Welcome Guest ( Log In | Register )



2 Pages V   1 2 >  
Reply to this topicStart new topic
> Invisible Malware, The blue pill
pyost
post Aug 8 2006, 09:41 AM
Post #1


Nenad Bozidarevic
Group Icon

Group: [MODERATOR]
Posts: 1,049
Joined: 7-November 05
From: Belgrade, Serbia
Member No.: 9,500
myCENTs:9.92



In order to show that malicious software is present even without OS security holes, researchers have developed a prototype of malware that cannot be detected. It is invisible even on Windows Vista, which is supposed to be fully protected from these kinds of attacks. The concept Blue Pill, which is the prototype name, uses AMD's SVM/Pacifica virtualization technology and enables complete take-over of the operating system. The user is not aware of this, because everything happens without the computer being restarted, even without lowering the computer performance.

Blue Pill doesn't use bugs in the OS, and can be used on other operating systems, such as Linux and FreeBSD that are on a 64bit platform. Even though this was just a demonstration, not detecting malware is a big problem. Fortunately, the problem (and the solution, hopefully) has been sighted long before attacks will appear.
Go to the top of the page
 
+Quote Post
Pharoah
post Aug 19 2006, 03:05 PM
Post #2


Member [ Level 2 ]
Group Icon

Group: Members
Posts: 73
Joined: 19-August 06
Member No.: 15,394



That's cool, in a sick kind of way. I know a guy who downloads huge files from BitTorrent, things like GTA clones (he has dial-up too), and then he thinks he *might* have a virus when there are popups all over his screen. So the real question here is, how often do you guys wipe your hard drives? I never do, but i have nothing to steal.
Go to the top of the page
 
+Quote Post
KDEWolf
post Aug 23 2006, 12:15 AM
Post #3


Advanced Member
Group Icon

Group: Members
Posts: 179
Joined: 14-August 06
From: Vault 0 / Brazil
Member No.: 15,193



QUOTE(pyost @ Aug 8 2006, 06:41 AM) *

In order to show that malicious software is present even without OS security holes, researchers have developed a prototype of malware that cannot be detected. It is invisible even on Windows Vista, which is supposed to be fully protected from these kinds of attacks. The concept Blue Pill, which is the prototype name, uses AMD's SVM/Pacifica virtualization technology and enables complete take-over of the operating system. The user is not aware of this, because everything happens without the computer being restarted, even without lowering the computer performance.

Blue Pill doesn't use bugs in the OS, and can be used on other operating systems, such as Linux and FreeBSD that are on a 64bit platform. Even though this was just a demonstration, not detecting malware is a big problem. Fortunately, the problem (and the solution, hopefully) has been sighted long before attacks will appear.

Whoa! O_o
Theoretically it would be doomsday, then.
Where did you get this info from, I'm cusrious to know more about it. Does it work on Intel-based systems as well?
Go to the top of the page
 
+Quote Post
pyost
post Aug 23 2006, 09:55 AM
Post #4


Nenad Bozidarevic
Group Icon

Group: [MODERATOR]
Posts: 1,049
Joined: 7-November 05
From: Belgrade, Serbia
Member No.: 9,500
myCENTs:9.92



QUOTE(Pharoah @ Aug 19 2006, 05:05 PM) *

That's cool, in a sick kind of way. I know a guy who downloads huge files from BitTorrent, things like GTA clones (he has dial-up too), and then he thinks he *might* have a virus when there are popups all over his screen. So the real question here is, how often do you guys wipe your hard drives? I never do, but i have nothing to steal.


Yeah, but that's the users fault. He downloads torrents and risks getting his computer infected. But he also seem like a person who cares a lot for these things. Not to mention that he could get rid off most of these virii by a single computer scan.

But this malware is different. No matter how much you try to protect yourself by using high quality anti-virus programs, you would still get infected! And it's not only a problem for regular users, but for big companies, too. We can just hope this doesn't get developed by crackers.
Go to the top of the page
 
+Quote Post
Jeigh
post Aug 23 2006, 11:38 AM
Post #5


Whitest Black Mage
Group Icon

Group: [MODERATOR]
Posts: 1,371
Joined: 20-May 05
From: NB, Canada
Member No.: 5,281
myCENTs:65.99



Pyost, you have a link for where this info came from? Not that I don't trust you, just kind of curious as to the details about this.
Go to the top of the page
 
+Quote Post
yordan
post Aug 23 2006, 01:46 PM
Post #6


Way Out Of Control - You need a life :)
Group Icon

Group: [MODERATOR]
Posts: 2,242
Joined: 16-August 05
Member No.: 7,896
myCENTs:44.47



QUOTE(Jeigh @ Aug 23 2006, 01:38 PM) *

Pyost, you have a link for where this info came from? Not that I don't trust you, just kind of curious as to the details about this.

You can find some info here for instance : http://www.eweek.com/article2/0,1895,1983037,00.asp
It uses rootkits and a kind of virtualization.
Not downloadable yet, except for security testing purposes.
Go to the top of the page
 
+Quote Post
TavoxPeru
post Aug 23 2006, 07:05 PM
Post #7


Super Member
Group Icon

Group: [HOSTED]
Posts: 805
Joined: 8-April 06
From: Lima - Peru
Member No.: 12,579
myCENTs:46.87



QUOTE(pyost @ Aug 8 2006, 04:41 AM) *

In order to show that malicious software is present even without OS security holes, researchers have developed a prototype of malware that cannot be detected. It is invisible even on Windows Vista, which is supposed to be fully protected from these kinds of attacks. The concept Blue Pill, which is the prototype name, uses AMD's SVM/Pacifica virtualization technology and enables complete take-over of the operating system. The user is not aware of this, because everything happens without the computer being restarted, even without lowering the computer performance.

Blue Pill doesn't use bugs in the OS, and can be used on other operating systems, such as Linux and FreeBSD that are on a 64bit platform. Even though this was just a demonstration, not detecting malware is a big problem. Fortunately, the problem (and the solution, hopefully) has been sighted long before attacks will appear.

Thanks for the info, its really amazing all the things that the hUman can create, i hope that i never be infected by this malware, yes yes, i know, i ask too mUch wink.gif

BTW, a few months ago i lost my 30GB HD especially becaUse of downloading torrents, i know that i can find good things in this format but my experience told me that the risk to get some virri is very high.

Best regards,
Go to the top of the page
 
+Quote Post
lonebyrd
post Aug 24 2006, 05:40 AM
Post #8


Premium Member
Group Icon

Group: Members
Posts: 302
Joined: 23-February 06
From: Northeastern Connecticut USA
Member No.: 11,487



I read something about this in a PC World magazine a few months ago. I can't find the article online unfortunaly, but it said something about this first starting from music companies. They would put this 'malware' (though I'm not even sure what that is) in the music disc that has a DVD feature on it. Then it would get into your computer. I'm not the most computer saavy person in the world, but I know it didn't sound good to me. They showed a 'cute' little picture of a computer with 'bugs' at the very bottom of it saying that nothing could get to it, not even anti-virus, or spy-ware blockers.
Go to the top of the page
 
+Quote Post
pyost
post Aug 24 2006, 12:53 PM
Post #9


Nenad Bozidarevic
Group Icon

Group: [MODERATOR]
Posts: 1,049
Joined: 7-November 05
From: Belgrade, Serbia
Member No.: 9,500
myCENTs:9.92



QUOTE(Jeigh @ Aug 23 2006, 01:38 PM) *

Pyost, you have a link for where this info came from? Not that I don't trust you, just kind of curious as to the details about this.


It's a news I read in a local computer newspaper, and I can guarantee that they wouldn't provide false information - after all, they do have a 15-year-long tradition smile.gif
Go to the top of the page
 
+Quote Post
Xisle
post Sep 3 2006, 04:11 PM
Post #10


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 14
Joined: 3-September 06
Member No.: 15,699



QUOTE(pyost @ Aug 23 2006, 09:55 AM) *

Yeah, but that's the users fault. He downloads torrents and risks getting his computer infected. But he also seem like a person who cares a lot for these things. Not to mention that he could get rid off most of these virii by a single computer scan.

But this malware is different. No matter how much you try to protect yourself by using high quality anti-virus programs, you would still get infected! And it's not only a problem for regular users, but for big companies, too. We can just hope this doesn't get developed by crackers.



You know, I read about someones virus problem the other day...

He cleaned his harddrive(reset it completely), bought new ram, ran several several virus scans with several different programs.... and he still has the virus....

And trust me, it's a virus not a computer problem...
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Bad_pool_header(11)
  2. Lop(4)
  3. Why Are All My New Post Invisible?(3)
  4. Blue Fusion(2)
  5. Malware Scan Site(0)
  6. Help! Blue Screen Error!(5)
  7. Have You Heard Of The Blue-ray(23)
  8. 'trauma Pill' Could Make Memories Less Painful(3)
  9. Blue Background And Bar...no Windows?(12)
  10. My New Wallpaper(20)
  11. 1 Joomla Skin For Flash Animated Portals: Mbt_macro_blue(0)
  12. Windows Restarts Itself Out Of The Blue(12)
  13. Blue Screen - irql_not_less_or_equal(35)
  14. Windows 98 Blue Screen Of Death(4)
  15. How To Create An Invisible Folder In Windows Xp(5)


 



- Lo-Fi Version Time is now: 5th December 2008 - 12:18 AM