March 18, 2016
Physical weaknesses in memory chips that make computers and servers susceptible to hack attacks dubbed “Rowhammer” are more exploitable than previously thought and extend to DDR4 modules, not just DDR3, according to a recently published research paper.
The paper, titled How Rowhammer Could Be Used to Exploit Weaknesses in Computer Hardware, arrived at that conclusion by testing the integrity of dual in-line memory modules, or DIMMs, using diagnostic techniques that hadn’t previously been applied to finding the vulnerability. The tests showed many of the DIMMs were vulnerable to a phenomenon known as “bitflipping,” in which 0s were converted to 1s and vice versa. The report was published by Third I/O, an Austin, Texas-based provider of high-speed bandwidth and super computing technologies. The findings were presented over the weekend at the Semicon China conference.
“Based on the analysis by Third I/O, we believe that this problem is significantly worse than what is being reported,” the paper warned. “And it is still visible on some DDR4 memory modules.”