video thumbnail 19:43
The Discovery of Zenbleed ft. Tavis Ormandy

2023-08-18

[public] 21.8K views, 3.88K likes, dislikes audio only

channel thumbLiveOverflow

How did Tavis Ormandy fuzz CPUs to discover Zenbleed? In this video we learn about the techniques to make this work!

Watch part 2: /youtube/video/9EY_9KtxyPg

buy my font (advertisement): https://shop.liveoverflow.com/

This video is sponsored by Google: https://security.googleblog.com/2023/08/downfall-and-zenbleed-googlers-helping.html

Original Zenbleed Writeup: https://lock.cmpxchg8b.com/zenbleed.html

AMD Security Bulletin: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7008.html

Tavis Ormandy: https://twitter.com/taviso

Sudoedit Exploit Series: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx

Documented Intel Performance Counters: https://perfmon-events.intel.com/skylake_server.html

RIDL Video: /youtube/video/x_R1DeZxGc0

Chapters:

00:00 - Intro

01:22 - Zenbleed Proof of Concept

03:06 - Tavis Ormandy

04:18 - How Fuzzing Works

06:31 - CPU Performance Counters

11:06 - Detect Bugs with "Oracle Serialization"

15:09 - Fuzzing and Discovering Zenbleed

18:46 - Outro

=[ ❤️ Support ]=

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

2nd Channel: https://www.youtube.com/LiveUnderflow

=[ 🐕 Social ]=

→ Twitter: https://twitter.com/LiveOverflow/

→ Streaming: https://twitch.tvLiveOverflow/

→ TikTok: https://www.tiktok.com/@liveoverflow_

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Intro
/youtube/video/neWc0H1k2Lc?t=0
Zenbleed Proof of Concept
/youtube/video/neWc0H1k2Lc?t=82
Tavis Ormandy
/youtube/video/neWc0H1k2Lc?t=186
How Fuzzing Works
/youtube/video/neWc0H1k2Lc?t=258
CPU Performance Counters
/youtube/video/neWc0H1k2Lc?t=391
Detect Bugs with "Oracle Serialization"
/youtube/video/neWc0H1k2Lc?t=666
Fuzzing and Discovering Zenbleed
/youtube/video/neWc0H1k2Lc?t=909
Outro
/youtube/video/neWc0H1k2Lc?t=1126
Asking Android Developers About Security at Droidcon Berlin 26,614 views
/youtube/video/-X03UKo_obE
Support liveoverflow.com
https://liveoverflow.com/support
How The RIDL CPU Vulnerability Was Found 112,600 views
/youtube/video/x_R1DeZxGc0