Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 8th, 2008, 04:19 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Z0mBiE rootkit- Bypassed all ARK tools

http://forum.sysinternals.com/forum_...TID=13773&PN=1

It has been a long time to read about some interesting malware/ POC.
Unforunately the rootkit is private.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #2  
Old March 8th, 2008, 05:02 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

According to EP_X0FF, this rootkit doesn't work in LUA
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #3  
Old March 8th, 2008, 05:27 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Are there rootkits that work in LUA?
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #4  
Old March 8th, 2008, 05:31 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

EP_X0FF said:
Quote:
I believe, in x64, only system approach can handle this NT hell. Fully restricted access to kernel mode part, new security model (with updated NTFS) and a fully isolated kernel with self-integrity control. But this will lead to the end of: personal firewalls, host intrusion prevention system, some antiviruses, sandboxes, most of utilities and executable packers.

Everything else just a weak attempts and hijacking money from users.
Quote:
One good solution cannot change everything. Besides it will become a primary target for script-kiddies, malware writers etc. So its bypassing will be a question of time (as it was in case of RkTrap). Windows already support enough security model, but almost nobody doesn't use it. It is very strange be against something with administrative .

New OS is better than security through obscurity.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #5  
Old March 8th, 2008, 05:57 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Originally Posted by aigle
Are there rootkits that work in LUA?
Full user-mode rootkits should work in LUA.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #6  
Old March 8th, 2008, 06:03 PM
SirMalware SirMalware is offline
Regular Poster
 
Join Date: Jun 2006
Posts: 133
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Full user-mode rootkits should work in LUA.
How, if no execution/write is possible.
  #7  
Old March 8th, 2008, 06:19 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Execution is allowed everywhere under LUA (unless you're combining LUA with SRP) and you can do some process hiding (AFAIK)
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #8  
Old March 8th, 2008, 07:34 PM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Originally Posted by aigle
Are there rootkits that work in LUA?

If with LUA you mean simple standard Windows limited user account (without any other kind of restrictions) yes, there are, of course.
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute
  #9  
Old March 8th, 2008, 07:40 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Thanks Lucas n Eraser.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #10  
Old March 8th, 2008, 09:17 PM
Primrose's Avatar
Primrose Primrose is offline
Security Expert
 
Join Date: Sep 2002
Posts: 2,743
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Might be a good idea to now read the whole thread there...it is very funny So many ego's and not enough stages in the world.
  #11  
Old March 9th, 2008, 10:45 AM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Originally Posted by Primrose
Might be a good idea to now read the whole thread there...it is very funny So many ego's and not enough stages in the world.

Oh so true,the VT bit about samples made me chuckle....some folks forget that VT uploads are sent out on the wire as received to the participating Vendors.Whether or not they look at a sample is another kettle of fish tho but all uploads should be trackable and recoverable by MD5 alone IRC

So what's in a name ...."Z0mBiE"....returns
__________________
Ade Gill
Malwarebytes Researcher
  #12  
Old March 9th, 2008, 03:08 PM
SirMalware SirMalware is offline
Regular Poster
 
Join Date: Jun 2006
Posts: 133
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
unless you're combining LUA with SRP
This was my point. I should have been more specific.
Quote:
Execution is allowed everywhere under LUA
If used in conjunction with Windows Policies, that's false.

Last edited by SirMalware : March 9th, 2008 at 03:39 PM.
  #13  
Old March 9th, 2008, 04:35 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Originally Posted by SirMalware
If used in conjunction with Windows Policies, that's false.
Correct
Have you tested LUA+SRP against live exploits?
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #14  
Old March 9th, 2008, 05:26 PM
SystemJunkie SystemJunkie is offline
Resident Conspiracy Theorist
 
Join Date: Mar 2006
Location: Germany
Posts: 1,500
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Unforunately the rootkit is private.
Only related to the mass.

WakeUp_Neo why you do not join this thread? Mr Chameleon always present or his bot friend whatever.
Zombies are everywhere

Last edited by SystemJunkie : March 9th, 2008 at 07:55 PM.
  #15  
Old March 9th, 2008, 05:39 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Which HIPS and sandboxes does it bypass (when granted execution rights)?
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #16  
Old March 9th, 2008, 05:50 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Originally Posted by lucas1985
Which HIPS and sandboxes does it bypass (when granted execution rights)?
Ya, System Junkie! can u try it against some HIPS, sandboxes and post us some screenshots or just plain info if it,s not against EULA?

I will like to know about:

CFP Defence plus
GesWall
ThreatFire
SBIE
EQS

Thanks
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #17  
Old March 9th, 2008, 07:47 PM
SirMalware SirMalware is offline
Regular Poster
 
Join Date: Jun 2006
Posts: 133
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
Have you tested LUA+SRP against live exploits?
Of course, many. I have yet to be infected.
  #18  
Old March 9th, 2008, 10:43 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

That's good to know. Thanks
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #19  
Old March 9th, 2008, 11:54 PM
SirMalware SirMalware is offline
Regular Poster
 
Join Date: Jun 2006
Posts: 133
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

It's (LUA+SRP) a methodology that not too many people seem to use. I don't know why; it's easy, secure, free and gets even better using 64-bit Vista. I have two test boxes, one with XP Pro, the other with Vista 64-bit. I try to test with the newest files I can find, the ones AV software don't recognize yet. I then check for any possible infiltration(s) using a variety of tools run from inside the hard drive and also from outside the hard drive.
  #20  
Old March 10th, 2008, 12:16 AM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

That would be great.
LUA + SRP is slowly (but surely) catching people's attention here at Wilders. See here and here.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #21  
Old March 10th, 2008, 08:46 AM
SystemJunkie SystemJunkie is offline
Resident Conspiracy Theorist
 
Join Date: Mar 2006
Location: Germany
Posts: 1,500
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Quote:
if it,s not against EULA?
Probably it is
  #22  
Old March 10th, 2008, 09:33 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: Z0mBiE rootkit- Bypassed all ARK tools

Are u sure? U might ask the vendor!
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:40 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums