PC Review


Reply
Thread Tools Rate Thread

Blue Pill: a rootkit using virtualization technology

 
 
YKhan
Guest
Posts: n/a
 
      30th Jun 2006
I was wondering when this was going to happen. A researcher has come up
with a proof-of-concept rootkit, which depends on Pacifica
virtualization technology to bypass the operating system. I'm sure this
can also be done using Vanderpool virtualization. It was bound to
happen, a virtualization hypervisor is a super-OS, higher than the OS
itself. The OS runs as an application under the Hypervisor. It's
interesting why the researcher chose to do it under Pacifica rather
than Vanderpool? Perhaps Pacifica made her job easier to create the
hypervisor?

BTW, I think the term "Blue Pill" refers to the Matrix movies, where
Morpheus offers Neo either a red pill or a blue pill. The red pill
opened up the truth, while the blue pill kept the truth hidden.

Slashdot | Undetectable Rootkits Through Virtualization?
http://it.slashdot.org/article.pl?sid=06/06/29/2111208

Here's the main story:

Blue Pill A Threat To Vista x64
http://www.securitypronews.com/news/...oVistax64.html


Yousuf Khan

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
"Blue Pill" Malware Mark D. VandenBerg Windows Vista Security 19 13th Jul 2006 02:06 AM
"Blue Pill" Malware Mark D. VandenBerg Windows Vista General Discussion 19 13th Jul 2006 02:06 AM
Mark's Latest Blog - More RootKit technology in play R. McCarty Windows XP General 1 8th Feb 2006 03:53 AM
AMD Pacifica virtualization technology specs released YKhan Processors 1 26th May 2005 01:03 PM
New rootkit detection technology Ian JP Kenefick Anti-Virus 8 11th Mar 2005 06:33 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:07 PM.