{"id":73756,"date":"2020-03-11T20:42:30","date_gmt":"2020-03-11T17:42:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu"},"modified":"2020-03-11T20:42:30","modified_gmt":"2020-03-11T17:42:30","slug":"lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu","title":{"rendered":"LVI \u2014 nj\u00eb klas\u00eb e re e sulmeve n\u00eb mekanizmin spekulativ t\u00eb ekzekutimit n\u00eb CPU","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00334.html\">Jan\u00eb publikuar<\/a><\/noindex> informacione mbi nj\u00eb klas t\u00eb ri sulmesh <noindex><a rel=\"nofollow\" href=\"https:\/\/lviattack.eu\/\">LVI<\/a><\/noindex> (Load Value Injection, <noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/software-guidance\/load-value-injection\">CVE-2020-0551<\/a><\/noindex>) n\u00eb mekanizmin e ekzekutimit spekulativ n\u00eb CPU-t\u00eb Intel, t\u00eb cilat mund t\u00eb p\u00ebrdoren p\u00ebr t\u00eb organizuar rrjedhjen e \u00e7el\u00ebsave dhe informacioneve sekrete nga enklavat Intel SGX dhe procese t\u00eb tjera.<\/p>\n<p>Klasa e re e sulmeve bazohet n\u00eb manipulimin e t\u00eb nj\u00ebjtave struktura mikroarkitekturore si n\u00eb sulmet <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50684\">MDS<\/a><\/noindex> (Microarchitectural Data Sampling), <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49608\">Spectre dhe Meltdown.<\/a><\/noindex>. Sidoq\u00eb pem\u00ebzimi i ri nuk bllokohet nga metodat ekzistuese t\u00eb mbrojtjes kund\u00ebr Meltdown, Spectre, MDS dhe sulmeve t\u00eb ngjashme. P\u00ebr t\u00eb siguruar mbrojtje efektive kund\u00ebr LVI, k\u00ebrkohen ndryshime harduerike n\u00eb CPU. Kur organizohet mbrojtja p\u00ebrmes programeve, duke shtuar nga kompilator\u00ebt instruksionin LFENCE pas \u00e7do operacioni ngarkimi nga memoria dhe duke z\u00ebvend\u00ebsuar instruksionin RET me POP, LFENCE dhe JMP, shpenzimet jan\u00eb shum\u00eb t\u00eb m\u00ebdha \u2014 sipas vler\u00ebsimeve t\u00eb studiuesve, mbrojtja e plot\u00eb programore do t\u00eb sjell\u00eb nj\u00eb r\u00ebnie t\u00eb performanc\u00ebs prej 2-19 her\u00eb. <\/p>\n<p>Pjes\u00ebrisht, v\u00ebshtir\u00ebsia e bllokimit t\u00eb problemit kompenzohet nga fakti q\u00eb p\u00ebr momentin sulmi ka nj\u00eb karakter m\u00eb tep\u00ebr teorik sesa praktik (sulmi \u00ebsht\u00eb teorikisht i mundsh\u00ebm, por shum\u00eb i v\u00ebshtir\u00eb p\u00ebr t'u realizuar dhe \u00ebsht\u00eb p\u00ebrs\u00ebrit\u00ebs vet\u00ebm n\u00eb teste sintetike).<br \/>\nKompania Intel <noindex><a rel=\"nofollow\" href=\"https:\/\/blogs.intel.com\/technology\/2020\/03\/ipas-security-advisories-for-march-2020\/\">i ka dh\u00ebn\u00eb<\/a><\/noindex> problemit nj\u00eb nivel t\u00eb moderuar rreziku (5.6 nga 10) dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00334.html\">l\u00ebshoi<\/a><\/noindex> nj\u00eb p\u00ebrdit\u00ebsim t\u00eb firmuerit dhe SDK p\u00ebr mjedisin SGX, n\u00eb t\u00eb cilin tentoi t\u00eb bllokonte realizimin e sulmit me an\u00eb t\u00eb nj\u00eb rruge anashkalimi. Metodat e sugjeruara t\u00eb sulmit aktualisht jan\u00eb t\u00eb aplikueshme vet\u00ebm p\u00ebr procesor\u00ebt Intel, por nuk p\u00ebrjashtohet mund\u00ebsia e adaptimit t\u00eb LVI-s\u00eb dhe p\u00ebr procesor\u00eb t\u00eb tjer\u00eb ndaj t\u00eb cil\u00ebve jan\u00eb t\u00eb zbatueshme sulmet e klas\u00ebs Meltdown.<\/p>\n<p>Problemi u zbulua n\u00eb prill t\u00eb vitit t\u00eb kaluar nga hulumtuesi Jo Van Bulck nga Universiteti i Leven, pas s\u00eb cil\u00ebs, me pjes\u00ebmarrjen e 9 hulumtuesve nga universitetet e tjera, u zhvilluan pes\u00eb metoda themelore t\u00eb realizimit t\u00eb sulmeve, t\u00eb cilat lejojn\u00eb ekzistenc\u00ebn e varianteve m\u00eb specifike. <noindex><a rel=\"nofollow\" href=\"https:\/\/transient.fail\/\">varianti<\/a><\/noindex>. Pavar\u00ebsisht, n\u00eb shkurt t\u00eb k\u00ebtij viti, hulumtuesit nga kompania Bitdefender gjithashtu <noindex><a rel=\"nofollow\" href=\"https:\/\/businessinsights.bitdefender.com\/bitdefender-researchers-discover-new-side-channel-attack\">u zbuluan<\/a><\/noindex> nj\u00eb nga variantet e sulmit LVI dhe e raportuan at\u00eb n\u00eb Intel. Variantet e sulmeve ndryshojn\u00eb n\u00eb p\u00ebrdorimin e strukturave t\u00eb ndryshme mikroarkitekturore, si\u00e7 jan\u00eb bufferi i ruajtjes (SB, Store Buffer), bufferi i mbushjes (LFB, Line Fill Buffer), bufferi i switch-it t\u00eb kontekstit FPU dhe cache-n\u00eb e nivelit t\u00eb par\u00eb (L1D), t\u00eb cilat jan\u00eb p\u00ebrdorur m\u00eb par\u00eb n\u00eb sulme si  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51852\">ZombieLoad<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52260\">RIDL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50684\">Fallout<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=48775\">LazyFP<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49134\">Foreshadow.<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47856\">Meltdown<\/a><\/noindex>.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/lviattack.eu\/lvi.pdf\"><img decoding=\"async\" alt=\"LVI - nj\u00eb klas\u00eb e re sulmesh mbi mekanizmin e ekzekutimit spekullativ n\u00eb CPU\" src=\"\/wp-content\/uploads\/2020\/03\/c367a275f86969b470990eb458ec6875.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p> Dallimi kryesor <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/articles\/load-value-injection-flaw\">i LVI-s\u00eb nga sulmet MDS \u00ebsht\u00eb se MDS manipulon p\u00ebrcaktimin e p\u00ebrmbajtjes s\u00eb strukturave mikroarkitekturore q\u00eb mbeten n\u00eb cache pas p\u00ebrpunimit spekulativ t\u00eb p\u00ebrjashtimeve (fault) ose operacioneve ngarkimi dhe ruajtjeje, nd\u00ebrsa<\/a><\/noindex> sulmet LVI lejojn\u00eb p\u00ebrfshirjen e t\u00eb dh\u00ebnave nga sulmuesi n\u00eb strukturat mikroarkitekturore p\u00ebr t\u00eb ndikuar n\u00eb p\u00ebrpunimin e ardhsh\u00ebm spekulativ t\u00eb kodit t\u00eb viktim\u00ebs. Me an\u00eb t\u00eb k\u00ebtyre manipulimeve, sulmuesi mund t\u00eb nxjerr\u00eb p\u00ebrmbajtjen e strukturave t\u00eb dh\u00ebnash t\u00eb mbyllura n\u00eb procese t\u00eb tjera gjat\u00eb ekzekutimit t\u00eb nj\u00eb kodo t\u00eb caktuar n\u00eb b\u00ebrthamat e CPU-s\u00eb t\u00eb synuara.<br \/>\neksplorimit t\u00eb problemit<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/lviattack.eu\/lvi.pdf\"><img decoding=\"async\" alt=\"LVI - nj\u00eb klas\u00eb e re sulmesh mbi mekanizmin e ekzekutimit spekullativ n\u00eb CPU\" src=\"\/wp-content\/uploads\/2020\/03\/164558b64621d92b32eb40245f7014e6.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>P\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/lviattack.eu\/lvi.pdf\">n\u00eb kodin e procesit-viktim\u00eb<\/a><\/noindex> duhet t\u00eb p\u00ebrmbushen <noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-load-value-injection\">sekuenca t\u00eb ve\u00e7anta t\u00eb kodit (gadget) n\u00eb t\u00eb cilat ngarkohet nj\u00eb vler\u00eb e kontrolluar nga sulmuesi, dhe ngarkimi i k\u00ebsaj vlere sjell n\u00eb shfaqjen e p\u00ebrjashtimeve (fault, abort ose assist), q\u00eb refuzojn\u00eb rezultatin dhe p\u00ebrs\u00ebrisin instruksionin. Gjat\u00eb p\u00ebrpunimit t\u00eb p\u00ebrjashtimit, ndodh nj\u00eb dritare spekulative, gjat\u00eb s\u00eb cil\u00ebs ndodh rrjedhja e t\u00eb dh\u00ebnave q\u00eb po p\u00ebrpunohen n\u00eb gadget. N\u00eb ve\u00e7anti, procesori fillon t\u00eb ekzekutoj\u00eb n\u00eb m\u00ebnyr\u00eb spekulative nj\u00eb pjes\u00eb kodi (gadget), pastaj p\u00ebrcakton se parashikimi nuk u realizua dhe rikthen operacionet n\u00eb gjendjen fillestare, por t\u00eb dh\u00ebnat e p\u00ebrpunuara gjat\u00eb p\u00ebrpunimit spekulativ mbesin n\u00eb cache-n\u00eb L1D dhe buferat mikroarkitekturore dhe jan\u00eb t\u00eb aksesueshme p\u00ebr t'u nxjerr\u00eb prej tyre duke p\u00ebrdorur metoda t\u00eb njohura p\u00ebr p\u00ebrcaktimin e t\u00eb dh\u00ebnave mbet\u00ebse p\u00ebrmes kanaleve an\u00ebsore.<\/a><\/noindex> sekuenca speciale kodi (gadget) n\u00eb t\u00eb cilat ngarkohet nj\u00eb vler\u00eb e kontrolluar nga sulmuesi, dhe ngarkimi i k\u00ebsaj vlere \u00e7on n\u00eb shfaqjen e p\u00ebrjashtimeve (fault, abort ose assist) q\u00eb hedhin posht\u00eb rezultatin dhe rishkruajn\u00eb instrukcionin. Gjat\u00eb p\u00ebrpunimit t\u00eb p\u00ebrjashtimit ndodh nj\u00eb dritare spekulative, gjat\u00eb s\u00eb cil\u00ebs ndodh rrjedhja e t\u00eb dh\u00ebnave t\u00eb p\u00ebrpunuara n\u00eb gadget. N\u00eb ve\u00e7anti, procesori fillon t\u00eb ekzekutoj\u00eb n\u00eb m\u00ebnyr\u00eb spekulative nj\u00eb cop\u00eb kodi (gadget), m\u00eb pas p\u00ebrcakton se parashikimi nuk \u00ebsht\u00eb realizuar dhe rikthen operacionet n\u00eb gjendjen e saj t\u00eb m\u00ebparshme, por t\u00eb dh\u00ebnat e p\u00ebrpunuara gjat\u00eb ekzekutimit spekulativ q\u00ebndrojn\u00eb n\u00eb cache-n\u00eb L1D dhe tampon\u00ebt mikroarkitektural\u00eb dhe jan\u00eb t\u00eb disponueshme p\u00ebr t'u nxjerr\u00eb nga to duke p\u00ebrdorur metoda t\u00eb njohura t\u00eb identifikimit t\u00eb t\u00eb dh\u00ebnave mbet\u00ebse p\u00ebrmes kanaleve an\u00ebsore.<\/p>\n<p>P\u00ebrjashtimi \u00abassist\u00bb, ndryshe nga \u00abfault\u00bb, trajtohet brenda procesorit pa thirrje p\u00ebr trajtues programor\u00eb. Assist mund t\u00eb ndodh\u00eb, p\u00ebr shembull, kur \u00ebsht\u00eb e nevojshme t\u00eb p\u00ebrdit\u00ebsohet bita A (Accessed) ose D (Dirty) n\u00eb tabel\u00ebn e faqeve t\u00eb memories. V\u00ebshtir\u00ebsia kryesore n\u00eb realizimin e nj\u00eb sulmi ndaj proceseve t\u00eb tjera q\u00ebndron n\u00eb iniciimin e ndodhis\u00eb assist, duke manipuluar me procesin e viktim\u00ebs. P\u00ebr momentin nuk ka m\u00ebnyra t\u00eb besueshme p\u00ebr ta b\u00ebr\u00eb k\u00ebt\u00eb, por n\u00eb t\u00eb ardhmen nuk p\u00ebrjashtohet se mund t\u00eb gjenden. Mund\u00ebsia p\u00ebr t\u00eb kryer nj\u00eb sulm deri tani \u00ebsht\u00eb konfirmuar vet\u00ebm p\u00ebr enkllav\u00ebt Intel SGX, skenar\u00ebt e tjer\u00eb mbeten teorik\u00eb ose t\u00eb riprodhuesh\u00ebm n\u00eb kushte sintetike (k\u00ebrkohet shtimi n\u00eb kod t\u00eb disa gadgets t\u00eb caktuar).<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/lviattack.eu\/lvi.pdf\"><img decoding=\"async\" alt=\"LVI - nj\u00eb klas\u00eb e re sulmesh mbi mekanizmin e ekzekutimit spekullativ n\u00eb CPU\" src=\"\/wp-content\/uploads\/2020\/03\/25916ac2d7df502276a5feaa50deda57.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/lviattack.eu\/lvi.pdf\"><img decoding=\"async\" alt=\"LVI - nj\u00eb klas\u00eb e re sulmesh mbi mekanizmin e ekzekutimit spekullativ n\u00eb CPU\" src=\"\/wp-content\/uploads\/2020\/03\/57202000ccc222ee6cd4404406f4b2c0.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Vektor\u00eb t\u00eb mundsh\u00ebm sulmesh:<\/p>\n<ul>\n<li class=\"l\"> Shkalla e t\u00eb dh\u00ebnave nga strukturat thelb\u00ebsore n\u00eb procesin n\u00eb nivelin e p\u00ebrdoruesit. Mbrojtja q\u00eb ekziston n\u00eb b\u00ebrtham\u00ebn Linux kund\u00ebr sulmeve t\u00eb klas\u00ebs Spectre 1, si dhe mekanizmi i mbrojtjes SMAP (Mbrojtja e Qasjes n\u00eb Modin Mbik\u00ebqyr\u00ebs), ndihmojn\u00eb ndjesh\u00ebm n\u00eb zvog\u00eblimin e mund\u00ebsis\u00eb s\u00eb sulmit LVI. Nj\u00eb mbrojtje shtes\u00eb n\u00eb b\u00ebrtham\u00eb mund t\u00eb k\u00ebrkohet n\u00ebse zbulohet n\u00eb t\u00eb ardhmen metoda m\u00eb t\u00eb thjeshta p\u00ebr kryerjen e sulmit LVI.\n<li class=\"l\"> Shkalla e t\u00eb dh\u00ebnave nd\u00ebrmjet proceseve t\u00eb ndryshme. P\u00ebr k\u00ebt\u00eb sulm k\u00ebrkohet q\u00eb t\u00eb ekzistojn\u00eb fragmente t\u00eb caktuara kodi n\u00eb aplikacion dhe t\u00eb p\u00ebrcaktohet m\u00ebnyra e formimit t\u00eb p\u00ebrjashtimit n\u00eb procesin e synuar.\n<li class=\"l\"> Shkalla e t\u00eb dh\u00ebnave nga mjedisi mikprit\u00ebs n\u00eb sistemin mysafir. Sulmi \u00ebsht\u00eb klasifikuar si shum\u00eb i komplikuar, i cili k\u00ebrkon kryerjen e hapave t\u00eb ndrysh\u00ebm t\u00eb v\u00ebshtir\u00eb dhe parashikimin e aktiviteteve n\u00eb sistem.\n<li class=\"l\"> Shkalla e t\u00eb dh\u00ebnave nd\u00ebrmjet proceseve n\u00eb sisteme t\u00eb ndryshme mysafire. Vektori i sulmit \u00ebsht\u00eb i ngjash\u00ebm me organizimin e shkall\u00ebs s\u00eb t\u00eb dh\u00ebnave nd\u00ebrmjet proceseve t\u00eb ndryshme, por k\u00ebrkon gjithashtu kryerjen e manovrave t\u00eb komplikuara p\u00ebr t\u00eb kaluar p\u00ebrmes izolimit nd\u00ebrmjet sistemeve mysafire.\n<\/ul>\n<p>K\u00ebrkuesit kan\u00eb publikuar <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/bitdefender\/lvi-lfb-attack-poc\">disa<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/jovanbulck\/sgx-step\/tree\/master\/app\/lvi\">prototipe<\/a><\/noindex> me demostrimin e principeve t\u00eb kryerjes s\u00eb sulmit, por ato ende nuk jan\u00eb t\u00eb p\u00ebrshtatshme p\u00ebr kryerjen e sulmeve t\u00eb v\u00ebrteta. Shembulli i par\u00eb lejon t\u00eb drejtohet ekzekutimi spekullativ i kodit n\u00eb procesin viktim\u00eb, n\u00eb m\u00ebnyr\u00eb t\u00eb ngjashme me programimin e orientuar nga kthimi (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=48730#rop\">ROP<\/a><\/noindex>, Return-Oriented Programming). N\u00eb k\u00ebt\u00eb shembull, procesi viktim\u00eb \u00ebsht\u00eb nj\u00eb proces i p\u00ebrgatitur posa\u00e7\u00ebrisht, q\u00eb p\u00ebrmban gadgets t\u00eb nevojshme (aplikimi i sulmit ndaj proceseve t\u00eb jashtme \u00ebsht\u00eb i v\u00ebshtir\u00ebsuar). Shembulli i dyt\u00eb lejon t\u00eb nd\u00ebrhyhet n\u00eb llogaritjet gjat\u00eb enkriptimit AES brenda enklav\u00ebs Intel SGX dhe t\u00eb organizohet nj\u00eb shkall\u00eb t\u00eb dh\u00ebnash gjat\u00eb ekzekutimit spekullativ t\u00eb instruksioneve p\u00ebr t\u00eb rikuperuar vler\u00ebn e \u00e7el\u00ebsit t\u00eb p\u00ebrdorur p\u00ebr enkriptim.<\/p>\n<p><center><br \/>\n<div class=\"youtube-placeholder\" data-id=\"goy8XRXFlh4\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/goy8XRXFlh4\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52517\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0430\u0442\u0430\u043a LVI (Load Value Injection, CVE-2020-0551) \u043d\u0430 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c \u0441\u043f\u0435\u043a\u0443\u043b\u044f\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0432 CPU Intel, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0442\u0435\u0447\u043a\u0438 \u043a\u043b\u044e\u0447\u0435\u0439 \u0438 \u0441\u0435\u043a\u0440\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u041d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0430\u0442\u0430\u043a \u043e\u0441\u043d\u043e\u0432\u0430\u043d \u043d\u0430 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u044f\u0445 \u0441 \u0442\u0435\u043c\u0438 \u0436\u0435 \u043c\u0438\u043a\u0440\u043e\u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u043d\u044b\u043c\u0438 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430\u043c\u0438, \u0447\u0442\u043e \u0438 \u0432 \u0430\u0442\u0430\u043a\u0430\u0445 MDS (Microarchitectural Data Sampling), Spectre [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":73757,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-73756","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0430\u0442\u0430\u043a\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47LVI \u2014 \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0430\u0442\u0430\u043a \u043d\u0430 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c \u0441\u043f\u0435\u043a\u0443\u043b\u044f\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0432 CPU | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0430\u0442\u0430\u043a\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-11T17:42:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-11T17:42:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47LVI \u2014 nj\u00eb klas\u00eb e re sulmesh mbi mekanizmin e ekzekutimit spekullativ n\u00eb CPU | ProHoster","description":"Jan\u00eb publikuar t\u00eb dh\u00ebna mbi nj\u00eb klas\u00eb t\u00eb re sulmesh","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47LVI \u2014 \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0430\u0442\u0430\u043a \u043d\u0430 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c \u0441\u043f\u0435\u043a\u0443\u043b\u044f\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0432 CPU | ProHoster","og:description":"\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0430\u0442\u0430\u043a","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/lvi-novyj-klass-atak-na-mehanizm-spekulyativnogo-vypolneniya-v-cpu","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-11T17:42:30+00:00","article:modified_time":"2020-03-11T17:42:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"73756","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:27:32","updated":"2022-10-05 20:14:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/73756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=73756"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/73756\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/73757"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=73756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=73756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=73756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}