VBootkit Bypasses Vista's Code Signing Mechanisms

VBootkit Bypasses Vista's Code Signing Mechanisms.

Interesting work:

Experts say that the fundamental problem that this highlights is that every stage in Vista's booting process works on blind faith that everything prior to it ran cleanly. The boot kit is therefore able to copy itself into the memory image even before Vista has booted and capture interrupt 13, which operating systems use for read access to sectors of hard drives, among other things.

This is not theoretical; VBootkit is actual code that demonstrates this. 
[Schneier on Security]

This entry was posted on Friday, April 6th, 2007 at 7:15 am and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

You must be logged in to post a comment.