Spectre Meltdown Vulnerability - How To Check Your System
Hey guys! HackerSploit here back again with another video, in this video, i am going to be showing you how to detect and mitigate the Spectre and Meltdown CVE's on Linux, more specifically Kali Linux.
Github Repo: https://github.com/speed47/spectre-meltdown-checker
------------------------------------------------------
HackerSploit Website: https://hsploit.com/
Pure VPN Affiliate Link:
PureVPN: https://billing.purevpn.com/aff.php?aff=33288
📗 Get My Courses at $10 Only!
The Complete Deep Web Course 2017:
https://www.udemy.com/the-complete-deep-web-course-2017/?couponCode=DWCBP2017
I Hope you enjoy/enjoyed the video.
If you have any questions or suggestions feel free to ask them in the comments section or on my social networks as well as my blog.
✔️SOCIAL NETWORKS
-------------------------------
Facebook: https://www.facebook.com/HackerSploit/
Twitter: https://twitter.com/HackerSploit
Discord: https://discord.gg/8BEcPVd
Kik Username: HackerSploit
Patreon: http://patreon.com/hackersploit
--------------------------------
Thanks for watching!
Благодаря за гледането
感谢您观看
Merci d'avoir regardé
Grazie per la visione
Gracias por ver
شكرا للمشاهدة
देखने के लिए धन्यवाद
What You'll Learn
The video demonstrates how to detect and mitigate the Spectre and Meltdown vulnerabilities on Linux, specifically Kali Linux, using the Spectre Meltdown Checker tool from the speed47/spectre-meltdown-checker GitHub repository.
Full Transcript
[Music] hey guys hackersploit here back again with another video and this is just going to be a quick video and essentially what we're going to be looking at today is uh how to detect and to mitigate the vulnerabilities that were earlier discovered this year the spectre and meltdown vulnerabilities that have affected processes uh so uh really i'm focusing this on linux and more specifically kali linux that's because most of the major software or operating systems have actually been following up on this and have released you know various updates for example windows released the updates uh within i think about 20 something or almost 30 hours so that was quite impressive to see that they were able to um you know so-called patch uh the problem uh up but uh if you've never heard of what i'm talking about it is essentially a vulnerability or these uh they're actually released earlier this year that showed uh the process uh or the memory leak that processors had and the mitigations that that the software companies have put in place or hardware companies really in relation with these software companies i've actually started to impact the performance of some computers so it'll be really interesting to see what people uh or they'll do in order to bring back everyone's or the affected users systems uh into the their respective performance uh performance class but irregardless as i said it's very very important that you know how to handle these issues these kernel related issues when it comes down to linux and more specifically kali linux right so a lot of people have been asking me this and there is actually it's very important to check this now the risk is higher if you're using an intel cpu so again i would highly recommend that you upgrade your distribution and you upgrade your kernel it doesn't matter what distribution you're running but um i'm pretty sure that debian have released theirs their update and again if you're running a certain processor there might be some um some processing caps or performance issues that you'll experience so i'm going to show you how to check this and this can be done with an awesome tool here it's called the spectre meltdown checker that essentially just uh checks your computer against the the cvs that were that were released earlier this year so it's really very simple uh it's very very simple to get uh on your system and to uh to actually run so what i'm gonna do is uh let me just open up my terminal here and go to my desktop and what we're going to do is we're going to clone this so a lot of people have been asking me why i actually physically paste in what i'm doing and that's because a lot of people if i use the keymap commands or keyboard shortcuts a lot of people will ask me what i did and you know it just gets a whole lot complicated so if you want to paste in you know how to do it it's a simple right click and paste if you want to use the keyboard shortcut use the control um the control shift v right i think is that is the correct key map yeah there we are all right so and then just hit enter to clone it so i've cloned it on the desktop it'll just take a few seconds there we are let me change directory into there like so all right so let me list the files and as you can see it's a shell file or a bash so if we just run it spectra or actually let me just clear this and let me just maximize this because there's a lot of information that's going to be printed out uh so what we're going to do is there we are so spectra oops meltdown checker there we are and it's going to start uh checking it now because i'm running this in a virtual machine and i already know that the host operating system it does not have a vulnerable uh it does not it's not really vulnerable uh to this uh to the cvs uh i know that yes as you can see here you know it's gonna it's a very very fast uh script essentially there were three cvs uh or spectra variants as they are called as the these cvs were called we had the spectre variant one and two and then finally we had the third one which was called meltdown right uh so essentially what's happening here is as you can see the first cv or the spectra variant one i am vulnerable to this and this is mainly for almost all processes released uh you know in in the in modern time and as you can see only 23 opcodes found heuristics should be improved when official patches become available so this is something related to the kernel uh as you can see here the spectra variant too there is mitigation that already exists so support for mitigation for this process say yes kernel support no but again as you can see it's not vulnerable your cpu vendor reported your cpu as not vulnerable so i'm pretty much safe there um as for the meltdown which is probably the worst of them all or the most the most damage causing you have your again for me it's not vulnerable now for yourself it could be vulnerable and i would recommend that you immediately update your kernel headers and everything related to your system uh just as a precaution and probably uh you shouldn't uh be using it for uh you know because it is vulnerable and regardless of what you're using your virtual machine for or whether or not you've installed it on a physical machine you should take these steps to mitigate uh these um these uh these vulnerabilities uh as they're called so yeah that's gonna be it for this video guys i hope i helped you in this video and you know i provided value uh to you if you if you found value in this video please leave a like down below if you have any questions or suggestions hit me up in the comments section on my social networks you can find the documented version uh of this video on my website it's actually quite popular and how to mitigate yourself uh correctly on all platforms really so yeah thank you so much for watching guys and i'll be seeing you in the next video peace [Music] you
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from HackerSploit · HackerSploit · 42 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
▶
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
Wireshark Tutorial for Beginners - Installation
HackerSploit
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
Wireshark Tutorial for Beginners - Capture options
HackerSploit
Wireshark Tutorial for Beginners - Filters
HackerSploit
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
Zenmap Tutorial For Beginners
HackerSploit
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
VPN And DNS For Beginners | Kali Linux
HackerSploit
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
Steganography Tutorial - Hide Messages In Images
HackerSploit
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
Best Linux Distributions For Penetration Testing
HackerSploit
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
Terminator - Kali Linux - Multiple Terminals
HackerSploit
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
Q&A #2 - Mr Robot?
HackerSploit
Metasploit Community Web GUI - Installation And Overview
HackerSploit
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
ARP Spoofing With arpspoof - MITM
HackerSploit
WordPress Vulnerability Scanning With WPScan
HackerSploit
Generating A PHP Backdoor with weevely
HackerSploit
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
MITM With Ettercap - ARP Poisoning
HackerSploit
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit
More on: Security Basics
View skill →Related AI Lessons
⚡
⚡
⚡
⚡
How to Keep Customer Payment Data Secure and PCI-Compliant on a Tight Budget
Dev.to AI
Data Breach at Indian Supplier Tata Electronics Exposes iPhone 18 Pro Details and Photos
Daring Fireball
Google put encryption inside phone calls because AI can now fake your mom’s voice It only works if…
Medium · Cybersecurity
Nigeria’s CBN Data Localisation Directive: What Most People Are Missing
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI