RkUnhooker saga – Grey Panthers Savannah https://grey-panther.net Just another WordPress site Wed, 21 Feb 2007 06:10:00 +0000 en-US hourly 1 https://wordpress.org/?v=7.1.2 206299117 Manifesto of the ethical Anti-Rootkit writer https://grey-panther.net/2007/02/manifesto-of-the-ethical-anti-rootkit-writer.html https://grey-panther.net/2007/02/manifesto-of-the-ethical-anti-rootkit-writer.html#respond Wed, 21 Feb 2007 06:10:00 +0000 https://grey-panther.net/?p=900 Rootkits are a controversial subject. When the book (Rootkits, Subverting the Windows Kernel) came out and the associated site (rootkit.com) was started, the subject exploded. Of course the Sony DRM fiasco did also plenty to generate media buzz. Because of this, many detection tools were born. Some were created by traditional security companies and some by relatively unknown people. A small fraction of the people creating these tools have dubious ethical background (proven by the fact that they condone and solicitate illegal activities like DDoS-ing and defacing, seek to create rootkits which are not detectable by anyone, etc). Why doest this matter? Because these tools work by loading their code in the kernel and thus only work if they are started from an Administrator account. Metaphorically speaking: running these tools is like handing over the keys to your house to let them check if your security system works. When doing that you should make sure that you trust the right person!

Given my recent negative experience with the author of one such home-brew tool, I thought that I put together a list of ideas the developers of such programs should follow and ask them to sign it (it’s written in quotes because obviously the signature will be a virtual one). So here is the list:

Manifesto of the ethical Anti-Rootkit writer

  • I will give a high level description of the actions performed by my program which can be understood by even moderately technical savvy user (so called power users) and I will follow that description to the letter (for example, if you state that this tool allows the detection of hidden processes, the tool should only detect the processes, not terminate them. If the tool also terminates them, that should be included in the description).
  • The program will not perform possibly dangerous operations without user consent. The message informing the user should contain a simple enough description of the action so that power users are able to understand it, and also list the possible risks.
  • I will limit my kernel mode code to as little as possible.
  • I will clearly list the supported platforms (operating system version and patch level) and give the user warnings if the s/he is using the tool on an unsupported platform.
  • I do not approve or am engaged in illegal activities (like site defacement, DDoS, etc)
  • All of my research is done on computers owned by me or by consenting people. In case I ask other people to test my programs / products, I will provide them with a detailed description of what the program does, what the associated risks of using this program are and what files / registry keys are associated with / modified by the program.
  • I practice responsible disclosure. I notify vendors prior to releasing any information which could negatively impact the security of the people using their products.

The undersigned:

If you are a vendor / author of an Anti-Rootkit program and would like to appear in the above list, send me an e-mail ([email protected]) from a verifiable e-mail address (meaning that the sending e-mail address either appears on the site of the program or is from the same domain) stating that you understand the above terms and follow them and I will include your products name in the list. You can also e-mail me if you have suggestions and/or comments or you can leave me a comment below. I will get back to you as soon as possible.

Q: what are the guarantees that the products who appear on that list really will follow the terms?

A: There is no guarantee. The inclusion in the list is voluntary and does not involve any verification on my part (because I don’t have the time to disassemble all the versions of all the anti-rootkits out there and do this whenever a new version comes out). Further more some criteria on the list are not clearly defined (like the one with as little code in the kernel as possible).

Q: What does it prove if a vendor / program appears in this list?

A: Strictly speaking in proves that somebody with an e-mail account representative of the product has e-mail-ed me that they understand and follow these principles and would like to be included on the list. In a more broader sense it proves that they have thought about these issues and (most probably) follow them.

Q: Can people / vendors be removed from the list?

A: If there is public evidence of them violating these principles, they will be removed and a description will be posted of the reasons for removing them with links to the evidence.

Q: Why are the terms so vague?

A: The list tries to be as inclusive as possible. If somebody signs it, (hopefully) it means that they at least thought about these matters and follow some basic ethical principles. And make no mistake, there are some out there, who don’t follow even these broad terms. Also, the fact that a person / vendor appears on this list does not mean that this is their code of ethics. It may very well mean that they have a much stricter code of ethics which is included in the above list.

