Rowhammer.js: Root privileges for web apps?
media.ccc.de
media.ccc.de
In addition, they need to find a double-bit error, one that would change both the writable bit and an address bit, if a PTE was in that place in memory. They mentioned that they tested their laptop for these errors, and they're possible, but much rarer--how rare? This point was kind of just glossed over.
I'd guess that these two combined would make an exploitable error much more unlikely.
It varies widely between memory chips, memory controllers, and a variety of other factors.
Not to mention, Rowhammer was first disclosed early last year, and many vendors started shipping BIOS updates to prevent Rowhammer on the memory controller level months ago; additionally the problem has been fixed from the start on DDR4 RAM (the bug has been known to memory vendors before, but not been deemed a security problem, so the fix wasn't applied retroactively to DDR3).
So finding actually exploitable devices now is going to be difficult.
Edit: And additionally, yes, Windows 10 can ship BIOS updates, assuming the hardware and UEFI supports it.
The "?" in the end of the talk title should tip you off, same click bait as everyone else uses, sad.
0.) It is nice work
a.) There is no exploit shown
b.) They have no working exploit
c.) The title is used as click bait with the common adding-"?"-to-the-end tactic
d.) It is sad that security researchers would use c.)
They cobbled together the primitives you'd need to build an exploit, thus proving it to be exploitable. That seems like a reasonable time to share your work to me. The title is provocative, but not to the extent which makes it clickbait.
I wanted to express that the title of the talk suggests that there exists something that is called Rowhammer.js that gives root access through the browser. And there isn't.
Additionally, there is something called Rowhammer.js:
1.) Rowhammer.js does not (yet) give root access through JS on a website, this is work in progress. The current Rowhammer JS script can create bit flips in DRAM lines.
2.) They do not show how to get root access with Rowhammer.js, they describe a scenario they are working on and that might work in the future, which involves getting access to memory pages with memory cached versions of scripts that someone might execute as root.
edit: video file is here http://c3media.vsos.ethz.ch/congress/2015/webm-hd/32c3-7197-...