NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
Home / News / Microsoft / Tools & Applications

Tools & Applications


Download Tool to Bypass Driver Signing on 32-bit and 64-bit Windows Vista

Windows XP and Windows Server 2003

By Marius Oiaga, Technology News Editor

30th of July 2007, 13:34 GMT

Adjust text size:


Windows Vista
Enlarge picture
Want to load unassigned drivers into 32-bit and 64-bit Windows Vista, Windows XP and Windows Server 2003? Then Atsiv, a tool created by Linchpin Labs & OSR, is the right thing for you. Specifically, Atsiv will enable you to circumvent the mandatory driver signing in the 64-bit editions of Vista. Microsoft applauded the fact that in the x64 editions of Vista unsigned code could not be loaded into the kernel. The security feature aims to prevent the techniques associated with rootkits and malicious kernel drivers. According to Linchpin Labs & OSR, Atsiv is designed to deliver compatibility for legacy drivers, that would otherwise prove a pain to load as unsigned drivers
into the x64 versions of Microsoft's latest operating system.

"When looking at how it did its magic the original .exe contains two resource sections: DRIVER_BIN32 and DRIVER_BIN64. These are actually signed 32-bit and 64-bit drivers. The command line tool loads the appropriate driver, which then in turn allows loading of unsigned drivers due to the implementation of their own PE loader," explained Ollie Whitehouse, Symantec Advanced Threat research Architect. "So in order for Microsoft to mitigate the risk of malicious code utilizing this signed driver to load their own, they are going to have to revoke the signing certificate. It'll be interesting to see how long it takes Microsoft to do this."

"Atsiv doesn't add the driver to the PsLoadedModuleslist so it is not visible in the standard drivers list.
The loaded driver is not completely loaded into memory - the DOS header for example, is not loaded. Atsiv ignores dependencies and will load a single driver regardless of its dependencies. If a driver has dependencies ensure they have all been loaded prior to loading the driver. If loading by file name a fake registry path is passed in to the drivers DriverEntry routine. Unlike the NT Loader Atsiv allows drivers with the same name to be loaded multiple times. Some drivers are not compatible with multiple instances running," Linchpin Labs & OSR revealed.

The fact of the matter is that even if Microsoft does revoke one specific signing certificate, the process will only move on to focus on another, still valid, certificate. However, Linchpin Labs & OSR revealed that Atsiv is neither fully safe nor reliable, although all possible efforts in this matter have been done. As a result, the process - which is different from the operating system's Loader - can result in platform crashes. The developers advise the users to exercise care when deploying unsigned drivers to Vista.

Atsiv 1.01 was tested by Softpedia as being 100% Clean and is available for download here.

TAGS:

Atsiv | Windows Vista | unsigned driver


Rating:
Fair (2.7/5) 8 vote(s) so far    

Read by 10,076 user(s) | Add comment | Link to this article
Subscribe to news | Print article | Send to friend

© Copyright 2001-2008 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Kills Multiple Graphics Processing Units Video Cards

Microsoft Doesn't Know Its Own Vista = Poor XP vs. Vista Business vs. Vista Ultimate Comparison

Suck on Microsoft's Windows Vista Lollipop!

x64 and x86 Network Monitor 3.1 for Windows Vista

Windows Vista SP1 Available for Download Next Week - July 16!

Linux in Last Place! Windows Vista Didn't Do It!

Upgrade 32-bit XP, Windows 2000, Vista and 64-bit XP and Vista to 62-bit Windows Vista

Windows Vista SP1 Delayed until 2009?

Forget about DirectX 10 - Introducing DirectX 10.1 Preview for Windows Vista SP1

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

You are not logged on. Comments can still be added, but they will have to be approved before going live.
Log on to get your comments posted and visible instantly.
Your Name:
Your Email Address:
(will not be used for commercial purposes)
Your review/opinion:

 






SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM