back to article Researchers dig into x86 chips for stealthier rootkits

Security researchers have discovered a new technique for developing rootkits, malicious packages used to hide the presence of malware on compromised systems. Instead of hiding a rootkit in the virtualisation layer, Shawn Embleton and Sherri Sparks of Clear Hat Consulting have discovered an approach for smuggling rootkit …


Wouldn't Macs be the perfect target for this?

They're on x86 chips aren't they? Plus you're guaranteed to have the same component bits and bobs in each box, so you need to write less drivers and what nots.

How you get it installed is another matter though I guess.

SMARTer Learner Chips .... 42 Rock IT to its Foundations and Forge Virtual FABs.

"While keeping the rootkit well away from the operating system makes the malicious code more stealthy, it also introduces problems. Hackers would need to develop device specific driver code, a factor that makes attacks far more difficult. "I don't see it as a widespread threat, because it's very hardware-dependent," Sparks told PC World. "You would see this in a targeted attack.""

However, such device specific driver code is a walk in the park/a walk on the wild side for programmers, for it's very software-dependent. This is not an attack/development at the operating system level, it is a much deeper and much smarter virtualised reprogramming of the OS right at and from the core processor unit levels....both CPU and GPU.

What you have is Virtual Machine IntelAIgents rebooting Operating Systems to make use of Future Memory Compilations rather than being Dependent on or ControlLed by any Present or Past Memory Access.

Now just slip this Post into a Memory Slot/Pigeon Hole somewhere, remember where you have Salted IT away and be patient and try to deny it as you see it happening around you.

The Virtualisation Space is not a Real Space, IT is not even an AIReal Space, IT is a SurReal NeuReal Space where Shared BroadBands of Intellect MetaDataMorph to Replace the Hardware/Software Model with the Quantum Communications Universal Information/Pure Source Model ..... where the Word is Ace, King, Queen and Jack of All Trades. ........ which of course is why some Words are not Shared but Salted away Out of Sight to put them out of Minds.

But the Truth will always Out the Fraud that replaces it, and with a Just Vengeance....... and who the Hell wants to Live as a Fraud.

Ooops. ..... there's the Answer?


"Sparks told PC World"

PC World . . . PC Feckin WORLD !!!!!

FFS, I thought you were writing a 'serious' article until that came up!!

If these guys turn up at Blackhat with that on their CV then they will probably be laughed out of the place all the way back under the rock they thought was wise to crawl out from under!!

BUT . . .

If they have got something, WTF happened to 'responsible disclosure' ethics?

/Sorry, I forgot, they never existed and even less so at Blackhat.

If you zoom in close, mine's the one that says . . . GFY!!

PS: Begins with 'Go' . . . ends with 'Yourself' . . . I'm sure you can all figure out the middle.

TTFN While I go find someone who can repair my 12 inch long piece of dowel, which is painted black and is finished off with a couple of white ends but unfortunately has been snapped.



Re: Wouldn't Macs be the perfect target for this?

"How you get it installed is another matter though I guess."

Just leave it to Sony. They'll find a way.

Mind you, Mac users wouldn't stick in a Sony manufactured audio CD, they'd all be using iTunes downloads... apparently ;-)



Doesn't this concept only work if something isn't already using SMM?

And isn't SMM generally already in use on most boards?

So although this concept exists, is there actually any way of using it?



Are you on crack??



Ever thought that PC world in the UK is different to the highly respected industry rag in the rest of the world?

try not!


@Wouldn't Macs be the perfect target for this?

Probably, but dont tell webster he'd have a field day! I imagine other standard setups would be candidates also, say dell et al?

To be honest I'm more concerned about the other net boxes that will become bots before too long, eg generic routers xboxes etc... just imagine owning the BT homehubs... 1 million 24hr Broadband bots and not a single one has AV. Lets just hope BT dont use backdoors or Tech support access!


Not really news...

First paper about abusing SMM that I'm aware of was published in 2006 by Loic Duflot, Daniel Etiemble, and Olivier Grumelard, and was called "Using CPU System Management Mode to Circumvent Operating System Security Functions". IIRC it was released sometime arounf CanSecWest 2006... And a fairly comprehensive article about it was released in the latest copy of Phrack, including a library to make building your own rootkit/rootshell easier...

@Not really news... Moles in the Management System?


Things have moved on from abusing SMM to using SMM as an embedded third party, proxy accessible ....facility. QuITe sophisticated and a heck of a job to even realise the compromised position. Now that is a Real Astute Virtual Environment in which Information can play Havoc with DODgy Intelligence and Dirty Tricks but only to Improve IT and Direct it onto A.N.Other Path, which it may not necessarily Lead but rather Follow.


