Wednesday, February 8, 2012
Linux, Security, Rants and Raves

Categories


 

January 2008
S M T W T F S
« Dec   Feb »
 12345
6789101112
13141516171819
20212223242526
2728293031  

Archives


Boot Record Rootkit Threatens Vista, XP, NT

January 8th, 2008 by Baldy

Paul sends us word on a new exploit seen in the wild that attacks Windows systems completely outside of the control of the OS. “Unfortunately, all the Windows NT family (including Vista) still have the same security flaw — MBR [Master Boot Record] can be modified from usermode. Nevertheless, MS blocked write-access to disk sectors from userland code on VISTA after the pagefile attack, however, the first sectors of disk are still unprotected… At the end of 2007 stealth MBR rootkit was discovered by MR Team members (thanks to Tammy & MJ) and it looks like this way of affecting NT systems could be more common in near future if MBR stays unprotected.”

Posted in Security | No Comments »