David Overton's Blog and Discussion Site
This site is my way to share my views and general business and IT information with you about Microsoft, IT solutions for ISVs, technologists and businesses, large and small

This blog is purely the personal opinions of David Overton. . If you can't find the information you were looking for e-mail me at admin@davidoverton.com. If you want to narrow down the content consider these links:


Do you remember the Matrix - the "Blue Pill" - well someone has developed a scary security rootkit using the VM technology in AMD & Intel's chips for Windows x64, Linux etc
David Overton's Blog

Syndication

ISV

Developer

Live and SAAS

Small Business Blogs

Business

Home Server

Office Blogs

Windows Vista Blogs and Links

Microsoft Feeds

Useful Blogs of note

User Groups

News

Star Wars

Useful Sponsored Links

Some may know that my history includes a bit of serious security IT work.  Having said that, it also includes mission critical systems work and even part of my degree was on system security, but that is what you get for sharing a flat with someone doing a security degree.

Anyway, the e-week article discusses a process to make the "undetectable" rootkit using virtualisation technology.  A very interesting read and a sign of scary times in the future for security subsystems.

OK, I thought about it a bit more and discussed it on im with Susan Bradley and perhaps some of the old questions come into play.  Can a user with standard admin rights get infected?  Could you have an anti-rootkit hypervisor to test and ensure that the "right" hypervisor is running?

Once this beasty was in, detection would be very hard, however, for it to get ontop your machine - this could be just like every other rootkit today - needs admin clearance, so don't say yes to it!!

ttfn

David


Posted Thu, Jun 29 2006 9:18 PM by David Overton

Add a Comment

(required)  
(optional)
(required)  
Remember Me?

(c)David Overton 2006-8