The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Rootkit migrates Windows into virtual machine
Time: 01:47 EST/06:47 GMT | News Source: *Linked Within Post* | Posted By: Kenneth van Surksum

Another virtual machine rootkit which can migrate Windows into a virtual machine (VM) while it is running was presented at the Microsoft initiated BlueHat hacker conference, held at the end of October. The rootkit, known as Vitrol, uses Intel's Virtualization Technology (VT-x, formerly Vanderpool). In contrast to software virtualization techniques, hardware-based virtualization solutions offer direct processor support.

It is then impossible for Windows or Linux, once migrated into a VM, to remove the rootkit, as it runs below their detection horizon. Virus scanners and rootkit sniffers would have no chance of protecting the system against such rootkits. Vista's new PatchGuard and driver signature kernel protection functions for 64-bit systems would also be useless. Vitriol was developed by security specialist Dino Dai Zovi and has already been presented - but not demonstrated - at the Black Hat conference. By contrast, Joanna Rutkowska gave a practical demonstration of a prototype of her Blue Pill VM rootkit at Black Hat. Blue Pill uses AMD's SVM/Pacifica virtualization solution to infiltrate a hypervisor into Windows whilst it is running. Microsoft is also looking at the effect of VM rootkits with its SubVirt proof of concept rootkit.

Write Comment
Return to News

  Displaying 301 through 301 of 301
Prev | First
  The time now is 12:58:53 AM ET.
Any comment problems? E-mail us
#301 By 4240821 (77.83.4.69) at 11/24/2024 9:12:34 PM
https://justpaste.me/CIng4
https://justpaste.me/CKnZ
https://justpaste.me/BdKG5
https://justpaste.me/BfQa2
https://justpaste.me/BoXc1
https://justpaste.me/By0Z
https://justpaste.me/Bv2J2
https://justpaste.me/CKnZ
https://justpaste.me/CZN8
https://justpaste.me/CU3n

Write Comment
Return to News
  Displaying 301 through 301 of 301
Prev | First
  The time now is 12:58:53 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *