DVForge - Virus Prize 2005
what the hell are these people thinking, offering to pay people to write viruses for the mac and spread them in the wild? like virus writers don't already have enough motivation to write and spread viruses - especially when it comes to being the first one for a new platform or the first one in the wild for a new platform... those sorts of things already make them (in)famous...
these folks have clearly had a break our ethical reality - you do not need a proof of concept virus to prove viruses can spread on the mac - mac OS X is basically a form of unix and the very first viruses that fred cohen wrote when doing his seminal work on viruses back in the '80s worked on unix systems... and they did work, they spread on production systems...
come on, folks - all general pupose computing platforms are susceptible to viruses... all of them... it's been proven - and i don't mean the way you prove things in court with evidence, because there will always be new platforms for which there is no evidence yet... i mean it's been proven on paper with logic - the only facilities a virus needs are those that are already present in the definition of general purpose computer...
these people are not solving any real problem by offering a reward to virus writers for writing yet more viruses (and you know damn well there are going to be a lot more viruses written than rewards handed out)... all they are doing is making virus spreading (because you do need to spread your virus so that it makes it's way onto the target systems naturally in order to get the reward) seem more legitimate by wrapping it up like it's some sort of good deed that puts a set of misconceptions by uninformed people to bed... the fact is that they are soliciting behaviour that is illegal under canadian laws (criminal mischief pertaining to data) as well as laws in a variety of other countries that have unauthorized-access-related legislation...
john mcafee reputedly paid for virus collections and thus became a pariah in the anti-virus industry for supplying virus writers with financial motivation to write viruses... these people here are supplying financial motivation to write & spread viruses and that absolutely contributes to the problem, rather than the solution... these people are not interested in the greater good, they're only interested in making a name for themselves and they don't care how much damage they cause in the process...
update 5:30pm: well, that was quick... seems a lot of people contacted the guy in charge and convinced him to stop the contest... hurray!... now let's move on...
devising a framework for thinking about malware and related issues such as viruses, spyware, worms, rootkits, drm, trojans, botnets, keyloggers, droppers, downloaders, rats, adware, spam, stealth, fud, snake oil, and hype...
Showing posts with label unix. Show all posts
Showing posts with label unix. Show all posts
Saturday, March 26, 2005
Sunday, March 13, 2005
rootkits for windows
this page tries to explain what rootkits are and the emerging threat they pose for the windows platform...
that's all well and good but there's something that just doesn't sit well with me... let's take a closer look:
i like this explanation... it's simple, it's consistent, it makes sense.... a rootkit is a tool used to gain root (*nix speak for administrator) privileges...
now this is not so good... apparently rootkits for windows don't really have anything to do with giving a principle administrative privileges... it does a bunch of the other things it's unix counterpart does (i.e. it uses sophisticated techniques to hide) but no elevation of privilege...
does that make sense to you?
if i take the self-replication out of a virus, regardless of the fact that it can still do all the other things it used to be able to do, it is no longer a virus...
why then if i take the root granting functionality out of a rootkit does it remain a rootkit?
it doesn't seem to make a lot of sense, it is not logically consistent... by rights, what they're calling rootkits for windows should be called (in keeping with the spirit of the rootkit name) stealthkits...
now, this was an f-secure description so you may well be thinking that maybe those f-secure folks are a little confused... but no, if that were the case then why does sophos also seem to think that rootkits are more about hiding than they are about privilege elevation (which they don't even mention)... and then there's sysinternal's explanation of rootkits which also focuses on hiding rather than privilege elevation...
this seems like it might actually be industry wide, in which case i can just site here in awe and wonder because the industry appears to be from a completely different planet than you and me...
that's all well and good but there's something that just doesn't sit well with me... let's take a closer look:
The term rootkit is very old and is dated back to the days when UNIX ruled the world. Rootkits for the UNIX operating system were typically used to elevate the privileges of a user to the root level (=administrator). This explains the name of this category of tools.
i like this explanation... it's simple, it's consistent, it makes sense.... a rootkit is a tool used to gain root (*nix speak for administrator) privileges...
Rootkits for Windows work in a different way and are typically used to hide malicious software from for example an antivirus scanner. Rootkits are typically not malicious by themselves but are used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what was known as full stealth viruses in the MS-DOS environment.
now this is not so good... apparently rootkits for windows don't really have anything to do with giving a principle administrative privileges... it does a bunch of the other things it's unix counterpart does (i.e. it uses sophisticated techniques to hide) but no elevation of privilege...
does that make sense to you?
if i take the self-replication out of a virus, regardless of the fact that it can still do all the other things it used to be able to do, it is no longer a virus...
why then if i take the root granting functionality out of a rootkit does it remain a rootkit?
it doesn't seem to make a lot of sense, it is not logically consistent... by rights, what they're calling rootkits for windows should be called (in keeping with the spirit of the rootkit name) stealthkits...
now, this was an f-secure description so you may well be thinking that maybe those f-secure folks are a little confused... but no, if that were the case then why does sophos also seem to think that rootkits are more about hiding than they are about privilege elevation (which they don't even mention)... and then there's sysinternal's explanation of rootkits which also focuses on hiding rather than privilege elevation...
this seems like it might actually be industry wide, in which case i can just site here in awe and wonder because the industry appears to be from a completely different planet than you and me...
Tags:
f-secure,
malware,
rootkit,
sophos,
stealth,
stealthkit,
sysinternals,
trojan,
unix,
windows
Subscribe to:
Posts (Atom)