<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Rootkits Infecting the MBR</title>
	<atom:link href="http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-110059</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Tue, 12 Feb 2008 01:59:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-110059</guid>
		<description>@J. Lion

If it was I think you would know already ;)</description>
		<content:encoded><![CDATA[<p>@J. Lion</p>
<p>If it was I think you would know already <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Lion</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-110028</link>
		<dc:creator>J. Lion</dc:creator>
		<pubDate>Mon, 11 Feb 2008 23:24:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-110028</guid>
		<description>scary...

I wonder if my MBR is infected...</description>
		<content:encoded><![CDATA[<p>scary&#8230;</p>
<p>I wonder if my MBR is infected&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-108157</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Thu, 07 Feb 2008 05:42:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-108157</guid>
		<description>Props to the ping pong virus!

I never though MBR viruses would ever make a comeback. Now the black hats reverted to old tactics, it seems AV will be forced to keep up and catch them before they get installed. Another way around this (aside from programs that stop the modification of vital system files) is a program that is called something like shadow drive. This program basically makes an image of your hard drive(s) and all changes made are not actually stored on the hard drive itself but the image. I have not used the program myself but at some point you are allowed to write the files to the hard drive allowing the computer to be both safe and usable.</description>
		<content:encoded><![CDATA[<p>Props to the ping pong virus!</p>
<p>I never though MBR viruses would ever make a comeback. Now the black hats reverted to old tactics, it seems AV will be forced to keep up and catch them before they get installed. Another way around this (aside from programs that stop the modification of vital system files) is a program that is called something like shadow drive. This program basically makes an image of your hard drive(s) and all changes made are not actually stored on the hard drive itself but the image. I have not used the program myself but at some point you are allowed to write the files to the hard drive allowing the computer to be both safe and usable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Security news roundup: January 20 &#124; IT Security &#124; TechRepublic.com</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100712</link>
		<dc:creator>&#187; Security news roundup: January 20 &#124; IT Security &#124; TechRepublic.com</dc:creator>
		<pubDate>Mon, 21 Jan 2008 12:44:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100712</guid>
		<description>[...] which gets a boast in their subversion of the kernel before the operating system even loads. Excerpt from The Darknet: About 30,000 websites, mostly located in Europe, are actively trying to install the rootkit by [...]</description>
		<content:encoded><![CDATA[<p>[...] which gets a boast in their subversion of the kernel before the operating system even loads. Excerpt from The Darknet: About 30,000 websites, mostly located in Europe, are actively trying to install the rootkit by [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mumble</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100517</link>
		<dc:creator>mumble</dc:creator>
		<pubDate>Sun, 20 Jan 2008 20:40:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100517</guid>
		<description>@goodpeople - &quot;A Cookie&quot;

I find it fascinating that a number of older people - among them security researchers and pentesters, all remember this stuff with glee from back when they were behaving like juvenile delinquents. Plus la change, plus la meme chose... (Yes, I mangled that, but I don&#039;t have bindings for French characters on my keyboard....Unicode doesn&#039;t fix the &quot;where&#039;s the any key!?!?&quot; problem.)</description>
		<content:encoded><![CDATA[<p>@goodpeople &#8211; &#8220;A Cookie&#8221;</p>
<p>I find it fascinating that a number of older people &#8211; among them security researchers and pentesters, all remember this stuff with glee from back when they were behaving like juvenile delinquents. Plus la change, plus la meme chose&#8230; (Yes, I mangled that, but I don&#8217;t have bindings for French characters on my keyboard&#8230;.Unicode doesn&#8217;t fix the &#8220;where&#8217;s the any key!?!?&#8221; problem.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: goodpeople</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100444</link>
		<dc:creator>goodpeople</dc:creator>
		<pubDate>Sun, 20 Jan 2008 12:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100444</guid>
		<description>My best memories lie with the cookiemonster virus...

.. can I have a cookie?</description>
		<content:encoded><![CDATA[<p>My best memories lie with the cookiemonster virus&#8230;</p>
<p>.. can I have a cookie?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody_Holme</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100014</link>
		<dc:creator>Nobody_Holme</dc:creator>
		<pubDate>Sat, 19 Jan 2008 13:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-100014</guid>
		<description>Anything oldskool DOS needs some re-writing to make it work these days... 
Ping-pong virus.... The memories!</description>
		<content:encoded><![CDATA[<p>Anything oldskool DOS needs some re-writing to make it work these days&#8230;<br />
Ping-pong virus&#8230;. The memories!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mumble</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-99822</link>
		<dc:creator>mumble</dc:creator>
		<pubDate>Sat, 19 Jan 2008 03:14:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-99822</guid>
		<description>Does anyone else remember the ping-pong virus?

The scary thing is that I might still have a copy bouncing around. That beast was written in simon-pure assembly, and the size was measured in bytes....</description>
		<content:encoded><![CDATA[<p>Does anyone else remember the ping-pong virus?</p>
<p>The scary thing is that I might still have a copy bouncing around. That beast was written in simon-pure assembly, and the size was measured in bytes&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-99771</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Sat, 19 Jan 2008 00:37:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-99771</guid>
		<description>@ mumble

Better watch out Leisure Suit Larry is also making his return ;)

Indeed some antiviral packages are oblivious to very old attack vectors, they have become very concerned with spam/scam/phish and blocking content that they haev forgotten about old skool technique&#039;s
(.. stumbles through a pile of old 5 1/4&quot; floppies looking for an MBR infecting proogy from the darkages, darn, the C2D is too fast to do old style DOS progs (or cmd is too limited)</description>
		<content:encoded><![CDATA[<p>@ mumble</p>
<p>Better watch out Leisure Suit Larry is also making his return <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Indeed some antiviral packages are oblivious to very old attack vectors, they have become very concerned with spam/scam/phish and blocking content that they haev forgotten about old skool technique&#8217;s<br />
(.. stumbles through a pile of old 5 1/4&#8243; floppies looking for an MBR infecting proogy from the darkages, darn, the C2D is too fast to do old style DOS progs (or cmd is too limited)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody_Holme</title>
		<link>http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-99666</link>
		<dc:creator>Nobody_Holme</dc:creator>
		<pubDate>Fri, 18 Jan 2008 17:17:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/new-rootkits-infecting-the-mbr/#comment-99666</guid>
		<description>Good good... *feels happy and safe*

who wants to bet i get owned in about 5 minutes now?</description>
		<content:encoded><![CDATA[<p>Good good&#8230; *feels happy and safe*</p>
<p>who wants to bet i get owned in about 5 minutes now?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
