<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Security Flaw in Vista and XP - Rootkit exploit in the wild</title>
	<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/</link>
	<description>Antirootkit Software, News, Articles and Forums</description>
	<pubDate>Fri, 12 Mar 2010 04:27:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: Spyware Remover Help &#187; Blog Archive &#187; Stealth techniques in rootkits</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-27420</link>
		<pubDate>Fri, 08 Feb 2008 08:30:22 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-27420</guid>
					<description>[...] Some days ago MR Team members warned that a new stealth technique was being used by some rootkits. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Some days ago MR Team members warned that a new stealth technique was being used by some rootkits. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: ManBearPig</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-27035</link>
		<pubDate>Sat, 02 Feb 2008 22:36:08 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-27035</guid>
					<description>Thanks for the good info</description>
		<content:encoded><![CDATA[<p>Thanks for the good info
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: מתקנים מתנפחים</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-26731</link>
		<pubDate>Mon, 28 Jan 2008 10:15:58 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-26731</guid>
					<description>i heard about rookit so much.
i plane to work in Vista in few months
when you will have solution for that?</description>
		<content:encoded><![CDATA[<p>i heard about rookit so much.<br />
i plane to work in Vista in few months<br />
when you will have solution for that?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Information Web Net &#187; Blog Archive &#187; MBR Rootkit: A Web Threat?</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-26502</link>
		<pubDate>Thu, 24 Jan 2008 01:18:16 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-26502</guid>
					<description>[...] James Cridland wrote an interesting post today.Have a look for your self, Here&#8217;s an excerpt, read the full story at the blogMore information at:. http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/; http://www2.gmer.net/mbr/. Update courtesy of Senior Escalation Engineers Joseph Cepe and Marvin Cruz. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] James Cridland wrote an interesting post today.Have a look for your self, Here&#8217;s an excerpt, read the full story at the blogMore information at:. <a href='http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/;' rel='nofollow'>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/;</a> <a href='http://www2.gmer.net/mbr/.' rel='nofollow'>http://www2.gmer.net/mbr/.</a> Update courtesy of Senior Escalation Engineers Joseph Cepe and Marvin Cruz. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: steo</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25948</link>
		<pubDate>Fri, 11 Jan 2008 01:23:21 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25948</guid>
					<description>Hi Richard,
indeed this particular rootkit does not work on Vista.
I think the main point here is that the MBR in Vista can be written to. Later versions can target Vista because of this.
regards
Steo</description>
		<content:encoded><![CDATA[<p>Hi Richard,<br />
indeed this particular rootkit does not work on Vista.<br />
I think the main point here is that the MBR in Vista can be written to. Later versions can target Vista because of this.<br />
regards<br />
Steo
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Richard</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25908</link>
		<pubDate>Thu, 10 Jan 2008 06:21:33 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25908</guid>
					<description>MBR rootkits doesn't work on Window's Vista because Derek's code doesn't  supported vista.For MBR rootkit to work on Vista it has to be based on VBOOTKIT.
As Vista booting process is totally different from XP.</description>
		<content:encoded><![CDATA[<p>MBR rootkits doesn&#8217;t work on Window&#8217;s Vista because Derek&#8217;s code doesn&#8217;t  supported vista.For MBR rootkit to work on Vista it has to be based on VBOOTKIT.<br />
As Vista booting process is totally different from XP.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: MBR Rootkit: A Web Threat? &#124; TrendLabs &#124; Malware Blog - by Trend Micro</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25905</link>
		<pubDate>Thu, 10 Jan 2008 04:08:53 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25905</guid>
					<description>[...] http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/ [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] <a href='http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/' rel='nofollow'>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/</a> [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Blog do Anderson Thiago (a.k.a Anderson T) : Rootkit utiliza falha em MBR para ter controle total no Windows</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25691</link>
		<pubDate>Sat, 05 Jan 2008 17:54:03 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25691</guid>
					<description>[...] Rootkit utiliza falha em MBR para ter controle total no Windows No inicio de Dezembro de 2007, um Rootkit que se escondia na MBR foi encontrado sendo&#160;mais uma Prova de Conceito (POC). Este Rootkit aproveita uma falha na MBR para se instalar e quando conclui, tem total controle sobre o Sistema Operacional (XP, NT e Vista). Esta POC é mais um exemplo de que os autores de Rootkit estão desenvolvendo técnicas cada vez mais complexas&#160;para driblarem os Softwares Anti Rootkits. Os passos seguidos por este tipo de Rootkit são:  Se instala nos últimos setores da unidade de disco do usuário Modifica outros setores Modifica o setor 0 e se instala no mesmo A partir disto, o Rootkit é executado antes mesmo do Windows ser iniciado, podendo instalar/executar qualquer tipo de código malicioso sem que o usuário e/ou Windows saiba o que esta ocorrendo e com pleno controle total. O Software GMER's Anti Rootkit consegue localizar este novo tipo de vetor de ataque, porém, não consegue removê-lo pelo Windows. Para que seja possível sua remoção, o código do Rootkit não pode estar sendo executado, logo, a unidade de disco nào pode ser iniciada. Fonte: Anti Rootkit Blog  Publicado Saturday, January 05, 2008 3:41 PM por Anderson T Tags da mensagem: Falha, Windows, Seguran&#231;a, Rootkit, MBR [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Rootkit utiliza falha em MBR para ter controle total no Windows No inicio de Dezembro de 2007, um Rootkit que se escondia na MBR foi encontrado sendo&nbsp;mais uma Prova de Conceito (POC). Este Rootkit aproveita uma falha na MBR para se instalar e quando conclui, tem total controle sobre o Sistema Operacional (XP, NT e Vista). Esta POC é mais um exemplo de que os autores de Rootkit estão desenvolvendo técnicas cada vez mais complexas&nbsp;para driblarem os Softwares Anti Rootkits. Os passos seguidos por este tipo de Rootkit são:  Se instala nos últimos setores da unidade de disco do usuário Modifica outros setores Modifica o setor 0 e se instala no mesmo A partir disto, o Rootkit é executado antes mesmo do Windows ser iniciado, podendo instalar/executar qualquer tipo de código malicioso sem que o usuário e/ou Windows saiba o que esta ocorrendo e com pleno controle total. O Software GMER&#8217;s Anti Rootkit consegue localizar este novo tipo de vetor de ataque, porém, não consegue removê-lo pelo Windows. Para que seja possível sua remoção, o código do Rootkit não pode estar sendo executado, logo, a unidade de disco nào pode ser iniciada. Fonte: Anti Rootkit Blog  Publicado Saturday, January 05, 2008 3:41 PM por Anderson T Tags da mensagem: Falha, Windows, Seguran&#231;a, Rootkit, MBR [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Security Flaw in Vista and XP - Rootkit exploit in the wild - Donna&#39;s SecurityFlash</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25670</link>
		<pubDate>Sat, 05 Jan 2008 08:35:46 +0000</pubDate>
		<guid>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comment-25670</guid>
					<description>[...] http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/  Published Saturday, January 05, 2008 8:35 AM by donna [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] <a href='http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/' rel='nofollow'>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/</a>  Published Saturday, January 05, 2008 8:35 AM by donna [&#8230;]
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
