Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS)
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 26th, 2006, 08:46 PM
TheQuest's Avatar
TheQuest TheQuest is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Kent. UK by the sea
Posts: 2,226
Default "Blue Pill" [Do not read if Paranoid]

Hi, Jason R0

Will the new AppDefend be able to deal with the 'Blue Pill'.

Posted more in jest, then from being paranoid.


Take Care,
TheQuest
__________________
When Nothing is Certain, Anything is Possible.
  #2  
Old July 26th, 2006, 09:04 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,089
Default Re: "Blue Pill" [Do not read if Paranoid]

You know that if you tell paranoid people not to read something then they absolutly have to.
  #3  
Old July 26th, 2006, 09:25 PM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: "Blue Pill" [Do not read if Paranoid]

It will be able to be "intercepted" from occuring (not that AD supports this exact interception atm, but AppDefend x64 would be better than nothing for intercepting parts of the attack) and should still be able to be detected in various ways. That's not to say it will be easy, it is obvious that the new technology they are putting into PC hardware (for Digital Rights Management and other uses) will also likely be misused. This isn't "new", as new technology is always fertile ground for fancy new attacks. The biggest problem comes from the hardware limiting what other software (in this case security software) can do.
  #4  
Old July 26th, 2006, 11:09 PM
TheQuest's Avatar
TheQuest TheQuest is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Kent. UK by the sea
Posts: 2,226
Default Re: "Blue Pill" [Do not read if Paranoid]

Hi, Jason R0

Thank you for your reply.

I knew you will be able to keep abreast [or in front] and stop them.

Take Care,
TheQuest
__________________
When Nothing is Certain, Anything is Possible.

Last edited by TheQuest : July 26th, 2006 at 11:28 PM. Reason: [or in front]
  #5  
Old July 27th, 2006, 12:24 AM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Security Expert
 
Join Date: May 2004
Location: North West, United Kingdom
Posts: 2,839
Default Re: "Blue Pill" [Do not read if Paranoid]

Quote:
Originally Posted by TheQuest
Posted more in jest, then from being paranoid.
Joanna mentions there being 3 countermeasures to Blue Pill in her blog (I'd guess they would include opcode filtering to catch the special instructions used, installing a hypervisor beforehand and disabling the IOMMU which handles the address translation necessary for Pacifica) so this is unlikely to be an "undefeatable" technique for long. However it is another interesting case of how processor architecture can be exploited for nefarious ends.
  #6  
Old July 27th, 2006, 12:35 AM
TheQuest's Avatar
TheQuest TheQuest is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Kent. UK by the sea
Posts: 2,226
Default Re: "Blue Pill" [Do not read if Paranoid]

Hi, Paranoid2000


Thank you for your reply and input, as ever you understood what you was reading in the blog.

Where I was not sure what it was saying.

Take Care,
TheQuest
__________________
When Nothing is Certain, Anything is Possible.
  #7  
Old July 27th, 2006, 05:39 AM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Security Expert
 
Join Date: May 2004
Location: North West, United Kingdom
Posts: 2,839
Default Re: "Blue Pill" [Do not read if Paranoid]

Quote:
Originally Posted by TheQuest
...as ever you understood what you was reading in the blog.
I'm afraid you're being over-generous there! Joanna is being a bit of a tease (ladies, eh?) in not providing more details on the counters and the AMD documentation is, um, a little less than approachable. Hopefully things will be clarified soon and we won't have to guess further.
  #8  
Old July 28th, 2006, 09:54 PM
Jito463 Jito463 is offline
Infrequent Poster
 
Join Date: Jul 2006
Posts: 14
Default Re: "Blue Pill" [Do not read if Paranoid]

One possible alternative to block this is to be there first. The security software would do exactly what this "Blue Pill" software aims to do, so that the user (through the security software) will ultimately have more control over the system. So I consider this discovery a good thing. By the way, I thought you were told not to read this, Paranoid.

Quote:
[Do not read if Paranoid]
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS) « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:31 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums