Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

February 10th, 2007, 11:15 GMT · By

Disabling Mandatory Kernel Mode and Driver Signing In x64 Vista

SHARE:

Adjust text size:


64-bit Windows Vista kernel protection is divided into two dimensions: PatchGuard and Mandatory Kernel Mode and Driver Signing. Kaspersky has made their perspective on the Kernel Patch
Protection public, calling it more of a joke than a serious security barrier against rootkits. And the Mandatory Kernel Mode and Driver Signing was not overlooked by the Russian antivirus maker.

Kaspersky revealed that there are a set of documented methods designed to disable signature checking. With x64 Vista, digital signature for any module or driver at kernel level is mandatory. "There are several documented methods for disabling signature checking, among them methods which are designed to simplify the driver development and testing process. This is because the issue of how to develop drivers is real - it's impossible to ask for a digital signature for every build prior to testing - which is why there are several ways to disable signature checking," stated Alisa Shevchenko, Virus analyst, Kaspersky Lab.

In this regard, connecting a system debugger, booting into a mode with no drivers control or monitoring and enabling support for test signatures are all valid methods of disabling Mandatory Kernel Mode and Driver Signing. Kaspersky claims that the methods of disabling Mandatory Kernel Mode and Driver Signing are not limited to these three examples and that there is plenty of room for experiments.

"We anticipate a multitude of methods designed to get around kernel mode protection by loading unsigned components. Once again, the verdict is the same: yes, this function protects the operating system against malicious code, but it is not as effective as the developers claim," Shevchenko concluded.

TELL US WHAT YOU THINK:

22,933 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Crack Available to Install Windows Vista with Only 256MB RAM

PC Sales Skyrocket Following the Release of Windows Vista

The $500 Million Windows Vista "Wow"

Vista Is Live - Buy and Download Now from Windows Marketplace

Vista Upgrade Kills Windows XP

READER COMMENTS:


Comment #1 by: John Thompson on 21 Jun 2009, 05:51 UTC reply to this comment

Nice article...oh except for the extreme lack of detail. That kind of makes the article suck. Yeah. How about Kaspersky back up their claims with some detailed examples? I can say that I forsee SOOO many ways that people will walk out of Fort Knox with truck loads of gold bars just as easily as the claims they make here. And my claims are probably equally as valid. Booting into test mode to allow unsigned drivers is not at all a vulnerability in 64-bit Vista. If you claim there is a vulnerability -- prove it -- or shut up and quit trying to get free press for you AV products.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM