Computerworld
Rootkits outfox old-school malware protection
Trusted computing no silver bullet
Darren Pauli  30 March, 2007 12:33

Security experts now believe that trojan, spam and malware protection software cannot adequately prevent system compromise by increasingly sophisticated rootkits.

Rootkits are used to conceal the presence of trojans, hacker backdoors, and botnets by cloaking their files and processes through modifying the output of common operating system routines. They grant administrator access to a system after a hacker installs them typically through obtaining user level access by exploiting known vulnerabilities.

Intelligent Business Research Services analyst James Turner said rootkits will be increasingly used in highly targeted attacks as they become more sophisticated and form a critical part of hacker arsenals.

"We are going to see rootkits used in highly targeted attacks where hackers will source, for example, a CFO's operating system and the typical applications they use, and then find a specific vulnerability based on these which allows a rootkit to be inserted," Turner said.

According to Turner, information security infrastructure is heating up through increased education and simulations of information security warfare, however he said the biggest problem is getting people who have been hacked to warn the public about it.

Rootkits can be classified as; kernel-mode, which intercept kernel interface calls and alter OS kernel data to conceal rootkits from process lists; persistent, which use the system registry to execute on boot; user-mode, which can use keyloggers and infect or masquerade as OS commands; and memory-based, which rely on manual user execution to operate.

The most critical exist in unpatched exploits in common applications, according to Chris Gatford, senior security analyst at penetration testing firm Pure Hacking.

"Microsoft Word has an unspecific exploit that has been unpatched for 47 days; if I were a hacker I would certainly target these kinds of exploits because the scope is so wide," Gatford said.

"Hackers are using the same spyware model but are distributing them with the next-level of rootkits."

Security firm Markets-Alert director Jeff McGeorge said rootkits are the frontline arsenal of hackers and are too sophisticated for rootkit revealers, and virus and spam protection software to combat.

"Rootkits are being dynamically inserted on-the-fly which means they can sit invisibly in a Web page's source code using a Windows cloaking function, and download on to your machine without raising any attention because they disable download warnings and spyware applications from flagging them," McGeorge said.

He said the rootkits use plug and play software drivers to gain access to the Windows kernel, where they generate dummy SSL session pages to capture user authentication details from packets, then completely uninstall and continue to monitor the victim's ports and IP address when the user leaves the infected Web page.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

LANPlanner | Ensuring High Performance WLAN Networks

Learn how the Motorola LANPlanner facilitates prompt and precise planning and the design and measurement of robust 802.11a/b/g/n networks. Download this paper now to discover how to take wireless network performance to the next level.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.