<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>pingudownunder.com &#187; windows</title>
	<atom:link href="http://www.pingudownunder.com/blog/tag/windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pingudownunder.com/blog</link>
	<description>my wierd little corner on this world wide interweb thingy</description>
	<lastBuildDate>Tue, 22 Jun 2010 11:24:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Return of the Bootsector Virus?</title>
		<link>http://www.pingudownunder.com/blog/2007/05/03/return-of-the-bootsector-virus/</link>
		<comments>http://www.pingudownunder.com/blog/2007/05/03/return-of-the-bootsector-virus/#comments</comments>
		<pubDate>Thu, 03 May 2007 13:13:28 +0000</pubDate>
		<dc:creator>Simon Harvey</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.pingudownunder.com/2007/05/03/return-of-the-bootsector-virus/</guid>
		<description><![CDATA[A very interesting article caught my eye which is being presented to BlackHat Europe and HITB Dubai conferences. Two Indian graduates have developed a Vbootkit, which is just like a standard rootkit in Windows … but importantly is invoked before the OS itself starts booting up, i.e. by compromising the boot sectors. Before the OS [...]]]></description>
			<content:encoded><![CDATA[<p>A very interesting article caught my eye which is being presented to BlackHat Europe and HITB Dubai conferences. Two Indian graduates have developed a Vbootkit, which is just like a standard rootkit in Windows … but importantly is invoked before the OS <span id="more-10"></span>itself starts booting up, i.e. by compromising the boot sectors. Before the OS is loaded.</p>
<p>Could this herald the return of the “bootsector” virus with a nasty undetectable payload, giving it root privileges? An article about it (very interesting read, highly recommended) is at <a href="http://www.nvlabs.in/?q=node/16">http://www.nvlabs.in/?q=node/16</a> including detailed technical information (pdf format) and presentation slides/video demonstration also on the site. One to keep in mind …</p>
<p>The demo, of course, compromises Windows Vista. Or if you’re feeling like a bit of fun this weekend, you can download the source code for the vbootkit for Windows 2000, XP and 2003 from the same site. Shame they didn’t put the antispam on their blog page, where there are the usual spamdverts for certain medicals and loans.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pingudownunder.com/blog/2007/05/03/return-of-the-bootsector-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
