Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

'Blue Pill' Prototype Creates 100% Undetectable Malware
PC Magazine (excerpt) ^ | June 28, 2006 | Ryan Naraine

Posted on 06/28/2006 7:35:03 PM PDT by HAL9000

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-33 last
To: Swordmaker
Joanna Rutkowska, a stealth malware researcher at Singapore-based IT security firm COSEINC, says the new Blue Pill concept uses AMD's SVM/Pacifica virtualization technology...

I think that Rutkowska may be referring to Linux and BSD running on AMD chips. Unless Intel is using this AMD virtualization technology it appears that Macs may escape.

21 posted on 06/28/2006 9:57:14 PM PDT by John Valentine
[ Post Reply | Private Reply | To 18 | View Replies]

To: John Valentine
I think that Rutkowska may be referring to Linux and BSD running on AMD chips. Unless Intel is using this AMD virtualization technology it appears that Macs may escape.

That's why the PING! said "...could..." The new Intel Core processors also have a virtualization layer... it may just be time or secrecy that keeps us from knowing about a rootkit that will work on it.

22 posted on 06/28/2006 10:10:22 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 21 | View Replies]

To: Swordmaker

Love my G4 Mac(s) even more now.


23 posted on 06/29/2006 12:07:56 AM PDT by mhx
[ Post Reply | Private Reply | To 18 | View Replies]

To: Perdogg

Without a virus, there'd be no need to buy an antivirus.
Sounds like a perfect self-perpetuating business plan to me......:]


24 posted on 06/29/2006 3:23:15 AM PDT by Salamander (And don't forget my Dog; fixed and consequent)
[ Post Reply | Private Reply | To 4 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

25 posted on 06/29/2006 5:36:47 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Theo

but at least it doesn't take up so much HD space like the old stupid-fat and bloated subhypervisors.

if women would just start having sex with these virus writing geeks all this crap would come to a grinding stop.


26 posted on 06/29/2006 6:01:02 AM PDT by postaldave (McCain & Bush, you traitorous !#!$!!s. you two are no different then ted kennedy.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: HAL9000

Damn scary stuff. I believe I had a run in with something similar last year.

I won in the end, but it was a tough fight.


27 posted on 06/29/2006 6:19:33 AM PDT by KoRn
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
" FreeBSD (OS X) could be vulnerable"

I don't think so. Apparently, this relies on AMD processors. Even if Intel adds this kind of virtualization technology to their processors, this particular exploit probably wouldn't work.
28 posted on 06/29/2006 6:20:16 AM PDT by DesScorp
[ Post Reply | Private Reply | To 18 | View Replies]

To: HAL9000

Sounds to me like a hardware based back door. Shame on AMD.


29 posted on 06/29/2006 6:23:40 AM PDT by beef (Who Killed Kennewick Man?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Theo
"You got a problem with my ultra-thin hypervisor, punk??"


30 posted on 06/29/2006 8:38:11 AM PDT by Turbopilot (iumop ap!sdn w,I 'aw dlaH)
[ Post Reply | Private Reply | To 14 | View Replies]

To: InMemoriam
If this is stored on the hard drive, boot from a CD, and find it sitting unexecuted on the hard drive.

A *really* good one should first try to write extra instructions to the firmware in your PC, to thwart this sort of detection later.
31 posted on 06/29/2006 8:45:15 AM PDT by beezdotcom
[ Post Reply | Private Reply | To 6 | View Replies]

To: beezdotcom
A *really* good bad one should first try to write extra instructions to the firmware in your PC, to thwart this sort of detection later.

There, fixed it for you.

32 posted on 06/29/2006 9:40:47 AM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!")
[ Post Reply | Private Reply | To 31 | View Replies]

To: postaldave

"if women would just start having sex with these virus writing geeks all this crap would come to a grinding stop."

ROTF!!


33 posted on 06/29/2006 10:45:07 AM PDT by rzeznikj at stout (ASCII and ye shall receive... (Computers 3:14))
[ Post Reply | Private Reply | To 26 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-33 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson