CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

News-Roots
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17293

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Thu Jul 13, 2006 7:21 pm    Post subject: News-Roots
Reply with quote

Here you will find the latest, and sometimes the strangest, news on Rootkits featuring our very own News-Roots Reporter wawadave. Thumbs Up

image


* Anyone can post rootkit related news here. Include a brief excerpt and the link to the full story.

(Please do not quote whole articles verbatim unless you have the written permission of the authors or publishers to do so.)

**If you want to discuss these stories, please open a seperate New Topic. Thanks.

***All posts are subject to our approval. Smile


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008


Last edited by Prince_Serendip on Thu Jul 13, 2006 10:55 pm, edited 3 times in total
Back to top
View users profile Send private message
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Thu Jul 13, 2006 7:37 pm    Post subject:
Reply with quote

Hello
This is not the newest or the strangest. But the news event that brought windows rootkits into the open for all to see.

Mark's Sysinternals Blog: Sony, Rootkits and Digital Rights ...

Yes long since after the fact. But to any newbies you should have a read and do a google you can see and learn some basics!

If anyone else has any recent news or alerts please feel free to post small exert and link to the original source web page will work fine!


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Tue Jul 18, 2006 5:01 am    Post subject:
Reply with quote

invisiblethings: Introducing Blue Pill
All the current rootkits and backdoors, which I am aware of, are based on a concept. For example: FU was based on an idea of unlinking EPROCESS blocks from the kernel list of active processes, Shadow Walker was based on a concept of hooking the page fault handler and marking some pages as invalid, deepdoor on changing some fields in NDIS data structure, etc... Once you know the concept you can (at least theoretically) detect the given rootkit.
http://theinvisiblethings.blogspot.com/2006/06/introducing-blue-pill.html


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Tue Jul 18, 2006 5:41 am    Post subject:
Reply with quote

7/11: Backdoor.Pcclient.B Trojan Dropped by Other Trojan
Backdoor.Pcclient.B is a back door Trojan horse program with rootkit functionality that
allows a remote attacker unauthorized access to the compromised computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2led,1,9bsk,9mal,9s3s,a9gz


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
plunx

Lieutenant
Lieutenant


Joined: Nov 01, 2005
Posts: 194
Location: Sweden

PostPosted: Tue Jul 18, 2006 10:59 pm    Post subject:
Reply with quote

The Haxdoor family....... Evil or Very Mad

They all steal passwords for mail accounts and online banking and opens
an backdoor.

http://www.f-secure.com/v-descs/haxdoor_m.shtml

http://www.f-secure.com/v-descs/haxdoor.shtml

http://www.symantec.com/security_response/writeup.jsp?docid=2006-071214-4735-99&tabid=1


Interresting "mismatch" between security vendors and versions....


Cool

Back to top
View users profile Send private message
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Mon Jul 24, 2006 4:35 am    Post subject:
Reply with quote

Windows rootkits of 2005, part one
This three-part article series looks at Windows rootkits indepth. Part one discusses what a rootkit is and what makes them so dangerous, by looking at various modes of execution and how they talk to the Windows kernel.
By: James Butler, Sherri Sparks 2005-11-04
http://www.securityfocus.com/infocus/1850


Windows rootkits of 2005, part two
This three-part article series looks at Windows rootkits indepth. Part two focuses on the latest cutting edge rootkit technologies that are used to hide malicious code from security scanners.
By: James Butler, Sherri Sparks 2005-11-17
http://www.securityfocus.com/infocus/1851


Windows rootkits of 2005, part three
The third and final article in this series explores five different rootkit detection techniques used to discover Windows rootkit deployments. Additionally, nine different tools designed for administrators are discussed.
By: James Butler, Sherri Sparks 2006-01-05
http://www.securityfocus.com/infocus/1854

Thank you TRPM!!!


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Mon Jul 24, 2006 4:46 pm    Post subject:
Reply with quote

MS HIRES ROOTKIT SLEUTH
Microsoft Corp. has acquired Winternals Software LP, the company
co-founded by rootkit detective Mark Russinovich.
http://www.net-security.org/news.php?id=11758


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Fri Jul 28, 2006 8:14 pm    Post subject:
Reply with quote

Suicidal' malware threatens corporate secrets: Cybertrust

Munir Kotadia, ZDNet Australia
July 28, 2006
URL: http://www.zdnet.com.au/news/security/soa/_Suicidal_malware_threatens_corporate_secrets_Cybertrust/0,2000061744,39265027,00.htm


The latest threat to intellectual property comes in the shape of malicious software (malware) that is capable of infecting a computer, hiding itself until the user accesses specific files or Web sites -- in order to steal files or passwords -- and then deleting any trace of itself.

