NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Disabling Mandatory Kernel Mode and Driver Signing In x64 Vista

Via documented methods

By Marius Oiaga, Technology News Editor

10th of February 2007, 11:15 GMT

Adjust text size:


64-bit Windows Vista kernel protection is divided into two dimensions: PatchGuard and Mandatory Kernel Mode and Driver Signing. Kaspersky has made their perspective on the Kernel Patch
Protection public, calling it more of a joke than a serious security barrier against rootkits. And the Mandatory Kernel Mode and Driver Signing was not overlooked by the Russian antivirus maker.

Kaspersky revealed that there are a set of documented methods designed to disable signature checking. With x64 Vista, digital signature for any module or driver at kernel level is mandatory. "There are several documented methods for disabling signature checking, among them methods which are designed to simplify the driver development and testing process. This is because the issue of how to develop drivers is real - it's impossible to ask for a digital signature for every build prior to testing - which is why there are several ways to disable signature checking," stated Alisa Shevchenko, Virus analyst, Kaspersky Lab.

In this regard, connecting a system debugger, booting into a mode with no drivers control or monitoring and enabling support for test signatures are all valid methods of disabling Mandatory Kernel Mode and Driver Signing. Kaspersky claims that the methods of disabling Mandatory Kernel Mode and Driver Signing are not limited to these three examples and that there is plenty of room for experiments.

"We anticipate a multitude of methods designed to get around kernel mode protection by loading unsigned components. Once again, the verdict is the same: yes, this function protects the operating system against malicious code, but it is not as effective as the developers claim," Shevchenko concluded.
Read by 17,789 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.0/5) 9 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Crack Available to Install Windows Vista with Only 256MB RAM

PC Sales Skyrocket Following the Release of Windows Vista

The $500 Million Windows Vista "Wow"

Vista Is Live - Buy and Download Now from Windows Marketplace

Vista Upgrade Kills Windows XP

Clean Installations of Windows Vista

Ballmer + Vista Failed to Gather a Crowd

New Windows Vista 3 Ways Crack

User opinions:


Comment #1 by: John Thompson on 21 Jun 2009, 05:51 GMT reply to this comment

Nice article...oh except for the extreme lack of detail. That kind of makes the article suck. Yeah. How about Kaspersky back up their claims with some detailed examples? I can say that I forsee SOOO many ways that people will walk out of Fort Knox with truck loads of gold bars just as easily as the claims they make here. And my claims are probably equally as valid. Booting into test mode to allow unsigned drivers is not at all a vulnerability in 64-bit Vista. If you claim there is a vulnerability -- prove it -- or shut up and quit trying to get free press for you AV products.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM