Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Tool Roots Out Virtualized Rootkits

Black Hat researchers to release virtualized rootkit detector

Aug 01, 2007 | 09:24 AM

By Kelly Jackson Higgins
DarkReading

LAS VEGAS -- Black Hat -- The researchers who publicly challenged Joanna Rutkowska to prove her virtualization-based rootkit is undetectable today said they are ready to release a tool that can detect her stealth virtual machine code. (See Hacker Smackdown.)

Thomas Ptacek, co-founder and researcher with Matasano Security; Nate Lawson, researcher at Root Labs; and Peter Ferrie, senior researcher at Symantec, demonstrated how their Samsara rootkit detection platform and testbed would shatter Rutkowksa's claims that there's no way to detect her VM code, called Blue Pill.

In a session called "Don't Tell Joanna, The Virtualized Rootkit Is Dead," the researchers argued that virtualized rootkits will always be a cat-and-mouse chase. They argue that virtualized rootkits leave a trail, and the malware would have to be bug-free to really emulate a system.

"Nothing is 100 percent undetectable," Lawson says. "We found a way to detect all rootkits out there."

But Rutkowska, who attended the session here today and is scheduled to present her latest virtualized rootkit research this afternoon with colleague Alexander Tereshkin, said afterward that their presentation didn't sway her position about Blue Pill's stealthiness.

Ptacek, Lawson, and Ferrie recently issued a challenge to Rutkowska, founder of Invisible Things Lab, to prove her claims by letting them use their tool to find Blue Pill in one of two laptops, one that was infected and the other that was clean. Rutkowska countered their contest rules by saying that more work needed to be done to make her code "commercial grade," and the contest never got off the ground. "Our challenge probably wasn't fair... It was on such short notice," Ptacek said in the presentation. "But we think this [tool] would work against her."

The tool will be released in binary format, and won't be "weaponizable," so it wouldn't be much use to an attacker, they said. It runs only on the MacBook based on Intel Core Duo Version 10.4.

Lawson says the researchers hope others will take the code and build on it for future testing and research. Samsara comes with a virtualized rootkit testbed component as well.

"It's hard to prove you're undetectable if you don't have an adversary. We're trying to provide you with that [adversary]," Ptacek says.

Still, the researchers admit this type of rootkit isn't a real threat today. "We've seen three VT-type rootkits, and none are in the wild infecting systems," Lawson says.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • Matasano Security LLC
  • Symantec Corp. (Nasdaq: SYMC)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)