Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

January 8th, 2008, 11:26 GMT · By

Boot Record Rootkit Brings Windows Vista to Its Knees

SHARE:

Adjust text size:



Enlarge picture
A new boot record rootkit in the wild has the potential to bring Windows Vista down to its knees. Despite having applauded Windows Vista throughout 2007 as the most secure Windows operating system on the market, the latest Microsoft client still has some problems involving write-access to raw disk sectors. In this context, in early January 2008, GMER revealed that at the end of 2007 a new stealth MBR rootkit was detected in the wild, which could compromise Windows Vista.

"Unfortunately, all the Windows NT family (including VISTA) still have the same security flaw - MBR can be modified from usermode. Nevertheless, MS blocked
write-access to disk sectors from userland code on VISTA after the pagefile attack, however, the first sectors of disk are still unprotected", the GMER member explained. "At the end of 2007 stealth MBR rootkit was discovered by MR Team members and it looks like this way of affecting NT systems could be more common in near future if MBR stays unprotected."

Once it has infected a Vista machine, the rootkit will have full control over the boot process-code that is executed in advance of starting the operating system. The rootkit would only need to take ownership of just a few disk sectors in order to become stealth and hide itself. This scenario is further catalyzed by the fact that the rootkit code does not exist as a single file, but it is spread across disk sectors, and by the fact that no registry entry is made as the malicious item is loaded by the MBR code.

The rootkit is apparently based on a project delivered by security researchers Derek Soeder and Ryan Permeh, at Black Hat USA 2005. The eEye BootRoot exemplified a way for the subversion of the Windows kernel during the loading process via custom boot sector code. Back in 2006, as Windows Vista was passing through the final stages of development, security researcher Joanna Rutkowska successfully executed the pagefile attack on a Release Candidate 2 build of the operating system. Since then, the Redmond company has blocked write-access to raw disk sectors for user mode applications, even if the items run with elevated privileges.
FILED UNDER:
Windows Vista
rootkit
MBR

TELL US WHAT YOU THINK:

2,702 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Think Vista Is Safe - Well, It Doesn't Really Matter

Windows Vista vs. Mac OS X

"Keep Everything Clear of the Doors" - Even with Windows Vista

Think XP and Vista Are Security Disasters? Have You Looked at Tiger and Leopard Lately?

Windows Vista Multilingual User Interface Available for Download

READER COMMENTS:


Comment #1 by: jack straw on 09 Jan 2008, 12:39 UTC reply to this comment

Who has copy-pasted from whom?
http://www.pctipsbox.com/boot-record-rootkit-brings-windows-vista-to-its-knees/


Comment #2 by: Sorin on 09 Jan 2008, 14:20 UTC reply to this comment

It's obvious if you take into account that pctipsbox looks like a typical MFA site...


Comment #3 by: Alfie on 17 Sep 2008, 14:59 UTC reply to this comment

Yeah, pctipsbox also copied my articles and posted it into their website without any acknowledgment. Shame on them.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM