Archive for February, 2007

Manifesto of the ethical Anti-Rootkit writer

Wednesday, February 21st, 2007

Cd-MaN, a popular Romanian Blogger has written in his Blog recently that he is not getting on very well with the creators of one of the best known anti-rootkit scanners, Rootkit Unhooker.

In various posts, No love for RkUnhooker, And so the RkUnhooker saga begins and Mismoderated RkUnhooker comment Cd-MaN details the exchange of “words” between himself, EP_X0FF and MP_ART. It all began with a posting called Mixed links and commentary so start here. I will leave it up to the reader to come to their own conclusion and judgement on the events in these postings.

Following on from these postings Cd-MaN has set up a “Manifesto of the ethical Anti-Rootkit writer” where Anti Rootkit program authors are asked to sign up to a few simple rules :

From Cd-MaN’s Blog….

Manifesto of the ethical Anti-Rootkit writer

  • I will give a high level description of the actions performed by my program which can be understood by even moderately technical savvy user (so called “power users“) and I will follow that description to the letter (for example, if you state that “this tool allows the detection of hidden processes“, the tool should only detect the processes, not terminate them. If the tool also terminates them, that should be included in the description).
  • The program will not perform possibly dangerous operations without user consent. The message informing the user should contain a simple enough description of the action so that “power users” are able to understand it, and also list the possible risks.
  • I will limit my kernel mode code to as little as possible.
  • I will clearly list the supported platforms (operating system version and patch level) and give the user warnings if the s/he is using the tool on an unsupported platform.
  • I do not approve or am engaged in illegal activities (like site defacement, DDoS, etc)
  • All of my research is done on computers owned by me or by consenting people. In case I ask other people to test my programs / products, I will provide them with a detailed description of what the program does, what the associated risks of using this program are and what files / registry keys are associated with / modified by the program.
  • I practice responsible disclosure. I notify vendors prior to releasing any information which could negatively impact the security of the people using their products.

So if you are an Anti-Rootkit writer and you would like to sign up please visit his blog posting Manifesto of the ethical Anti-Rootkit writer and read the details.

I wonder if companies like F-Secure, Panda, McAfee and Sophos sign up?

Stay Safe,

Steo

www.antirootkit.com

New Linux Anti Rootkit Scanner released

Tuesday, February 20th, 2007