Re: Sony: The Return Of The Rootkit



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Quark IT - Hilton Travis schrieb:
Hi All,

Apparently Sony cannot learn from their past and have introduced another
rootkit with another of their devices. This time it is their Microvault
USB drive that has fingerprint security.

That is not exactly new news.

The devices are old and all that is "rootkit-like" about them is the
fact that they interact with the kernel in order to hide their own files
from corruption.

Not everything that interacts with the kernel is a rootkit. Or would
anyone want to classify GRSecurity as a rootkit? RBAC will let you hide
parts of your filesystem as well...

Have a read of

Have another one:
http://observed.de/?entnum=101

Now I was outraged by Sony's Copyprotection Rootkit - but this is simply
something different.

Many Greetings
Paul

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG1uvsaHrXRd80sY8RCvegAJ9C8GDeUIi5maRExcLnjdV4w3pCLACg8iDU
pM7XA3bdpQ81EMytNaMBre0=
=yk5I
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Registration Weakness in Linux Kernels Binary formats
    ... On Tuesday 03 October 2006 23:08, Julio Auto wrote: ... The observation is in fact something that can be used by rootkit ... writers or developers of other forms of malware. ... being able to insert an arbitrary kernel module into the running kernel. ...
    (Linux-Kernel)
  • Re: Rootkit???? Have tried everything...literally...
    ... remove a rootkit - only detect them. ... and hooking a function call from the kernel to the hardware....the site has ... > | Please see quote below from Microsoft Research Strider Rootkit Project ... > | not provide query/enumeration APIs or does not provide ...
    (microsoft.public.security.virus)
  • Re: Rootkit
    ... I know Windows from about XP have a kernel but it really ... No where could I find mention of a Linux rootkit. ... That's why it's a good idea to install chkrootkit. ...
    (Fedora)
  • Re: [Full-disclosure] one of my servers has been compromized
    ... Say the kernel has a rootkit and is ... connections, how do you find out what those connections are and what ... For instance say you got a guy with a userland rootkit. ... Also not everything has to be done in userland to get done. ...
    (Full-Disclosure)
  • Re: New rootkit detection technology
    ... In many sources root kits are counted ... A rootkit may also include utilities to help the attacker subsequently ... Rootkits come in two different flavours, kernel and application level ... detecting Ring 0 (kernel level) rogue processes is taskinfo, ...
    (microsoft.public.security.virus)