NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Vbootkit the First Rootkit Designed for Windows Vista Kernel Subversion

Via custom boot sector

By Marius Oiaga, Technology News Editor

26th of April 2007, 15:28 GMT

Adjust text size:



Enlarge picture
Vbootkit is a rootkit designed to load into Windows Vista's kernel from custom boot sectors. Its authors, security researchers Nitin Kumar and Vipin Kumar claim that this is the first example of such
technology. The Vbootkit's creators describe their rootkit as a back door, or a shortcut to access the Windows Vista Kernel. The Windows Vista kernel rootkit was developed on pre-release versions of the operating system, and only on the 32-bit editions of Windows Vista.

"Vboot kit is first of its kind technology to demonstrate Windows vista kernel subversion using custom boot sector. Vboot Kit shows how custom boot sector code can be used to circumvent the whole protection and security mechanisms of Windows Vista. Testing was performed on Windows Vista RC1 (build 5600) and Windows Vista RC2 (Build 5744). Majority of the stuff remains valid for Windows Vista RTM (Build 6000), though it has not been verified. Testing was done only on 32 bit systems," revealed the authors.

Vbootkit is a rootkit specific for Windows Vista that uses the boot-sectors (master boot record, CD , PXE , floppies etc) to load into the operating system's kernel. Nitin Kumar and Vipin Kumar informed that they did not release the source code online, but that the binaries were in fact submitted to anti-virus companies.

"Vista is still vulnerable to unsigned code execution.vbootkit is the name we have chosen ( V stands for Vista and boot kit is just a termed coined which is a kit which lets you doctor boot process).vbootkit concept presents how to insert arbitrary code into RC1 and RC2, thus effectively bypassing the famous Vista policy for allowing only digitally signed code to be loaded into kernel," additionally claimed the two authors on the NV Labs website.

TAGS:

Windows Vista | rootkit | kernel
Read by 3,145 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Under Attack Courtesy of Apple

Windows Vista Held Its Own Against .ANI Attacks

Windows Vista Is Top Dog

Watch Windows Vista Vulnerabilities Grow

Vista Dodges Fresh Windows Vulnerability

When Windows .ani Files Attack

Firefox 2.0 and IE7 - Attack Vectors for Windows Vista

Vista, Linux, Mac OS X - Apples, Apples, Apples?

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM