Your Ad Here

May 11, 2008

Hiding a Rootkit In System Management Mode

Sniper223 notes a PC World article on a new kind of rootkit recently developed by researchers, which will be demoed at Black Hat in August. The rootkit runs in System Management Mode, a longtime feature of x86 architecture that allows for code to run in a locked part of memory. It is said to be harder to detect, potentially, than VM-based rootkits. The article notes that the technique is unlikely to lead to widespread expoitation: "Being divorced from the operating system makes the SMM rootkit stealthy, but it also means that hackers have to write this driver code expressly for the system they are attacking."

Read more of this story at Slashdot.

Leave a Reply

Helpful Links:

Internal Links:

categories:

search blog:

other:

Blogroll

archives:

May 2008
M T W T F S S
« Apr   Jun »
 1234
567891011
12131415161718
19202122232425
262728293031  

Recent Posts:

Stay Up-To-Date With Posts

eXTReMe Tracker

33 queries. 0.750 seconds