The Rise of MBR Rootkits & Bootkits in the Wild
We have seen previous bootkits in the wild, this presentation will give a line up of bootkits, their methods and how they are used. Sinowal, Stoned and various bootkits from the wild will be discussed, and as an extra plus the Windows Product Activation for OEM PCs introduced with Vista and 7 will be explained in detail and how you can spoof it. Free Windows for everyone!
Peter Kleissner, Software Dev. Guru in Vienna
- Paper
- Hacking at Random 2009 Presentation
- TrueCrypt Encryption and RawFS
- Creating your own PDF Infector
Windows Product Activation
Microsoft has a secret arrangement with OEM hardware manufacturers to include a secret additional ACPI table to identify the system as OEM and activating it without any need of online activation. At Hacking at Random I showed how this internal OEM verification works, how it is based and how it can be spoofed.
^ Top
Last modified: 8 April 2010
Previous page: Stoned Bootkit
Next page: Stoned déjà vu - again
