<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
	<channel>
		<title>www.rootkit.com</title>
		<link>http://www.rootkit.com/</link>
		<description>: www.rootkit.com News :</description>
		<language>en-us</language>
		<lastBuildDate>Sat, 31 Jul 2010 08:38:21 PDT</lastBuildDate>
		<generator>edge XML/RSS Feed for www.rootkit.com</generator> 
	<item>
		 <title>HVM- going into details</title>
		 <link>http://www.rootkit.com/newsread.php?newsid=1006</link>
		 <description><![CDATA[Part 1

This is my first article so I expect you not to be rigorous.

Of course all of us experience lots of problems and maybe stuck in something when we try to get deeper into anything new. So t...]]></description>
		 <category>:: worthy ::</category>
		 <pubDate>Tue, 09 Mar 2010 02:04:33 PST</pubDate>
		<guid>http://www.rootkit.com/newsread.php?newsid=1006</guid>
	</item>
	<item>
		 <title>Kernel Sockets Module based on TDI and WSK - updated</title>
		 <link>http://www.rootkit.com/newsread.php?newsid=1002</link>
		 <description><![CDATA[
/*
** This code is published under the GNU GENERAL PUBLIC LICENSE without any warranties.
*/
//***************************************************************************************************...]]></description>
		 <category>:: worthy ::</category>
		 <pubDate>Mon, 01 Mar 2010 14:26:42 PST</pubDate>
		<guid>http://www.rootkit.com/newsread.php?newsid=1002</guid>
	</item>
	<item>
		 <title>Nostalgia: n00bk1t, an advanced ring3 rootkit in C</title>
		 <link>http://www.rootkit.com/newsread.php?newsid=1000</link>
		 <description><![CDATA[I had this laying around for a few years now. Maybe someone finds it useful :)

n00bk1t
-------

0x01 About
----------

n00bk1t is a user-mode (ring3) rootkit. It is very similar to hxdef but ...]]></description>
		 <category>:: deep article ::</category>
		 <pubDate>Sat, 27 Feb 2010 11:41:34 PST</pubDate>
		<guid>http://www.rootkit.com/newsread.php?newsid=1000</guid>
	</item>
	<item>
		 <title>TDL3 - Why so serious? Let's put a smile on that face ..</title>
		 <link>http://www.rootkit.com/newsread.php?newsid=979</link>
		 <description><![CDATA[Abstract: 

TDL or TDSS family is a famous trojan variant for its effectiveness and active technical development. It contains couple compoments: a kernel-mode rootkit and user-mode DLLs which perfor...]]></description>
		 <category>:: deep article ::</category>
		 <pubDate>Mon, 09 Nov 2009 00:59:02 PST</pubDate>
		<guid>http://www.rootkit.com/newsread.php?newsid=979</guid>
	</item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 038: Breaking Prevx 3 self-protection]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1032</link>
                 <description><![CDATA[
I’m not considered Prevx as something interesting for years. Just because there is nothing interesting in hash sum calculations and huge advertising. Several days ago the sample fell into my hands. ...]]></description>
                 <category></category>
                 <pubDate>Sat, 31 Jul 2010 05:06:42 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1032</guid>
        </item>
  <item>
                
		<title><![CDATA[ghost1369's blog: started the book today]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1022</link>
                 <description><![CDATA[I will be using this blog to track my progress as i go through the rootkit manual : )
I found a copy of the rootkit book locally, bought it, and finally had a chance to start reading it. As a c / c++...]]></description>
                 <category></category>
                 <pubDate>Sat, 08 May 2010 21:30:41 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1022</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 037: The story of bucks]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1021</link>
                 <description><![CDATA[Few days ago were happened so-called “earthquake” for Windows security software. It is called KHOBE 8.0, published by matousec.com, you can read this article here
http://www.matousec.com/info/article...]]></description>
                 <category></category>
                 <pubDate>Sat, 08 May 2010 08:33:39 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1021</guid>
        </item>
  <item>
                
		<title><![CDATA[_4epen's blog: smpl func for making pages read-write on newest linux kernels]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1020</link>
                 <description><![CDATA[
<code>
/*
 * set_page_addr_rw()
 * turn page containing desired address to read-write
 *  address - desired address
 */
int set_page_addr_rw(unsigned long address)
{
   pgd_t *pgd;
   pmd_t...]]></description>
                 <category></category>
                 <pubDate>Tue, 04 May 2010 08:42:15 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1020</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 036: Rootkit Unhooker LE 3.8.388.590 SR2]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1019</link>
                 <description><![CDATA[build date 02.05.2010

for changelog see help file version history

Important:
Use random name for RKU installation directory for counteracting
sophisticated malware.

