InSpectre : GRC.com Spectre & Meltdown testing tool


Recommended Posts

46 minutes ago, Mando said:

im finding matrixes like this invaluable to catalogue what fixes to kit under my remit will require, awaiting parents corp official response to addressing it, meanwhile im collating info to help myself when they do respond.

Yeah sorry, I just got stupidly cranky.

 

What other options really exist when social factors create a giant consensual delusion and nobody tracks it out far enough to see the eventual consequences. When all that gets figured out in the end, however long that takes, the reality is that there will just be another set of patches to fix the mess caused by this set of patches...

 

12 minutes ago, DevTech said:

Yeah sorry, I just got stupidly cranky.

 

What other options really exist when social factors create a giant consensual delusion and nobody tracks it out far enough to see the eventual consequences. When all that gets figured out in the end, however long that takes, the reality is that there will just be another set of patches to fix the mess caused by this set of patches...

 

no need to apologise buddy :) 

 

I do agree though, due to the press blowing it out of all proportion, its getting silly with some aspects, heck i was in an infosec call last week, and one very senior member of staff stated, its like Y2k all over again, all a storm in a T-cup...I had to bite my tongue as Y2k wasnt a major event due to all the pre-emptive work! They were happy knowing SEP claims to protect against the attack vector, so it was a non-starter...right because SEP never suffers from 0 day exposure and lack of protection....throw in their "eraser" engine update making a mess out of anything newer than W7 with the KBs installed.....you dont just put the SEP latch on the front door, but leave your inner lockable door wide open......

 

Belt N Braces, Belt n Braces!

  • Like 2
3 hours ago, Mando said:

Kudos to Kevin Beaumont for this matrix, its not mine. Lots of direct links to different vendors and patch status.

 

https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?usp=sharing&sle=true

 

1

Can confirm Secureaplus which is not on that list is compatible. 

Hello,

 

The reason for making the patch "triggerable" (for lack of a better term) on Windows Server is because the changes made to the operating system to patch the Meltdown (CVE-2017-5754) vulnerability can greatly increase the time required to perform certain operations for which servers are often used.  Because of this, Microsoft has presented the IT and Security folks with a choice:  If they feel the system is well-secured, runs trusted code and is not used in a multi-tenancy scenario, they can omit the patch in exchange for maintaining performance.

 

Because the security posture of each enterprise is different, because servers can be used in so many roles, and because the performance impact of the patch can vary tremendously, Microsoft has given its customers the option to decide on which servers to enable patch functionality.

 

By the way, the researchers at ESET have been keeping track of security announcements, bulletins and notifications related to the Spectre (CVE-2017-5715, CVE-2017-5754) and Meltdown (CVE-2017-5754)  vulnerabilities and have identified 240+ so far.  Complete list at https://www.welivesecurity.com/2018/01/05/meltdown-spectre-cpu-vulnerabilities/#vendors

 

Regards,

 

Aryeh Goretsky

 

  • Like 3
  • 1 month later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • This is weird. Mythos is more unrestricted compared to Fable. Technically it poses more risk!!
    • This is a great thing, I always have issues with Verizon while inside of certain football stadiums due to the saturation and walls blocking signal so a LOS way to connect would be great. Verizon was supposed to be offering sat data this year but I've not heard a word of it lately. Dude is sending rockets into space in a cheap manner, low waste foot print and has a great product with solar/battery tech. We would be so far behind China right now if not for him and a push to get back into space.
    • illegally? Proof of that? Seems you are posting misinformation or well a pure straight up lie cause there is zero proof of such a thing. But I get it...
    • KillerPDF 1.6.0 by Razvan Serea KillerPDF is a lightweight, portable PDF editor for Windows built for users who want full control without subscriptions, installers, or telemetry. It runs as a single executable, making it ideal for USB use and field work. You can view PDFs with smooth PDFium rendering, navigate quickly with thumbnails, zoom, and shortcuts, and reorganize pages using drag-and-drop. It supports merging multiple PDFs, splitting documents, and extracting selected pages. KillerPDF also allows inline text editing with font matching to preserve the original layout, plus annotations like text boxes, freehand drawing, highlights, and reusable signatures. You can search full text, copy content easily, and print documents with flattened annotations. Designed as a free and open alternative to bloated PDF tools, it works fully offline on Windows 10/11 x64. No runtimes install. Everything needed is inside the EXE (targets .NET Framework 4.8, which ships with every supported Windows release). KillerPDF key features: High-quality PDF rendering via PDFium Edit PDF text inline (double-click to modify text) Page thumbnails and fast navigation with zoom and shortcuts Merge multiple PDFs into one Split PDFs and extract selected pages Drag-and-drop page reordering Font matching to preserve original document appearance Text boxes for notes Freehand drawing tools Highlight overlays with adjustable color, size, opacity Undo actions and clear per-page annotations Create, draw, and save reusable signatures Click-to-place signatures anywhere Full-text search with highlighted results Drag-select or Ctrl+A to copy text Print with annotations flattened Portable single-file app (~15 MB) No installer, no admin rights required No account, no telemetry KillerPDF 1.6.0 changelog: A big release: major new features, a full visual refresh, and an internal rewrite. New Tabbed documents - open several PDFs at once, each restoring its page, zoom, and view OCR built into the exe (Tesseract) - OCR a page or dragged region to the clipboard, make a scan searchable, or extract all text; extra languages download on demand Digital signatures with a cloud certificate (Certum SimplySign), reusable signatures, and click-to-sign form fields Transform tool - rotate, scale, flip, and straighten a crooked scan, with live preview Edit existing text by double-clicking a line (the original is cleanly covered) Line tool, refreshed draw/highlight bars, resizable word-wrapping text boxes, and a full RGB color picker with eyedropper Print options (scale, position, margins, two-sided), page-number stamping, folder/.zip import, Document Info (F12), and recent files with file-type icons Translations: Bengali, Turkish, Simplified Chinese, German, French. Changed New logo, icons, fonts, and colors throughout Six themes with per-theme accent colors; sidebar docks left or right; toolbar style picker Internal rewrite: the ~15,000-line main window split into ~40 focused files (no behavior change) Fixed True 300 DPI printing, encrypted/damaged PDFs open on a background thread with a repair fallback, form fields render in every view mode, and undo is one item per press Download: KillerPDF 1.6.0 | 14.6 MB (Open Source) Link: KillerPDF Home Page | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      498
    2. 2
      +Edouard
      221
    3. 3
      PsYcHoKiLLa
      147
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      69
  • Tell a friend

    Love Neowin? Tell a friend!