Attacking a co-hosted VM: A hacker, a hammer and two memory modules
thisissecurity.stormshield.com
thisissecurity.stormshield.com
It also looks like ECC greatly reduces the potential for this to be exploited.
echo 1 > /sys/kernel/mm/ksm/run set 0 to stop ksmd from running but keep merged pages,
set 1 to run ksmd e.g. "echo 1 > /sys/kernel/mm/ksm/run",
set 2 to stop ksmd and unmerge all pages currently merged,
but leave mergeable areas registered for next run
Default: 0 (must be changed to 1 to activate KSM,
except if CONFIG_SYSFS is disabled)
[1] https://www.kernel.org/doc/Documentation/vm/ksm.txtIf that doesn't take care of it, they can't have wanted me to read it.
https://chrome.google.com/webstore/detail/darken-text/kmonkh...
Definitely going to give that Just Read extension a go
This is a pretty sophisticated attack requiring a lot of stuff to fall into place (such as being provisioned on the same machine as the target), and even though it is technically quite impressive I doubt it is a frequent enough occurrence that you could conclude that if you host on a shared machine you're going to get hacked sooner or later.
The chances of being hacked through some simpler and more direct vector are a lot larger.
Even botnet operators are aiming for the best ROI they can get.
to be clear: i don't mean to lump security researchers and cybercriminals into a common group. it just so happens that they both have motivating interests in this industry shift.