<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Inquisitr &#187; rootkits</title>
	<atom:link href="http://www.inquisitr.com/tag/rootkits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.inquisitr.com</link>
	<description>The Better Mix</description>
	<lastBuildDate>Tue, 14 Feb 2012 20:06:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Bootkit &#8211; the next generation rootkit terror</title>
		<link>http://www.inquisitr.com/31615/bootkit-the-next-generation-rootkit-terror/</link>
		<comments>http://www.inquisitr.com/31615/bootkit-the-next-generation-rootkit-terror/#comments</comments>
		<pubDate>Sun, 02 Aug 2009 03:40:19 +0000</pubDate>
		<dc:creator>Steven Hodson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[bootkits]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/31615/bootkit-the-next-generation-rootkit-terror/</guid>
		<description><![CDATA[<br />I remember well the noise that was made when word of rootkits began to surface. They were nasty little suckers that threaten to by-pass your security programs and load all kinds of nasty bugger onto your computer. It was one of these rootkits that got SonyBMG into really big trouble in 2005 when it was [...]<p><a href="http://www.inquisitr.com/31615/bootkit-the-next-generation-rootkit-terror/">Bootkit &ndash; the next generation rootkit terror</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
			<content:encoded><![CDATA[<p><center><img title="bootkit" border="0" alt="bootkit" src="http://www.inquisitr.com/wp-content/bootkit.png" width="495" height="184" /> </center>
<p>I remember well the noise that was made when word of <a href="http://en.wikipedia.org/wiki/Rootkit">rootkits</a> began to surface. They were nasty little suckers that threaten to by-pass your security programs and load all kinds of nasty bugger onto your computer. It was one of these rootkits that got SonyBMG into really big trouble in 2005 when it was discovered that their music CDs were installing them as part of their DRM effort.</p>
<p>Well it seems that the next generation of these horrors has now arrived on the scene and are going by the name of ‘bootkits’ and these bootkits make the rootkits look like boy scouts. Announced at the Black Hat conference where its creator, 18 year-old Peter Kleissner, showed how the bootkit, called Stoned, was capable of bypassing a TrueCrypt encrypted partition and system encryption.</p>
<p>Stoned, the bootkit, combines a rootkit with the ability to modify a PC’s Master Boot Record which enables malware to be activated even before the operating system is started. Kleissner’s bootkit is able to infect all available 32 bit varieties of Windows from Windows 2000 to Windows Vista along with the most current Release Candidate of Windows 7.</p>
<blockquote><p>Stoned injects itself into the Master Boot Record (MBR), a record which remains unencrypted even if the hard disk itself is fully encrypted. During startup, the BIOS first calls the bootkit, which in turn starts the TrueCrypt boot loader. Kleissner says that he neither modified any hooks, nor the boot loader, itself to bypass the TrueCrypt encryption mechanism. The bootkit rather uses a &quot;double forward&quot; to redirect I/O interrupt 13h, which allows it to insert itself between the Windows calls and TrueCrypt. Kleissner tailored the bootkit for TrueCrypt using the freely available TrueCrypt source code.</p>
<p>Once the operating system has been loaded, Stoned can get to work and install malware, such as a banking trojan, in the system. Peter Kleissner, who is only 18 years old, has also included several plug-ins, for example a boot password cracker and a routine for infecting the BIOS. The framework layout of Stoned allows other programmers to develop their own plug-ins for the bootkit. Kleissner thinks that Stoned could also be of interest to investigation agencies, for example for developing a federal trojan.</p>
<p>Source: The H-Security :: <a href="http://www.h-online.com/security/Bootkit-bypasses-hard-disk-encryption--/news/113884">Bootkit bypasses hard disk encryption</a></p>
</blockquote>
<p>Interestingly enough the bootkit will not work under two conditions. The first being if the computer is using the successor to the BIOS – known as the <a href="http://en.wikipedia.org/wiki/Extensible_Firmware_Interface">Extensible Firmware Interface (EFI)</a>. The second is when the drive is encrypted using Windows own Bitlocker encryption mechanism.</p>
<p>For anyone old enough the use of Stoned as a name for this bootkit should bring back some memories as this was also <a href="http://en.wikipedia.org/wiki/Stoned_virus">the name of a silly but irritating virus back in the late 80’s</a> which I do remember quite well even though I never got hit by it.</p>
<p><a href="http://www.inquisitr.com/31615/bootkit-the-next-generation-rootkit-terror/">Bootkit &ndash; the next generation rootkit terror</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/31615/bootkit-the-next-generation-rootkit-terror/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/bootkit.png" />
		<media:content url="http://www.inquisitr.com/wp-content/bootkit.png" medium="image">
			<media:title type="html">bootkit</media:title>
		</media:content>
	</item>
		<item>
		<title>CPU poisoning affects Intel systems</title>
		<link>http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/</link>
		<comments>http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 17:38:38 +0000</pubDate>
		<dc:creator>Steven Hodson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[CPU]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/</guid>
		<description><![CDATA[<br />Researchers at Invisible Things Lab presented information at the CanSecWest conference on Thursday in Vancouver about a security exploit that could comprise computers running on Intel processors. The exploit involves the poisoning of of the cache of a CPU operating in System Management Mode (SMM). They also noted that this was the third such types [...]<p><a href="http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/">CPU poisoning affects Intel systems</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
			<content:encoded><![CDATA[<p><center><img title="poison" border="0" alt="poison" src="http://www.inquisitr.com/wp-content/poison.jpg" width="379" height="284" /> </center>
<p>Researchers at Invisible Things Lab presented information at the CanSecWest conference on Thursday in Vancouver about a security exploit that could comprise computers running on Intel processors. The exploit involves the poisoning of of the cache of a CPU operating in System Management Mode (SMM). They also noted that this was the third such types of security exploits that the team had found affecting Intel based computers in the last ten months.</p>
<p>The SMM exploit works by poisoning the chip’s cache memory which would allow for forced access to SMM, one of the most privileged CPU modes on x86 architectures. Even operating systems can’t access SMM – the mode that handles certain errors, power management and other features.</p>
<blockquote><p>The potential consequence of attacks on SMM might include SMM rootkits, hypervisor compromises, or OS kernel protection bypassing, they said.</p>
<p>Intel has been working on a solution to prevent caching attacks on SMM memory, and a spokesperson has said that many new systems are protected against the exploit. But, writing in their paper, Rutkowska and Wojtczuk said: “Some of Intel&#8217;s recent motherboards, like the popular DQ35, are still vulnerable to the attack. Additionally, the workarounds that Intel has mentioned to us are not yet officially documented.”</p>
<p>Source: SC Magazine &#8211; <a href="http://www.scmagazineus.com/Intel-CPU-exploit-threatens-PCs-worldwide/article/129194/">Intel CPU exploit threatens PCs worldwide</a></p>
</blockquote>
<p>Time to bloated Norton solution in 3 …. 2 …. 1…..</p>
<p><a href="http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/">CPU poisoning affects Intel systems</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/poison.jpg" />
		<media:content url="http://www.inquisitr.com/wp-content/poison.jpg" medium="image">
			<media:title type="html">poison</media:title>
		</media:content>
	</item>
	</channel>
</rss>