:WARNING:
May cause inc...]]></description>
                 <category></category>
                 <pubDate>Sat, 01 May 2010 20:59:04 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1019</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 035: The only one signatures way]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1018</link>
                 <description><![CDATA[Back to Dr.Web.

Since their total laziness almost 7 month after spidie 1.4 they didn't managed to close this backdoor and any others. Self-Protection is still used by stupid PR division as one of t...]]></description>
                 <category></category>
                 <pubDate>Sun, 25 Apr 2010 18:16:34 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1018</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 034: SpiDiE 2.1 at your service]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1010</link>
                 <description><![CDATA[Update of total fuckup of the Dr.Web Self-Protection, this time supporting newly released dwprot 6.0, spiderG3 and firewall :)))

::WARNING! RED ALERT!
Take care, when trying this Proof-of-Concept ...]]></description>
                 <category></category>
                 <pubDate>Wed, 24 Mar 2010 17:48:27 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1010</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 033: KernelMode.info new place for Ring0 explorations]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1007</link>
                 <description><![CDATA[
Author of RootRepeal - one of the best antirootkits - AD set up new forum which main goal will be:

Provide a place for people to discuss rootkits, debugging, reverse-engineering, malware analysis...]]></description>
                 <category></category>
                 <pubDate>Sun, 14 Mar 2010 08:03:44 PDT</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1007</guid>
        </item>
  <item>
                
		<title><![CDATA[lbs8901's blog: My RootKit Developer...]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1005</link>
                 <description><![CDATA[How Developer is RootKit]]></description>
                 <category></category>
                 <pubDate>Sun, 07 Mar 2010 06:49:15 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1005</guid>
        </item>
  <item>
                
		<title><![CDATA[lbs8901's blog: BsRootKit]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=1004</link>
                 <description><![CDATA[hi... bye.. Thanks...]]></description>
                 <category></category>
                 <pubDate>Sun, 07 Mar 2010 06:47:51 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=1004</guid>
        </item>
  <item>
                
		<title><![CDATA[hoglund's blog: HBGary is hiring RE's in 916]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=999</link>
                 <description><![CDATA[If you are in 916, or willing to reloc to 916, my company has posted two new rec's for reverse engineers.  The thing is, it has to be on site, no remote work.  If you have hacked games, or have cracke...]]></description>
                 <category></category>
                 <pubDate>Tue, 23 Feb 2010 20:25:45 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=999</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 032: Rootkit Unhooker LE 3.8.386.589 SR1 + Some Stuff]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=997</link>
                 <description><![CDATA[version 3.8 LE build 386/589 Service Release 1
build date 05.02.2010

for changelog see help file version history

Installer file hashes

MD5 for RkU3.8.386.589.exe
fac5a3c30788a90d6ffe5fce8ca...]]></description>
                 <category></category>
                 <pubDate>Fri, 05 Feb 2010 20:35:51 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=997</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 031: Rustock 2010]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=994</link>
                 <description><![CDATA[Rustock 2010

I wasn’t aware this rootkit series for almost one year. Because
everything was clean and game was over. New generation rootkit TDL series
now superseded everything else by technology...]]></description>
                 <category></category>
                 <pubDate>Mon, 25 Jan 2010 20:32:12 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=994</guid>
        </item>
  <item>
                
		<title><![CDATA[DiabloNova's blog: 030: Rootkit Unhooker LE 3.8.386.588 SR1]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=993</link>
                 <description><![CDATA[
version 3.8 LE build 386/588 Service Release 1
build date 12.01.2010

Greets to Dreg for helping with callgate detector! And sorry to be late with it release in RkU :) I was totally busy with TDL...]]></description>
                 <category></category>
                 <pubDate>Sat, 16 Jan 2010 20:19:35 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=993</guid>
        </item>
  <item>
                
		<title><![CDATA[Dreg's blog: Rootkit Arsenal, Installing a Call Gate]]></title>
		  <link>http://www.rootkit.com/blog.php?newsid=992</link>
                 <description><![CDATA[This is the translation of my spanish post published in blog.48bits.com: http://blog.48bits.com/2010/01/08/rootkit-arsenal-installing-a-call-gate/

Rootkit Arsenal, Installing a Call Gate

Hi, I w...]]></description>
                 <category></category>
                 <pubDate>Sat, 16 Jan 2010 07:56:37 PST</pubDate>
		<guid>http://www.rootkit.com/blog.php?newsid=992</guid>
        </item>
</channel></rss>