Dailydave mailing list archives

Rootkit Detection - No Worries


From: "Gage" <12gage () comcast net>
Date: Sun, 19 Jun 2005 21:05:01 -0400

For the Microsoft OS world:

 

More news worthy information, that BBX's ImmuneEngine detects and stops
kernel rootkits immediately, because of the binary search engine and the
inability to execute unauthorized installation through the BBX secure shell.

   
Microsoft doesn't even have confidence in their own developed tool to get
rid of Kernel Rootkits.  Take note of the last paragraph of the article
below.
 
Microsoft warns of future security danger

Kernel Rootkits could be the next bad thing

By Nick Farrell: Friday 18 February 2005, 08:25
A HITHERTO OBSCURE security expert and software colossus, based in Redmond
and called Microsoft has warned of a new generation of spyware that is
almost impossible to detect.

According to Computerworld, Volish experts told the RSA security
conference
that system monitoring programs, or "kernel rootkits", are undergoing a
transformation at the moment.

Mike Danseglio and Kurt Dillard, both of Microsoft's Security Solutions
Group said that the malicious snooping programs are becoming more common
and
could soon be used to create a new generation of mass-distributed spyware
and worms.

Rootkits run quietly in the background and can be spotted by looking for
memory processes that are running on the infected system.

However, kernel rootkits, which modify the kernel, or core request
processing, component of an operating system, are becoming more common,
Vole
says.

Newer rootkits can intercept system calls that are passed to the kernel
and
filter out queries generated by the software. This makes them invisible to
administrators and to detection tools, says Danseglio.

Microsoft researchers have developed a tool, named "Strider Ghostbuster"
that can detect rootkits by comparing clean and suspect versions of
Windows
and looking for differences.

However the paper admits that the only way to be sure that you have killed
a
kernel rootkit is to completely erase an infected hard drive and reinstall
the operating system from scratch.


Article found here..  <http://theinquirer.net/?article=21326>
http://theinquirer.net/?article=21326

 

Gage

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: