EH-Net
May 22, 2013, 08:58:00 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Malware
(Moderator:
don
) >
Boot Sector Rootkits
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Boot Sector Rootkits (Read 3233 times)
0 Members and 1 Guest are viewing this topic.
satyr
Newbie
Offline
Posts: 41
Boot Sector Rootkits
«
on:
February 12, 2012, 12:55:27 PM »
hi,
I wanted to look more into rootkits, specially kernel mode rootkits which affect the boot sector.
Please suggest resources for me to understand and learn so that I am able to analyse these malwares.
I want to dig deep into rootkits and understand how to analyze them.
Any help appreciated.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Boot Sector Rootkits
«
Reply #1 on:
February 13, 2012, 09:02:20 AM »
I haven't done much in this area, but
http://www.amazon.com/Rootkits-Subverting-Windows-Greg-Hoglund/dp/0321294319/ref=sr_1_2?ie=UTF8&qid=1329145052&sr=8-2
was a decent introductory read. It's from 2005 and is probably dated now, but Syngress has a couple of others that seem like they would be of interest to you:
http://www.amazon.com/Managed-Code-Rootkits-Hooking-Environments/dp/1597495743/ref=sr_1_3?ie=UTF8&qid=1329145052&sr=8-3
http://www.amazon.com/Guide-Kernel-Exploitation-Attacking-Core/dp/1597494860/ref=sr_1_12?ie=UTF8&qid=1329145052&sr=8-12
rootkit.com used to be a good resource as well, but it's not loading at the moment for me. I'm not sure if that's still around or not.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Boot Sector Rootkits
«
Reply #2 on:
February 13, 2012, 10:30:16 AM »
Wasn't rootkit.com Haugland's site that was involved with the whole Anonymous/HBGary Federal ordeal? Was it ever brought back up after that breach?
Logged
GSEC, eCPPT, Sec+
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Boot Sector Rootkits
«
Reply #3 on:
February 13, 2012, 10:34:15 AM »
Quote from: lorddicranius on February 13, 2012, 10:30:16 AM
Wasn't rootkit.com Haugland's site that was involved with the whole Anonymous/HBGary Federal ordeal? Was it ever brought back up after that breach?
Yea, that's correct. He's also the co-author of the first book I recommended.
I never participated there, so aside from hearing about that ordeal, I really don't know if it was ever brought back up. It very well may not have been.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Eleven
Full Member
Offline
Posts: 120
Re: Boot Sector Rootkits
«
Reply #4 on:
February 14, 2012, 10:36:59 AM »
Here is a nice analysis of the TDL4 rootkit.
http://resources.infosecinstitute.com/tdss4-part-1/
The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System Second edition will be out March 7.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...