Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 29th, 2006, 12:29 PM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,366
Default Undetectable Malware?

A security researcher with expertise in rootkits has built a working prototype of new technology that is capable of creating malware that remains "100 percent undetectable," even on Windows Vista x64 systems.


http://www.eweek.com/article2/0,1895,1983037,00.asp
__________________
One for all/All for one
  #2  
Old June 29th, 2006, 12:48 PM
steve1955's Avatar
steve1955 steve1955 is offline
Very Frequent Poster
 
Join Date: Feb 2004
Location: Sunny(in my dreams)Manchester,England
Posts: 1,237
Default Re: Undetectable Malware?

Quote:
Originally Posted by Antarctica
A security researcher with expertise in rootkits has built a working prototype of new technology that is capable of creating malware that remains "100 percent undetectable," even on Windows Vista x64 systems.


http://www.eweek.com/article2/0,1895,1983037,00.asp
Its only udetectable at the moment!do you really think it will remain so forever(or even or very long)?
__________________
The part of a computer that causes most problems is the bit that holds the mouse!
  #3  
Old June 29th, 2006, 01:09 PM
sosaiso's Avatar
sosaiso sosaiso is offline
Frequent Poster
 
Join Date: Nov 2005
Posts: 601
Default Re: Undetectable Malware?

It's undetectable because it hasn't made it onto the blacklists yet. That is the weakness of anti- [insert word here. ie. viruses, trojan, malware]. They rely on signatures. AKA blacklists. If it hasn't been seen, it won't be prevented.
__________________
Windows Firewall, SandboxIE.
  #4  
Old June 29th, 2006, 05:00 PM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: Undetectable Malware?

Hello,
It's so simple. Boot from CD / DVD ... Check out for files and folders that aren't there in normal state ...
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #5  
Old June 30th, 2006, 12:25 AM
emir emir is offline
Regular Poster
 
Join Date: Dec 2005
Posts: 61
Default Re: Undetectable Malware?

Mrkvonic, are you referring to something along the lines of Bart's PE, something which does not let the hard drive start up at all? Because I have read articles describing this, I can't remember where though. This is very good point for detection, but if you don't know it's there(polymorphonic/no signature) I guess you could just do this on the regular for good measure. Like if you are just that paranoid or curious or are admin of sensitive information database right? So like Knoppix STD or other Linux live distro is right up this alley huh?
  #6  
Old June 30th, 2006, 03:03 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Undetectable Malware?

Quote:
Originally Posted by Antarctica
A security researcher with expertise in rootkits has built a working prototype of new technology that is capable of creating malware that remains "100 percent undetectable," even on Windows Vista x64 systems.


http://www.eweek.com/article2/0,1895,1983037,00.asp

Unless we...
Gain control beneth the rootkit.
Gain control before os.
Have hardware detection, Intel, AMD.

It will be interesting to see how the relationship proceeds between concept and technology.

...If you dont know Joanna Rutkowskas work you can checkout her site/blog http://theinvisiblethings.blogspot.com/
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : June 30th, 2006 at 09:58 AM.
  #7  
Old June 30th, 2006, 03:36 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: Undetectable Malware?

Quote:
Originally Posted by emir
Mrkvonic, are you referring to something along the lines of Bart's PE, something which does not let the hard drive start up at all? Because I have read articles describing this, I can't remember where though. This is very good point for detection, but if you don't know it's there(polymorphonic/no signature) I guess you could just do this on the regular for good measure. Like if you are just that paranoid or curious or are admin of sensitive information database right? So like Knoppix STD or other Linux live distro is right up this alley huh?

Hello,
Yes, BartPE, Helix, Knoppix, etc...
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #8  
Old July 3rd, 2006, 05:23 PM
oopsminded oopsminded is offline
Infrequent Poster
 
Join Date: Apr 2006
Posts: 21
Default Re: Undetectable Malware?

Quote:
Originally Posted by Mrkvonic
Hello,
It's so simple. Boot from CD / DVD ... Check out for files and folders that aren't there in normal state ...
Mrk
Joanna Rutkowska, on http://theinvisiblethings.blogspot.com/
Quote:
The phrase "on the fly" is the most important thing about Blue Pill - it makes it possible to install a blue pill based malware without restarting the system and without any BIOS or boot sector modifications. I wish all those people who were posting about how easy it would be to detect Blue Pill by booting a system from a clean CD, spent more time on reading my original blog article, instead creating useless posts... (just a little wish).
  #9  
Old July 3rd, 2006, 11:53 PM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: Undetectable Malware?

Hello,
Negative.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #10  
Old July 4th, 2006, 10:41 AM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re: Undetectable Malware?

Yes this was posted about over here and with not much response.

http://www.wilderssecurity.com/showt...=135615&page=2

Based on what was wirtten over at antirootkit.com.
  #11  
Old July 4th, 2006, 10:45 AM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re: Undetectable Malware?

I knew of Johanna's invisable.org site but guess I didn't know of her blog.

And I did make a comment about the same group from rootkit dot com hanging out at antirootkit dot com but it really makes no difference.



controler
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:09 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums