 6K views . 6 min read
 

 Article
Asus TUF Gaming FX505DY, TUF Gaming FX705DY Laptops Launched in India With AMD CPU and GPU

HIGHLIGHTS   • Both laptops use the AMD Ryzen 5 3350H CPU and Radeon RX 560 GPU • The...

Recently posted . 5K views . 2 min read
 

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 4K views . 2 min read
 

 
 

More in Electronics & Gadgets

 Article
2018 KTM Duke 200 ABS launch price Rs 1.6 L – Rs 9K expensive than non ABS

About Rs 9k expensive than non ABS variant.

Recently posted. 958 views . 0 min read
 

 Article
[Exclusive] Apple iPad Pro 12.9 (2018) Images, Specs Leaked Ahead of Company’s September 12 Launch Event

The Apple iPad Pro 12.9 (2018) will most probably bring thinner bezels around the screen, making it more compact. It might also feature a TrueDepth camera setup at ...

Recently posted. 1K views . 2 min read
 

 Article
WhatsApp’s new disappearing messages feature

Earlier in October, the messaging app introduced revamped features for its Business users. This included a cloud-hosting service and in-app purchases.

Recently posted. 1K views . 1 min read
 

 Reviews
Review: GoPro Hero5 Black



Recently posted . 2K views . 26 min read
 

 Reviews
Top Best Window Fans in India – Complete Buying Guide



Recently posted . 2K views . 120 min read
 

 Article
Idea Cellular says company name changed to Vodafone Idea Limited

Indian telecom operator Idea Cellular has said that the company's name has been changed to Vodafone Idea Limited. The news comes hours after the National Comp...

Recently posted. 924 views . 3 min read
 

 Article
Samsung Galaxy J7 Prime 2 launched in India: Price, specifications and features

Samsung Galaxy J7 Prime 2 features 3GB of RAM, 5.5-inch full HD display and Samsung Pay Mini. The smartphone is available for Rs 13,990  

Recently posted. 931 views . 1 min read
 

 
 
 

   Prashnavali

  Thought of the Day

The price of success is hard work, dedication to the job at hand, and the determination that whether we win or lose, we have applied the best of ourselves to the task at hand.
Vince Lombardi

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top