Carberp Source Code Leaked
threatpost.com
threatpost.com
The code looks better than a lot of commercial kernel code of comparable complexity, and it is complex. From readme -
--
Bootkit is a driver for loading other drivers at the OS boot time. Driver is loaded before the initialization of NT kernel (i.e. before the start of the PatchGuard) and it can patch arbitrary kernel code. The driver gets launched before every other drivers, including the boot-time ones, and it can monitor and control their loading. No digital signature is required.Supported Windows versions - from XP to W8 inclusively.
Supported platforms - x86 and amd64.
Boot-loader works with all types of NTFS partitions.
The code is metamorphic, it consists of several blocks that are randomly rearranged with each build. The IPL (initial loader) code is encrypted and it is incrementally decrypted during the execution. Considered together, this means that each build of the bootkit is binary unique. The driver is also encrypted when stored on the disk and it is decrypted by IPL upon loading.
--
All in all, this is quite a leak. Very few people can code something like this and it's a unique chance to peek at and learn from their work.Sounds like we need another of Fabien Sanglard's source code reviews:) Normally I'd stay away from this sort of thing, but if it's a good as people say, I might have to check it out myself.
Of course, I agree with you completely wrt their morality.
As regular files (e.g. `cp ~/.gnupg/secring.gpg /media/kanguru/`) or can you somehow import them such as with a smart card?
I carry multiple devices at the moment but it would be nice to consolidate.
1 - Malware should be purged on shut down
2 - Only specific sites are accessed, e.g. banking domains, minimizing the risk of picking something up through e-mail or careless browsing.
3 - Obviously you shouldn't be running a server.
4 - You should still practice safe browsing, being aware of packet injection via public WiFi.
If you are being specifically targeted, that is another issue.
My point was that it's unlikely that you're dealing with malware so sophisticated that it can successfully corrupt any given OS disk image and/or fake-out a checksum verification on same -- and if it can, you're probably screwed anyway.
That's one little thing about HN -- most people are so literal, completely missing the point.
I'm sure that it's not (yet) possible to do that, although that would be a huge breakthrough. Imagine malware that could detect what (OS) is on the ISO image and inject itself into the files inside the ISO stealthily... all at run-time when you click the "burn this ISO to this CD" button.
Yeah, we'd just be screwed at that point.
So here are all the tabs I opened during my search instead.
http://www.kb.cert.org/vuls/id/649219
https://www.scmagazineus.com/Altor-Networks-Altor-VF/Review/...
https://www.juniper.net/us/en/products-services/software/sec...
http://news.cnet.com/8301-13846_3-10395695-62.html?tag=mncol...
http://www.itworld.com/security/80289/securing-your-virtual-...
http://www.symantec.com/connect/blogs/infographic-what-small...
A quick look at these shows them to be wholly not what I'm looking for. (And wholly unfit for HN I might add, which is where I got them.)
If anyone out there has a link to the vulnerability I'm thinking of (it was on HN at one point), or useful information on securing virtual machines against breakout malware, that would be awesome.
http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-pr...
http://www.vupen.com/blog/20120904.Advanced_Exploitation_of_...
Exploits are developed to break VMs, just like everything else, and are promptly patched once revealed. Apart from general intrusion detection tools, I think you would be hard pressed to find anything to guard against them.
Maybe run a VM inside another VM ;)
Otherwise it would make more sense to just run it themselves -- although that would of course expose them to [more] legal risk. Reminds me of bitcoin mining -- can you make more money selling ASIC miners or just mining BTC with the ones that you've built?
How many hours does it take a doctor to remove your appendix? Is that a relevant metric to judge or place a cost on?
Or, consider the average salary of a programmer with enough operating systems knowledge to write this.
But then, supply and demand is a strange thing.
But how it goes around the signature requirement of drivers is very clever.