REGISTER
desert eagle
main menu

home

forums
    Show me new threads!

bookmarks

post article

view blogs

vault

you must be level 2 to upload files to your vault

downloads

you must be logged to access downloads

Rootkit Collection

File Contributer Link
Hacker Def... hfn/a
HE4Hook adminn/a
BASIC CLAS... hoglundn/a
Vanquish xshadown/a
NT Rootkit hoglundn/a
FU fuzen_opn/a
WinlogonHi... JeFFOsZn/a
klister joannan/a
Patchfinde... joannan/a
MyNetwork hoglundn/a
MTDWin hoglundn/a
NTFSHider hoglundn/a
VideoCardK... hoglundn/a
VICE fuzen_opn/a
Klog Clandestin...n/a
NtIllusion Kdmn/a
AFX Rootki... TheRealAph...n/a
SInAR vulndevn/a
Shadow Wal... Clandestin...n/a
BootRootki... dereksoede...n/a
CHAZ - Nim... neocrackrn/a
Clandestin... merlvingia...n/a
FUTo petersilbe...n/a
Windows Me... alcapone66...n/a
RAIDE petersilbe...n/a
BOOT KIT vipinkumarn/a
BluePill Joanna and...n/a
DEFRAG blume1975n/a
Keyboard H... chpien/a
CheatEngin... DarkByten/a

search the site

backends
A news back-end to implement RootKit news into your website is here or more advanced version here.

An XML/RSS feed that includes both NEWS and BLOGS for RootKit is here: XML/RSS.

[Valid RSS]

Beta feed for replied posts here. feedback to admins not forums, we know about times being off...

ROOTKIT
Keep it stealth and keep it alive
Saturday July 31st
Featured Article: Nostalgia: n00bk1t, an advanced ring3 rootkit in C    by jeffosz
KEEPING BLIZZARD HONEST - Announcing the release of 'The Governor'

The Governor sniffs Warden activity

By: hoglund

Blizzard, a subsidary of Vivendi, builds and markets the popular computer game known as World of Warcraft, which claims more than 4.5 million players worldwide. Unknown to most players is the fact that World of Warcraft includes an embedded spyware(ref: is warden spyware?) program which indiscriminantly reads data from all open windows and processes on the users computer. The purpose of the warden is to verify compliance with the EULA and TOS. While many welcome the warden as a means to catch cheaters who use 3rd party 'botting' programs, many others may find this a violation of privacy.

The fact is that the warden client reads information from other processes on the computer. Regardless of the reasons, this technically counts as 'spying' on a user. So, reasons aside, the term 'spyware' is fitting.

Rather than debate the morality of this behavior, I would like to give the consumers the power to make this decision for themselves. I am releasing a program called 'The Governor'. The Governor is very simple - it watches the activities of World of Warcraft, and clearly reports which data is being read from other processes. The Governor makes no attempt to subvert or alter the behavior of the warden client, or World of Warcraft. The Governor will not assist you in cheating. The Governor exists for one reason, to tell you the truth.

Here is the governor, released with FULL SOURCE. There are no secrets or tricks. See the warden in action for yourself:

http://www.rootkit.com/vault/hoglund/Governor.rar

and, as a ZIP file,

http://www.rootkit.com/vault/hoglund/Governor.zip

In the screenshot, you can see World of Warcraft reading memory from the processes running on my computer.

Absolutely no reverse engineering is required to make the Governor work. The Governor monitors fully documented API calls which are offered by the Microsoft Windows operating system. To monitor these API calls, the Governor uses a documented library called 'Detours', which is available from Microsoft.

Will Blizzard ban me if I use The Governor?

I have personally been running The Governor on a test account and there have been no problems. The Governor does not modify the behavior of WoW.EXE or the warden. The Governor is not designed to assist cheaters, and offers no mechanism to help cheaters hide their programs.

But, that being said, Blizzard can choose to ban you for using a 3rd party program. The Governor is a 3rd party program. While the Governor poses absolutely no threat from a cheating aspect, it does expose the behavior of their warden client. In my opinion, banning people for seeking the truth about warden would sink Blizzard to a new all-time low. But, this isn't my decision. I cannot guarantee you won't be banned.

AN OPEN MESSAGE TO BLIZZARD
Blizzard, it is within your right to attempt to make your computer game that way you wish it to be, and to attempt to catch cheaters. But, reading the memory of other processes and windows that are not part of the World of Warcraft game client is a violation of privacy. Making a violation of privacy legal in your EULA and TOS does not make it also moral. It remains a violation of privacy. Please refactor your policy in regards to scanning memory, and limit the warden to integrity checking of the game client's memory space, and please stop opening other processes and reading windows that do not belong to you.

-Greg Hoglund

read comments (64) / write comment

recent comments:
You cannot see violation?nobody11109.Jan:00:59
How many possible hashesLexie15.Nov:09:48
Blowing 'The Warden' out of proportion.zel04.Nov:15:45
Blowing 'The Warden' out of proportion.zel04.Nov:15:43
procedure entry point not locatedserendipity02.Nov:09:26
. . .

printer-friendly version

login:
password:

ROOTKITS, Subverting the Windows Kernel
By: Greg Hoglund and Jamie Butler

Rootkits are powerful tools to compromise computer systems without detection. Get the original and best book on the subject here.


logged users

active for last 5 minutes

registered users:79912

There are currently 0 registered users and 20 guests browsing the website.

Welcome our latest registered user: Pris

recent board posts
subject author date
Hiding Tcp... _MAX_ Jul / 27
unload dri... dubteam2000 Jul / 26
APC Delive... aall87 Jul / 21
x64 SSDT h... lolwurst Jul / 21
password r... markedu9 Jul / 19
How to hid... Hack4freedom Jul / 15
UNC PATH A... pain_abator Jul / 15
CALL in na... _MAX_ Jul / 13
Conflict b... _MAX_ Jul / 08
Making dev... blackd0t Jul / 06
Hide proce... l0ngshot Jul / 01
Process Ha... krzys Jul / 01
Rooting VP... simplicityx Jun / 24
Rootkits: ... chimai Jun / 24
NDIS Inter... lclee_vx Jun / 17

recently replied posts
subject author date
x64 SSDT h... vrtulex Jul/27
unload dri... EreTIk Jul/27
Hiding Tcp... _MAX_ Jul/27
BIOS Rootk... rossettoecioccolato Jul/25
about this... DiabloNova Jul/22
APC Delive... aall87 Jul/21
password r... markedu9 Jul/19
UNC PATH A... pain_abator Jul/19
How to hid... vrtulex Jul/16
CALL in na... _MAX_ Jul/16
Hide proce... vrtulex Jul/10
Conflict b... _MAX_ Jul/08
Making dev... blackd0t Jul/07

recent blog entries
DiabloNova Jul 31, 12:06
ghost1369 May 09, 04:30
DiabloNova May 08, 15:33
_4epen May 04, 15:42
DiabloNova May 02, 03:59
Best Screenshots / Analog
May 14, 2010

dep.png /

click on the picture to enlarge and see description

!

read comments (0)
write comment

view archive(90) :

Analog(53) / Best Screenshots(37)

submit a picture to gallery

the most active news users
based on the number of news posts for last 30 days

user nr. of posted news

select skin



As a computer, I find your faith in technology amusing.