Speaking at the IT Security in Government Conference in Canberra on Friday, Brian Denehy, security assurance engineer at CyberTrust, told delegates that the vast majority of new malware uses "some type of stealth" or anti-forensic technology in an attempt to remain undetected before, during and after an attack.


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Fri Aug 04, 2006 5:09 am    Post subject:
Reply with quote

Some good info and links in this link.
Roootkit info and detection apps


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
plunx

Lieutenant
Lieutenant


Joined: Nov 01, 2005
Posts: 194
Location: Sweden

PostPosted: Wed Aug 16, 2006 1:02 pm    Post subject: Patch me up-Rootkit
Reply with quote

Hi

Maybe Off-topic....Very Happy

From F-secures weblog:

Australian band Root Kit - a favorite of ours - was the runner up in Gidol at GoogleIdol.com's Original Competition Demo. Root Kit received 4796 votes. Gidol, not affiliated with Google, holds online competitions using publicly available Google Videos.

If you have missed Root Kit's video "Patch Me Up", then you should definitely check it out at Google Video. Listen to the lyrics carefully; there's some sound security (and love life) advice in there.

http://www.f-secure.com/weblog/archives/archive-082006.html#00000949

Video.....
http://video.google.com/videoplay?docid=9151435244001559688

Cool

Back to top
View users profile Send private message
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2899

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Fri Aug 18, 2006 4:09 pm    Post subject: Detecting the Blue Pill Hypervisor rootkit is possible but n
Reply with quote

Greetings,

Detecting the Blue Pill Hypervisor rootkit is possible but not trivial

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17293

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Wed Aug 23, 2006 2:41 pm    Post subject:
Reply with quote

Just got this info from AplusWebMaster.

AplusWebMaster wrote:
FYI... something to add to the toolbag (more is better, yes?). Let me know how you make out with it:

- http://www.zdnet.com.au/news/security/print.htm?TYPE=story&AT=39267346-2000061744t-10000005c
August 23, 2006
"...Sophos on Wednesday unveiled a free tool* that can scan computers for suspicious processes..."

* http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html


Regards,


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17293

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Sep 19, 2006 7:07 pm    Post subject:
Reply with quote

Researchers discover 'invisible' rootkit
Will run on Vista too


http://www.pcadvisor.co.uk/news/index.cfm?newsid=6606


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
SimpleSum1

Corporal
Corporal


Joined: Sep 03, 2006
Posts: 65
Location: USA

PostPosted: Sun Sep 24, 2006 4:36 am    Post subject:
Reply with quote

They would commandeer a hidden section of a hard drive, zip up as many files as possible and immediately transmit the data to way stations in South Korea, Hong Kong or Taiwan before sending them to mainland China. They always made a silent escape, wiping their electronic fingerprints clean and leaving behind an almost undetectable beacon allowing them to re-enter the machine at will.

http://www.time.com/time/magazine/article/0,9171,1098961,00.html

This was the first article that lead me to learning about Rootkits. This was published last year, Sept. 5, 05.

(Copyright law allows me to excerpt any written published material for any purpose as long as it does not exceed 250 words in length and contains a reference to the author and or publisher. Does an html link constitute an acceptable reference?)

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17293

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sun Sep 24, 2006 8:11 am    Post subject:
Reply with quote

SimpleSum1 wrote:
Does an html link constitute an acceptable reference?


Yes, an HTML link is a valid reference online.

However, where did you get the idea that you can quote up to 250 words of a copyrighted work, without permission? Shocked

There's no provision for that in US copyright law. Please read the paragraph under #4 on this page (about Fair Use practices): http://www.copyright.gov/fls/fl102.html

My preference when referring to news articles is to state the title and provide the link. I may make comments about it in my own words. Permission is preferred when making any quotes from an article, but since this is for the purpose of both news and education, it may be considered fair use.

Note that normally we do not provide commentary such as this within the news topic thread, so if you wish to discuss this further, please open a topic in another forum such as: CastleCops Link/f1-General_Site.html

Thank you


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer