![]() |
Unreal: Rootkit Detectors / Bypassing |
Post Reply
|
Page 123 22> |
| Author | |
fl3a
Groupie
Joined: 12 October 2006 Online Status: Offline Posts: 82 |
Post Options
Quote Reply
Topic: Unreal: Rootkit Detectors / BypassingPosted: 09 November 2008 at 3:22pm |
|
Metatron did you see last article posted on rootkit.com. I suppose there is described the method you used to hide SSDT modifications...
|
|
![]() |
|
USForce
Senior Member
Joined: 26 October 2007 Location: United States Online Status: Offline Posts: 150 |
Post Options
Quote Reply
Posted: 08 November 2008 at 5:36pm |
100% agree |
|
![]() |
|
thug4lif3
Groupie
Joined: 05 August 2008 Location: Vietnam Online Status: Offline Posts: 62 |
Post Options
Quote Reply
Posted: 08 November 2008 at 5:07pm |
|
well, IMHO the game is only 100% fair in two cases:
- private rks vs. private detectors. - public rks vs. public detectors. As long as the rk stays private, it can be a phantom to most of arks. |
|
|
stay hungry, stay foolish.
CodeWalker AntiRootkit: http://cmcinfosec.com/download/cmcark_cw0.2.4.500.rar |
|
![]() |
|
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Posted: 07 November 2008 at 1:04pm |
|
|
|
Concentrate on your strengths.
|
|
![]() |
|
USForce
Senior Member
Joined: 26 October 2007 Location: United States Online Status: Offline Posts: 150 |
Post Options
Quote Reply
Posted: 07 November 2008 at 12:31pm |
Why don't you publish your rk? ![]() Edited by USForce - 07 November 2008 at 12:31pm |
|
![]() |
|
fl3a
Groupie
Joined: 12 October 2006 Online Status: Offline Posts: 82 |
Post Options
Quote Reply
Posted: 07 November 2008 at 11:23am |
|
OK. Now all is clear. Tool I was talking about isn't complete ARK. It is only user Process/Thread detector - nothing special. Edited by fl3a - 07 November 2008 at 11:24am |
|
![]() |
|
Metraton
Newbie
Joined: 14 October 2008 Location: Italy Online Status: Offline Posts: 15 |
Post Options
Quote Reply
Posted: 07 November 2008 at 11:13am |
|
@fl3a:
" thought that you are hiding user process what is extremely difficult and stupid (practiced by malware)"
I used this technique only in the first version, but rightly as you say is a obsolete technique
"it should include a thread object (should hide), doesn't it?"
yes, it is...
What kind of hidden objects can see your ark? (Process, Drivers, SSDT, Stealth Code, Code Hooks...etc.etc.) |
|
|
A. Einstein: "Tutti sanno che una cosa é impossibile da realizzare, finché arriva uno sprovveduto che non lo sa e la inventa"
|
|
![]() |
|
fl3a
Groupie
Joined: 12 October 2006 Online Status: Offline Posts: 82 |
Post Options
Quote Reply
Posted: 07 November 2008 at 10:48am |
|
But even if it doesn't include a process object (doesn't hide it) it should include a thread object (should hide), doesn't it? I thought that you are hiding user process what is extremely difficult and stupid (practiced by malware)... |
|
![]() |
|
Metraton
Newbie
Joined: 14 October 2008 Location: Italy Online Status: Offline Posts: 15 |
Post Options
Quote Reply
Posted: 07 November 2008 at 10:24am |
|
@SystemPro:
"Okay, but you could create private builds that only work on computers with a special id.
The other possibility are nags to disable the chance of malicious use." Wow...you are worst of St. Thomas
@USForce:
Why not publish your ark?
@fl3a:
My POC does not include a process (Unreal docet), then do not hide |
|
|
A. Einstein: "Tutti sanno che una cosa é impossibile da realizzare, finché arriva uno sprovveduto che non lo sa e la inventa"
|
|
![]() |
|
fl3a
Groupie
Joined: 12 October 2006 Online Status: Offline Posts: 82 |
Post Options
Quote Reply
Posted: 07 November 2008 at 10:11am |
|
I have PRIVATE RK detector also, which probably is able to detect Metatron's RK (Process). And probably not only we have own private detectors which are able to detect Metatron's RK, but I think Metatron's goal was to show everyone that all public ARKs are defeated (only) and that's all...
|
|
![]() |
|
Post Reply
|
Page 123 22> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |