Skip to content

ThePawn02

Gaming and Streaming Content

  • Blog
  • Editor's Picks
  • eSports
  • Guides
  • Headlines
  • News
  • Reviews
  • Uncategorized
  • Website Update
Primary Menu
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
    • Guild Mentality
    • The Zealots
    • Malign
  • Socials
    • Youtube Channel
    • Twitch Channel
    • Kick.com
    • Twitter
    • Instagram
    • Facebook
Subscribe
  • Home
  • 2024
  • December
  • Researchers have found a way to hack the memory on some virtual machines using a Raspberry Pi
  • News

Researchers have found a way to hack the memory on some virtual machines using a Raspberry Pi

Though an attacker would need physical access to make the most of it.
December 13, 2024 2 min read
Researchers have found a way to hack the memory on some virtual machines using a Raspberry Pi

Though an attacker would need physical access to make the most of it.

Designed with cloud computing security in mind, AMD’s Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP), which is an incredibly long and serious name to suggest how complicated it is, has recently seen a rather worrying security breach, involving RAM and a Raspberry Pi.

The SNP part of that phrase is an added security measure to SEV, which ensures those with access via a virtual machine (VM) can’t access data they aren’t intended to, i.e. other virtual machines. The increased data protection offered by this and its ability to scale memory to protect entire VMs has made it an attractive route for organisations over competitors like Intel’s SGX.

As reported by The Register, this is all according to a paper entitled “BadRAM: Practical Memory Aliasing Attacks on Trusted Execution Environments”.

In it, the researchers used a Raspberry Pi Pico to “unlock and modify DDR4 and DDR5 SPDs”, where the SEV-SNP safeguard lies, to create memory aliases. These can then be used to “manipulate memory mappings and corrupt or replay ciphertext, culminating in a devastating end-to-end attack”.

Once into the SDP, the Raspberry Pi can be used to disable and write protection and alter its contents. Ghost bits can then be made in the DIMM, which are “invisible to the memory controller”. This can allow the controller of the Raspberry Pi to navigate software restrictions, or even enable “software-only attacks”.

The Raspberry Pip Pico and DDR sockets required to do this cost “approximately $10” and can be sourced fairly easily. You will need a 7-10 V source, like a battery, but a malicious actor could get ahold of the necessary equipment with ease. If you’re particularly techy, or get a little too ambitious with your hobbies, there’s a chance you already have most of this gear lying around.

Where malicious actors might struggle is in gaining physical access in order to do this method. The paper also notes that two Corsair DDR4 DIMMs taken off the shelf left “the base configuration entirely unprotected, possibly exposing them to software-only BadRAM attacks.” This means, rarely, you can do this method without physical access.

Importantly, the paper notes times when physical access can be possible without it being particularly strange, like a “malicious employee at a cloud service provider”. Notably, this access would leave no physical trace behind.

This problem was reported to AMD, which now labels it a 5.3 (medium) severity problem, and there’s a fix, too.

Companies can mitigate problems by using memory modules that entirely lock SPD, “as well as following physical security best practices”. This is to say that someone shouldn’t be able to get physical access in the first place, which is generally always pretty good advice—don’t leave your front door unlocked.


Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

About Post Author

See author's posts

Continue Reading

Previous: After 3,500,000 units sold and its Game Awards wins, Balatro does a victory lap and absorbs 8 new crossovers in its unstoppable march to turn all games into cute little cards that get you points and stuff
Next: Teamfight Tactics champion pool, shop odds, and rolling chances explained

Related News

The Social Network Part II Is Happening, And Facebook Probably Won’t Like It
1 min read
  • News

The Social Network Part II Is Happening, And Facebook Probably Won’t Like It

ThePawn.com June 25, 2025
FTC issues $126 million in Fortnite refunds, gives eligible players an extra 2 weeks to apply for their money back
2 min read
  • News

FTC issues $126 million in Fortnite refunds, gives eligible players an extra 2 weeks to apply for their money back

ThePawn.com June 25, 2025
10 years after it launched, one of the best roguelikes of all time gets a surprise update on Steam with quality of life improvements and a new controls menu
2 min read
  • News

10 years after it launched, one of the best roguelikes of all time gets a surprise update on Steam with quality of life improvements and a new controls menu

ThePawn.com June 25, 2025

Latest YouTube Video

Check out these awesome streamers

ThePawn02 on twitch

From Gamewatcher

  • Best Nintendo Switch 2 Games To Play Right Now
  • PlayStation Plus Monthly Games for July 2025 Include Diablo 4 As the Subscription Service's 15th Anniversary Celebrations Begin
  • How do you use the new Sound Recorder in Phasmophobia?
  • Chrono Odyssey Preview
  • Warhammer 40,000: Space Marine Review

From IGN

  • Dying Light: Retouched Update Isn't Coming to Nintendo Switch as Techland Denies Plans for Switch 2 Port
  • Humble Bundle Roundup June 2025: Mafia x BioShock Collection, Capcom Publisher Sale, and More
  • Deals For Today: Coke Zero, Doritos, Borderlands 4, and Pokémon Legends Z-A Preorders
  • Crisol: Theater of Idols Is a Horror FPS Influenced by Spanish Folklore
  • You Can Preorder Sabrina Carpenter’s New Album Today (Yes, the Fortnite Girl)

From Kotaku

  • The Social Network Part II Is Happening, And Facebook Probably Won’t Like It
  • New Xbox 360 Update Adds More Ads 20 Years After Launch
  • John Cena Has An Idea For A Unique Way He Could Enter The MCU As Peacemaker
  • We Are Getting An Official X-Files Lego Set And It Looks Great
  • New Hot Shots Golf Game Cops To Using Generative AI For Trees

.

You may have missed

The Social Network Part II Is Happening, And Facebook Probably Won’t Like It
1 min read
  • News

The Social Network Part II Is Happening, And Facebook Probably Won’t Like It

ThePawn.com June 25, 2025
Dying Light: Retouched Update Isn’t Coming to Nintendo Switch as Techland Denies Plans for Switch 2 Port
3 min read
  • Headlines

Dying Light: Retouched Update Isn’t Coming to Nintendo Switch as Techland Denies Plans for Switch 2 Port

ThePawn.com June 25, 2025
FTC issues $126 million in Fortnite refunds, gives eligible players an extra 2 weeks to apply for their money back
2 min read
  • News

FTC issues $126 million in Fortnite refunds, gives eligible players an extra 2 weeks to apply for their money back

ThePawn.com June 25, 2025
10 years after it launched, one of the best roguelikes of all time gets a surprise update on Steam with quality of life improvements and a new controls menu
2 min read
  • News

10 years after it launched, one of the best roguelikes of all time gets a surprise update on Steam with quality of life improvements and a new controls menu

ThePawn.com June 25, 2025
Privacy Policy
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
  • Socials
  • Twitch
  • YouTube
  • Instagram
  • Twitter
  • Facebook
  • Kick.com
Copyright © All rights reserved. | MoreNews by AF themes.