 main menuhome
forums Show me new threads!
bookmarks
post article
view blogs
vault you must be level 2 to upload files to your vault
downloads you must be logged to access downloads
Rootkit Collection
A news back-end to implement RootKit news into your website is here or more advanced version here.
An XML/RSS feed that includes both NEWS and BLOGS for RootKit is here: XML/RSS.
Beta feed for replied posts here. feedback to admins not forums, we know about times being off...
|
ROOTKIT
Because the OS isn't enough!
|
Saturday July 31st |
| | Featured Article: Nostalgia: n00bk1t, an advanced ring3 rootkit in C by jeffosz | Loading unsigned drivers on Vista By: noideaAtsiv is a tool we threw together to help the support the hobbyist community to and to provide support to legacy drivers on Windows Vista without rebooting with special boot options or denial of service. As I'm sure you are all aware, with Windows Vista, Microsoft have released a new DRM implementation that restricts system performance and limits use of the system in general. One of the best papers we have read on Vista and DRM is a paper by Peter Gutmann who lifts the lid on Vista's DRM implementation .http://www.cs.auckland.ac.nz/~pgut001/pubs/vista_cost.html. One of the restrictions under Vista is enforced driver signing. Driver signing doesn’t prevent malware, it just prohibits freedom to choose, which on a general purpose operating system is simply not acceptable. A signed file uniquely identifies the company that developed that file but when companies can be created and registered in jurisdictions known for protecting the privacy of company founders and directors you have to ask what does driver signing actually represent? Signed drivers can be signed by an arbitrary legally registered company. Absent any control over what the driver actually is or does, this provides no real additional security, other than removing author anonymity. So do the new Vista “features” improve system security or only impose limitations? While driver signing certificates can be revoked new certificates, with enough money, can be created faster than it takes to change a files signature. If this is indeed the case then it is the hobbyists and home user that end up paying the cost. We have released a free command-line tool for loading unsigned drivers on Windows 32 and 64 bit Vista without requiring the "/debug on" bcdedit boot-option. This isn’t the first PE loading tool but it’s the first one I’ve seen that uses a signed component to load an unsigned component. Enjoy http://www.linchpinlabs.com/resources/atsiv/usage-design.htm
. . . |
| |
ROOTKITS, Subverting the Windows Kernel
By: Greg Hoglund and Jamie Butler
Rootkits are powerful tools to compromise computer systems without detection. Get the original and best book on the subject here.
|
active for last 5 minutes
registered users:79912
There are currently 0 registered users and 21 guests browsing the website.
Welcome our latest registered user: Pris
| Jul 31, 12:06 |
| May 09, 04:30 |
| May 08, 15:33 |
| May 04, 15:42 |
| May 02, 03:59 |
| Best Screenshots / Analog |
| the most active news users |
based on the number of news posts for last 30 days
|