![]() |
|
#1
|
||||
|
||||
|
A security researcher with expertise in rootkits has built a working prototype of new technology that is capable of creating malware that remains "100 percent undetectable," even on Windows Vista x64 systems.
http://www.eweek.com/article2/0,1895,1983037,00.asp
__________________
One for all/All for one |
|
#2
|
||||
|
||||
|
Quote:
__________________
The part of a computer that causes most problems is the bit that holds the mouse! |
|
#3
|
||||
|
||||
|
It's undetectable because it hasn't made it onto the blacklists yet. That is the weakness of anti- [insert word here. ie. viruses, trojan, malware]. They rely on signatures. AKA blacklists. If it hasn't been seen, it won't be prevented.
__________________
Windows Firewall, SandboxIE. |
|
#4
|
|||
|
|||
|
Hello,
It's so simple. Boot from CD / DVD ... Check out for files and folders that aren't there in normal state ... Mrk
__________________
http://www.dedoimedo.com All your base are belong to us Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA |
|
#5
|
|||
|
|||
|
Mrkvonic, are you referring to something along the lines of Bart's PE, something which does not let the hard drive start up at all? Because I have read articles describing this, I can't remember where though. This is very good point for detection, but if you don't know it's there(polymorphonic/no signature) I guess you could just do this on the regular for good measure. Like if you are just that paranoid or curious or are admin of sensitive information database right? So like Knoppix STD or other Linux live distro is right up this alley huh?
|
|
#6
|
||||
|
||||
|
Quote:
Unless we... Gain control beneth the rootkit. Gain control before os. Have hardware detection, Intel, AMD. It will be interesting to see how the relationship proceeds between concept and technology. ...If you dont know Joanna Rutkowskas work you can checkout her site/blog http://theinvisiblethings.blogspot.com/
__________________
Who controls the past controls the future Who controls the present controls the past vmworld Last edited by Meriadoc : June 30th, 2006 at 09:58 AM. |
|
#7
|
|||
|
|||
|
Quote:
Hello, Yes, BartPE, Helix, Knoppix, etc... Mrk
__________________
http://www.dedoimedo.com All your base are belong to us Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA |
|
#8
|
|||
|
|||
|
Quote:
Quote:
|
|
#9
|
|||
|
|||
|
Hello,
Negative. Mrk
__________________
http://www.dedoimedo.com All your base are belong to us Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA |
|
#10
|
||||
|
||||
|
Yes this was posted about over here and with not much response.
http://www.wilderssecurity.com/showt...=135615&page=2 Based on what was wirtten over at antirootkit.com. |
|
#11
|
||||
|
||||
|
I knew of Johanna's invisable.org site but guess I didn't know of her blog.
And I did make a comment about the same group from rootkit dot com hanging out at antirootkit dot com but it really makes no difference. controler |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|