]]>
https://grey-panther.net/2007/02/manifesto-of-the-ethical-anti-rootkit-writer.html/feed 0 900
Mismoderated RkUnhooker comment https://grey-panther.net/2007/02/mismoderated-rkunhooker-comment.html https://grey-panther.net/2007/02/mismoderated-rkunhooker-comment.html#respond Wed, 21 Feb 2007 05:44:00 +0000 https://grey-panther.net/?p=901 And here is an other event in the RkUnhooker saga. Because of the controversy I’m involved in regarding my No love for RkUnhooker post, I wanted to come out and state publicly that I erroneously mismoderated (rejected) MP_ART’s comment on my blog. Before I get accused of censorship, I just want to say that it was a honest mistake (which happened to me before), caused by the fact that the publish and reject links are so damn near. I felt that it was appropriate to publish his comment here (although it is the same thing as the post published on their forums and sent to me in private message on the SysInternals forums):

Cd-MaN, YOU ARE POOR GUY or, maybe, girl , who wants to advertise your poor, incompatible with logic blog [xx(] . We are sincerely hope, that this was your first and last post here . [b]If it not, then soon you, as well as your board will get “good” advertise over the Internet[/b]. What about your statements, so I can say that you understand a little (perhaps you are still in primary school) because all what you said about RkU can be applied to 70% of all antimalware soft (including all antirootkits).
I hope, that you do not get paid from GMER for this post, because you get less, than you should.
In a whole, I think that your blog is a scope of lamers statements and rediculus decisions. I found many funny statements, from which I can guess:
– GMER love your sorry ass
– You are kiddo
– You want glory (you will get it)
– In real life you a complete looser, that can’t even finish primary school
– Your English as well as you – are poor
– You have come here looks like because you wants to be bitten

PS: Tomorrow you will get comprehensive answer (without censored words) from EP_X0FF to all your statements and to your blog in a whole. But, I want, that you are not
able to reach tomorrow, as well as your f u c k i n blog.

So that was it in its full glory. I apologize for the foul language. As I already stated, there is absolutely no connection between me and GMER. One interesting part that I didn’t comment on yesterday is the fact that he says that 70% of the Anti-Rootkit industry uses the same approach that they use. If I would be in that industry I would be really hurt. I really don’t think (but then again, I might be wrong) that 70% of these people are involved / approve of illegal activities like defacing / DDoS’ing, threaten their critics or do not follow the principle of responsible disclosure (yes, these are the same guys who written the Unreal rootkit, which to me seems a little hypocritical).

]]>
https://grey-panther.net/2007/02/mismoderated-rkunhooker-comment.html/feed 0 901
And so the RkUnhooker saga begins https://grey-panther.net/2007/02/and-so-the-rkunhooker-saga-begins.html https://grey-panther.net/2007/02/and-so-the-rkunhooker-saga-begins.html#respond Tue, 20 Feb 2007 18:56:00 +0000 https://grey-panther.net/?p=902 The RkUnhooker story gets worse and worse (from the point of view of its authors). They (EP_X0FF and MP_ART) are making threats Russian mob style (not that I would know how a Russian mob threat sounds :-D), stating that You have come against wrong people and that want, that you are not able to reach tomorrow (I suppose he means that he wishes for me to die :-)).

Any my thread on the SysInternals forum was deleted because my post was not technical. This is true, but I feel that this information must be taken into consideration by anyone who wishes to run the program on her/his system.

You can read his entire reply on their forum. And I just observed that the title of the topic is Any sources for the dead hype-free.blogspot.com. Good going guys! I really don’t know what you’re after, but if getting hired by a security company and/or selling RkUnhooker as a commercial product, you can cross it of your list, since with an attitude like this you will have a hard time getting hired (and no, AV companies do not hire virus writers).

BTW, if I understand right, they are accusing me of being a GMER (which is an other amateur – in the sense that there is no company behind it – anti-rootkit product) fanboy. It is true that that I host a mirror of the GMER files because its site was/is under a DDoS attacks, but I have nothing to do with it, nor do I endorse the usage of any such products (as you can read in my original post).

It is interesting that the anti-rootkit market is such a highly flammable one, with waring tribes and each side having their groupies. I don’t understand where this comes from, since seemingly nobody is making any money out of this, not even with AdSense or similar things. It might be that they are aiming at being hired / bought by companies, and as I stated earlier, in this case the RkUnhooker guys just shot themselves in the foot.

]]>
https://grey-panther.net/2007/02/and-so-the-rkunhooker-saga-begins.html/feed 0 902
No love for RkUnhooker https://grey-panther.net/2007/02/no-love-for-rkunhooker.html https://grey-panther.net/2007/02/no-love-for-rkunhooker.html#comments Tue, 20 Feb 2007 14:43:00 +0000 https://grey-panther.net/?p=904 It seems that the author of RkUnhooker (you know, that guy named EP_X0FF) got very upset about my comments and first he wrote a comment to my blog – which I published a little late and I apologize for it. Then he got into personal mode and made a threatening post on his forum.

My thought are: if I deface my own site, do I get the source code? 😀 On a more serious note: after this incident would you consider running his program on your computer? Consider this: by running RkUnhooker you give somebody who clearly has anger management problems and sees violence as a viable response system wide access (because his soft needs Admin level privileges to be able to load the driver)! I looked through the current version of the software and it doesn’t contain any malicious code – and no, PECompact doesn’t protect your program from reverse engeneering, and packing your executable is a bad idea in itself – but this may change in the future judging his posts (the last post says in Russian: we are already working on it). You should make sure that you are not part of the solution and avoid his software.

The last install kit which I checked had a size of 147611 bytes, a MD5 of f79f711bd54bfc9f297eeefee69f8705 and a SHA1 of ccb2558366cb076451fe6f58c4c5081eae52f168. Do not run anything from him if possible!

]]>
https://grey-panther.net/2007/02/no-love-for-rkunhooker.html/feed 6 904
Mixed links and commentary https://grey-panther.net/2007/01/mixed-links-and-commentary-4.html https://grey-panther.net/2007/01/mixed-links-and-commentary-4.html#comments Sun, 28 Jan 2007 14:06:00 +0000 https://grey-panther.net/?p=914 A very nice T-Shirt. I especially like the Comments (0) part 😉

There has been some controversy over a recently released service which claims to tell you if your credicard number of social-security number has been compromised. While I understand (and agree with) all the arguments brought against it, I would like to point out that the risk of exposing the data can be reduced by storing its (salted) hash and not storing any relation between them (like this CC# and SS# belong to the same person) even if this was available in the source. I find it curious that nowhere in their FAQ is this mentioned, which leads me to believe that they are not using it, in which case panic, panic, panic since your security companies are dumb! (A side not: hashing, even with salt, is not the ultimate solutions since if somebody breaks into their site they will probably have access to the salt(s) and the key space is small – 9 digits for SS# and 15-19 digits for CC# – so that a brute-force attack is feasible). This is a dumb idea.

On episode 211 of .NET Rocks they interviewed Raymond Chen, a very smart programmer / blogger (and now book author) from Microsoft. Worth listening to!

Via Limite Exposure: a long list of online network tools. I didn’t had time to look at them all, but I very much liked the homepage of Team Cymru with many useful tools and explanations of the lesser known aspects of networking, the robtex swiss army knife which includes a linkable GIF (yes GIF, not Javascript or Flash!) that displays information about the user (you can see an example below) and traceroute.org, which lists different sites offering online traceroute services by country. PeeringDB is also very interesting, but it seems that IPSs (event the big players) from Romania are not well covered (most probably because this is a system which builds upon individuals contributing and not automatic datamining). And last but not least: Vendor/Ethernet MAC Address Lookup and Search.

robtex

Being a keyboard junky myself, this seems a very interesting product!

Java is (currently) the ultimate cross-platform application platform, but also the ultimate cross-platform exploitation engine. So follow SANS’s advice and make sure that you update / remove the old version. On a related note: Microsoft came out with something called WPF/E (Windows Presentation Foundation/Everywhere) which is something similar to Flash. What is very interesting is that the download is small (much like the Flash player), no managed code (ergo no need for a 22MB .NET framework) and support for alternative platforms (both in browsers – ie. Firefox – and platforms – they currently support Mac OSX but plans to support Linux are already announced). What is exciting about it is that they included the WMV / WMA decoder in it, so there is an other largely available technology to distribute multimedia content on the web! (Listen to the Hanselminutes show covering it)

A russian researcher (I put the work in quotes because he is more of a teen whose biggest wish is to brag) claims to created an undetectable rootkit called Unreal. My thoughts are:

  • EP_X0FF and the likes should get a first life. Somebody who is incapable of logical reasoning, who calls killing an utility bypassing it and tries to chat with anybody he believes to be a girl is not somebody who should be taken seriously (and neither should their product).
  • It is surprisingly how little attention the practice of running as limited user (as opposed to Administrator) gets both from security companies who don’t even mention it in their list of steps you can take to be more safe and from Microsoft itself. It is even more surprising if you think about the fact that running as limited user eliminates the possibility of getting infected by (kernel) rootkits and makes your security products immune to tampering from malware, so that they don’t have to use dirty and risky hacks to achieve this. Not yet convinced? Think about this: you get all this security for free (if you purchased Windows :-D), most programs have no or very little problem running under limited accounts and Microsoft has now a free program which can be used to quickly diagnose problems with ill-behaved programs.
  • There is of course the whole issue of ethical conflict, an other reason to ignore EP_XOFF and the likes.
  • There will never be a generic detection for rootkits, because any detection will have to run in the same security domain as the rootkit (we suppose that the tool is used after the fact). Much like the good old DOS days and the advice is the same: boot from a clean media (floppy in the old days, CD-ROM today) and do a scan from there. The big difference is however that we have the technological possibility to confine the malware: it is called protected mode. All you have to do is to run an operating system capable of using it (which is true for all the current ones, including Windows, Linux, the BSD variants, Mac OSX, etc) and configure it properly so that you don’t use the Administrator / root account!

In conclusion, my plea to the security companies is: if you are serious about user education, start educating them about running as non-privileged users!

]]>
https://grey-panther.net/2007/01/mixed-links-and-commentary-4.html/feed 2 914