hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

bonarez
anyone seen the news on hxxp://www.rootkit.com ?

QUOTE
Showtime : *WORKING* CreateProcess in KernelMode!
By: valerino

I don't think this code needs any comment.
Say welcome to usermode calls in kernel land..... with this technique you can even call MessageBox from inside your driver.
No more ugly non-working phrack samples, this is the real stuff smile.gif


Code is published on their site, since so many ppl are interested in kernel dev lately, this will certainly be interesting to someone..

bonarez
B3T4
the people who are interrested in this kind of code are already on rootkit.. no need to confront them kiddies with it. They only ask how to compile stuff ph34r.gif
tibbar
it's a very interesting development, valerino did very well to achieve this.

createprocess was easy to do in kernel anyway, i think more importantly is the ability to use any userland api.

that said, im sure we will see the driver startup method appearing in a few lame trojans soon
bonarez
QUOTE(B3T4 @ Feb 17 2005, 06:03 PM)
the people who are interrested in this kind of code are already on rootkit.. no need to confront them kiddies with it. They only ask how to compile stuff ph34r.gif
*



guess it was not really called for here, would have preferred irc, but cant seem to find any gso channel (looked on freequest)

bonarez
B3T4
This is MUCH more then just a startup methode! There is no need for a standard .exe anymore. U could become insanely stealth because everything now can run in kernelland. This, in combination with IFS would kick so hard ass!

Whoei, i gotta run...gotta do coding...ow no wait, im already in place laugh.gif

ps. irc.governmentsecurity.org (6667) , #gso-chat is the gso hangout on irc
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.