Given my recent negative experience with the author of one such home-brew tool, I thought that I put together a list of ideas the developers of such programs should follow and ask them to sign
it (it’s written in quotes because obviously the signature will be a virtual one). So here is the list:
Manifesto of the ethical Anti-Rootkit writer
power users) and I will follow that description to the letter (for example, if you state that
this tool allows the detection of hidden processes, the tool should only detect the processes, not terminate them. If the tool also terminates them, that should be included in the description).
power usersare able to understand it, and also list the possible risks.
The undersigned:
If you are a vendor / author of an Anti-Rootkit program and would like to appear in the above list, send me an e-mail ([email protected]) from a verifiable e-mail address (meaning that the sending e-mail address either appears on the site of the program or is from the same domain) stating that you understand the above terms and follow them and I will include your products name in the list. You can also e-mail me if you have suggestions and/or comments or you can leave me a comment below. I will get back to you as soon as possible.
Q: what are the guarantees that the products who appear on that list really will follow the terms?
A: There is no guarantee. The inclusion in the list is voluntary and does not involve any verification on my part (because I don’t have the time to disassemble all the versions of all the anti-rootkits out there and do this whenever a new version comes out). Further more some criteria on the list are not clearly defined (like the one with as little code in the kernel as possible).
Q: What does it prove if a vendor / program appears in this list?
A: Strictly speaking in proves that somebody with an e-mail account representative of the product has e-mail-ed me that they understand and follow these principles and would like to be included on the list. In a more broader sense it proves that they have thought about these issues and (most probably) follow them.
Q: Can people / vendors be removed from the list?
A: If there is public evidence of them violating these principles, they will be removed and a description will be posted of the reasons for removing them with links to the evidence.
Q: Why are the terms so vague?
A: The list tries to be as inclusive as possible. If somebody signs it, (hopefully) it means that they at least thought about these matters and follow some basic ethical principles. And make no mistake, there are some out there, who don’t follow even these broad terms. Also, the fact that a person / vendor appears on this list does not mean that this is their code of ethics. It may very well mean that they have a much stricter code of ethics which is included in the above list.
]]>Cd-MaN, YOU ARE POOR GUY or, maybe, girl , who wants to advertise your poor, incompatible with logic blog [xx(] . We are sincerely hope, that this was your first and last post here . [b]If it not, then soon you, as well as your board will get “good” advertise over the Internet[/b]. What about your statements, so I can say that you understand a little (perhaps you are still in primary school) because all what you said about RkU can be applied to 70% of all antimalware soft (including all antirootkits).
I hope, that you do not get paid from GMER for this post, because you get less, than you should.
In a whole, I think that your blog is a scope of lamers statements and rediculus decisions. I found many funny statements, from which I can guess:
– GMER love your sorry ass
– You are kiddo
– You want glory (you will get it)
– In real life you a complete looser, that can’t even finish primary school
– Your English as well as you – are poor
– You have come here looks like because you wants to be bittenPS: Tomorrow you will get comprehensive answer (without censored words) from EP_X0FF to all your statements and to your blog in a whole. But, I want, that you are not
able to reach tomorrow, as well as your f u c k i n blog.
So that was it in its full glory. I apologize for the foul language. As I already stated, there is absolutely no connection between me and GMER. One interesting part that I didn’t comment on yesterday is the fact that he says that 70% of the Anti-Rootkit industry
uses the same approach that they use. If I would be in that industry I would be really hurt. I really don’t think (but then again, I might be wrong) that 70% of these people are involved / approve of illegal activities like defacing / DDoS’ing, threaten their critics or do not follow the principle of responsible disclosure (yes, these are the same guys who written the Unreal rootkit, which to me seems a little hypocritical).
You have come against wrong peopleand that
want, that you are not able to reach tomorrow(I suppose he means that he wishes for me to die :-)).
Any my thread on the SysInternals forum was deleted because my post was not technical
. This is true, but I feel that this information must be taken into consideration by anyone who wishes to run the program on her/his system.
You can read his entire reply on their forum. And I just observed that the title of the topic is Any sources for the dead hype-free.blogspot.com
. Good going guys! I really don’t know what you’re after, but if getting hired by a security company and/or selling RkUnhooker as a commercial product, you can cross it of your list, since with an attitude like this you will have a hard time getting hired (and no, AV companies do not hire virus writers).
BTW, if I understand right, they are accusing me of being a GMER (which is an other amateur – in the sense that there is no company behind it – anti-rootkit product) fanboy. It is true that that I host a mirror of the GMER files because its site was/is under a DDoS attacks, but I have nothing to do with it, nor do I endorse the usage of any such products (as you can read in my original post).
It is interesting that the anti-rootkit market
is such a highly flammable one, with waring tribes
and each side having their groupies
. I don’t understand where this comes from, since seemingly nobody is making any money out of this, not even with AdSense or similar things. It might be that they are aiming at being hired / bought by companies, and as I stated earlier, in this case the RkUnhooker guys just shot themselves in the foot.
My thought are: if I deface my own site, do I get the source code?
On a more serious note: after this incident would you consider running his program on your computer? Consider this: by running RkUnhooker you give somebody who clearly has anger management problems and sees violence as a viable response system wide access (because his soft needs Admin level privileges to be able to load the driver)! I looked through the current version of the software and it doesn’t contain any malicious code – and no, PECompact doesn’t protect your program from reverse engeneering, and packing your executable is a bad idea in itself – but this may change in the future judging his posts (the last post says in Russian: we are already working on it
). You should make sure that you are not part of the solution and avoid his software.
The last install kit which I checked had a size of 147611 bytes, a MD5 of f79f711bd54bfc9f297eeefee69f8705 and a SHA1 of ccb2558366cb076451fe6f58c4c5081eae52f168. Do not run anything from him if possible!
]]>Comments (0)part
There has been some controversy over a recently released service which claims to tell you if your credicard number of social-security number has been compromised. While I understand (and agree with) all the arguments brought against it, I would like to point out that the risk of exposing the data can be reduced by storing its (salted) hash and not storing any relation between them (like this CC# and SS# belong to the same person) even if this was available in the source. I find it curious that nowhere in their FAQ is this mentioned, which leads me to believe that they are not using it, in which case panic, panic, panic since your security companies are dumb! (A side not: hashing, even with salt, is not the ultimate solutions since if somebody breaks into their site they will probably have access to the salt(s) and the key space is small – 9 digits for SS# and 15-19 digits for CC# – so that a brute-force attack is feasible). This is a dumb idea.
On episode 211 of .NET Rocks they interviewed Raymond Chen, a very smart programmer / blogger (and now book author) from Microsoft. Worth listening to!
Via Limite Exposure: a long list of online network tools. I didn’t had time to look at them all, but I very much liked the homepage of Team Cymru with many useful tools and explanations of the lesser known aspects of networking, the robtex swiss army knife which includes a linkable GIF (yes GIF, not Javascript or Flash!) that displays information about the user (you can see an example below) and traceroute.org, which lists different sites offering online traceroute services by country. PeeringDB is also very interesting, but it seems that IPSs (event the big players) from Romania are not well covered (most probably because this is a system which builds upon individuals contributing and not automatic datamining). And last but not least: Vendor/Ethernet MAC Address Lookup and Search.
Being a keyboard junky myself, this seems a very interesting product!
Java is (currently) the ultimate cross-platform application platform, but also the ultimate cross-platform exploitation engine. So follow SANS’s advice and make sure that you update / remove the old version. On a related note: Microsoft came out with something called WPF/E (Windows Presentation Foundation/Everywhere) which is something similar to Flash. What is very interesting is that the download is small (much like the Flash player), no managed code (ergo no need for a 22MB .NET framework) and support for alternative platforms (both in browsers – ie. Firefox – and platforms – they currently support Mac OSX but plans to support Linux are already announced). What is exciting about it is that they included the WMV / WMA decoder in it, so there is an other largely available technology to distribute multimedia content on the web! (Listen to the Hanselminutes show covering it)
A russian researcher
(I put the work in quotes because he is more of a teen whose biggest wish is to brag) claims to created an undetectable rootkit called Unreal. My thoughts are:
bypassing itand tries to chat with anybody he believes to be a girl is not somebody who should be taken seriously (and neither should their
product).
In conclusion, my plea to the security companies is: if you are serious about user education, start educating them about running as non-privileged users!
]]>