Forums: Rootkits: The Ultimate Stealth Attack - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Rootkits: The Ultimate Stealth Attack

#1 User is offline   jead99 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 179
  • Joined: 13-January 04

Posted 02 May 2005 - 03:53 AM

Ever hear of a rootkit? It's a surreptitious program that is specifically designed to conceal its presence on your system, most likely toward some malicious end.

How does a rootkit evade detection? The answer is that it makes the operating system lie by intercepting calls to the system and modifying the results they send to programs. For example, when you are running a programlike Microsoft Windows Explorerthat displays the contents of a directory, that program is making calls to the operating system to retrieve the names of files in the directory. What if a program, running at a sufficiently low level, intercepted those calls, waiting and watching for the names of its own files so it could keep them out of the listing? It could even modify the total number of bytes the directory seems to use. And once it had accomplished its goal, it could go about its business, whatever that might be.

That is how rootkits work. For years, they were primarily aimed at UNIX systems. Now they're targeting Windows systems more frequently and, as with other malware, there's every reason to think that this will be where the action is from now on.

Rootkits have the potential to cause a lot of damage. Not only can they conceal their own files, they can also hide malware, such as viruses and spyware, written to work with them. The particularly scary thing about rootkits is that they're virtually invisible to users. Worse, they're invisible to traditional anti-virus programs, and easy-to-use tools for discovering their presence haven't been available.

Before you decide to turn your system off for good, however, remember that for a rootkit to run, it needs to find its way onto your system and then be executed. If you're not already being infected by viruses and Trojan horses all the time, you probably already have the sort of measures in place that would block most attempts to place a rootkit on your system.

On the other hand, it wouldn't do to be too complacent: Rootkits are growing ever more sophisticated and, once a rootkit is installed with sufficient rights on a trusted system, it can become a vector to compromise anything else on the network. Until now, detecting the presence of rootkits has been a labor-intensive task that required extensive low-level system knowledge. Luckily, new tools that ease the task of uncovering rootkits have recently been released.

These tools don't look for specific rootkits in the way that antivirus software looks for specific patterns of data to identify particular viruses. Instead, the tools scan a system for clues to the existence of rootkits.

Microsoft Research recently announced Strider GhostBuster ( http://research.microsoft.com/rootkit/ ), which works by listing all the files on the system while it's running, then listing the contents of the same drives using a different operating system, and comparing the results. Files that show up only in the second copy, known as the "offline" listing, are suspicious.

Other vendors have also come out with tools to detect rootkits. Sysinternals has one (www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml ) called RootkitRevealer, and F-Secure has a beta tool called BlackLight ( www.f-secure.com/blacklight). Both work at a very low system level to attempt to get to a point where they can detect the rootkit before it can intercept the operating-system functions.

Rootkits inspire fear, and some of that fear is justified. These tools, all free at least for now, are a welcome addition to our security arsenals.

Larry Seltzer
http://www.pcmag.com...,1790572,00.asp
0

#2 User is offline   Pro21 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 230
  • Joined: 12-February 04

Posted 02 May 2005 - 07:11 PM

Buy Hxdef Gold rootkit ^^ it seems very powerful. There is a demonstration video on the official site, it s very nice. But it s true that is becoming very difficult to hide files or services under a Windows operating system :)

And the microsoft GhostBuster is not really new. it exists already technics like that but it s true that is not very knew by m$ administrators :)
0

#3 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 02 May 2005 - 07:15 PM

I think when a rootkit gets ring-0 access, it can hide itself from ALL system surveillance programs, thus making the kit undetectable... So a program like Strider GhostBuster could be fooled by rootkits...
Or did I understang wrong?
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#4 User is offline   White Scorpion 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 674
  • Joined: 05-September 04

Posted 02 May 2005 - 09:49 PM

Quote

I think when a rootkit gets ring-0 access, it can hide itself from ALL system surveillance programs, thus making the kit undetectable... So a program like Strider GhostBuster could be fooled by rootkits...
Or did I understang wrong?
basically you are right. everything that can be detected can be hidden as well. But rootkit revealers always walk one step behind since rootkit writers are always thinking about new ways to hide their stuff from the system and the revealers have to participate on that... read the topics on rootkit.com for more infob about rootkits.
The path of access leads to the server of wisdom..

The Syringe - My Latest Project.
Errors, Vulnerabilities & Exploits explained.
----
www.white-scorpion.nl
www.info-sec.eu
www.info-sec.info
0

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting