Rootkits allow hackers to hide content on infected computers
Rootkits allow hackers to hide content on infected computers
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Rootkits leave antivirus systems powerless

No defence in standard antivirus code

Iain Thomson, vnunet.com 18 Mar 2005
ADVERTISEMENT

An increasing number of virus writers are using so-called 'rootkit' technology to create malware that is invisible to existing antivirus packages, IT security experts warned today.

Rootkits have been around in Unix systems for about 15 years, but the technology has only been in Windows systems recently, according to security firm F-Secure.

They allow hackers to hide spam servers, stolen media and illegal content on infected computers, and provide a backdoor that gives full administrator privileges to those who know how to access it.

"Windows rootkit is a stealth technique for hiding files. But does it at the kernel level, rather than at the application level," explained Patrick Runald, senior technical consultant at F-Secure.

"As such, virtually none of the current antivirus products can detect a rootkit at work. You can bet they all will, but that will take about six months and the rootkits are being used now."

Two recent viruses, Myfip.H and Maslan.A, both had stealth features borrowed from rootkits, according to Runald.

Dr Emlyn Everitt, a consultant at Logicalis and the first person in Britain to gain a PhD in intrusion prevention, added: "The key to any hacking attack is privilege escalation.

"Most security conscious people will have limited PC privileges. These rootkits allow you to escalate the privileges and get full control, and they can be easily customised to get past antivirus security."

SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Foster Wheeler
Analyst Programmer - Applix TM1 -Competitive Salary - ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals ... more >
| Foster Wheeler
Analyst Programmer - JDEdwards- ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals lt;/p> Our UK-headquartered operations ... more >
| Google
The area: DoubleClick DoubleClick, a Google company, enables top marketers, publishers and agencies to utilize DoubleClick's expertise in ad serving, rich media, video and affiliate marketing to help them make the most of the digital ... more >
| Google
The area: Engineering Management Google's engineering teams exhibit high energy, deep technical skills and a drive to get things done. Our Engineering Managers need to be technical leaders and motivators who are comfortable leading these ... more >
More job opportunities