<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Beyond Rootkits: World&#8217;s First Standalone Kernel Mode Bot?</title>
	<link>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/</link>
	<description>Spam, Security, Privacy, Spyware, Phishing &#038; Viruses from the Front Lines.</description>
	<pubDate>Wed, 17 Mar 2010 23:16:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: Anubis</title>
		<link>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-1530</link>
		<pubDate>Wed, 06 Sep 2006 21:09:45 +0000</pubDate>
		<guid>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-1530</guid>
					<description>You know whats funny is it sounds like you guys that commented above me have no clue of what you are talking about. First off, this will be no worse than any other rootkit out there. Now if he divised some new rootkit technology, like a new way to hook ntoskrnl.exe's services then yeah, i'd be impressed. Tibbar, he's a good developer, but this whole Kernel-Mode IRCBot is not a new concept. I wrote a Kernel-Mode driver that exploited a remote windows system service to download the driver to the remote machine and run it. If I had released this into the wild there would be much more damage(possible) than your normal virus or worm. Rootkits(kernel drivers) have a much higher level of privileges, and my driver would do *anything* i wanted it to.  It would not be restrained to the currently running user context.</description>
		<content:encoded><![CDATA[<p>You know whats funny is it sounds like you guys that commented above me have no clue of what you are talking about. First off, this will be no worse than any other rootkit out there. Now if he divised some new rootkit technology, like a new way to hook ntoskrnl.exe&#8217;s services then yeah, i&#8217;d be impressed. Tibbar, he&#8217;s a good developer, but this whole Kernel-Mode IRCBot is not a new concept. I wrote a Kernel-Mode driver that exploited a remote windows system service to download the driver to the remote machine and run it. If I had released this into the wild there would be much more damage(possible) than your normal virus or worm. Rootkits(kernel drivers) have a much higher level of privileges, and my driver would do *anything* i wanted it to.  It would not be restrained to the currently running user context.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: myrdd1n</title>
		<link>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-662</link>
		<pubDate>Mon, 10 Apr 2006 06:54:10 +0000</pubDate>
		<guid>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-662</guid>
					<description>@weedougie&lt;br&gt; That is why something like this will never become a commercial product.&lt;br&gt; The source will leak, and people who actually have a clue will start compiling and distributing to unsuspectng user's computers.&lt;br&gt; I foresee an entire new breed of botnets. This new IRCBot gets major brownie points because it will most likely be undetectable by most of today's Anti Virus software.</description>
		<content:encoded><![CDATA[<p>@weedougie<br /> That is why something like this will never become a commercial product.<br /> The source will leak, and people who actually have a clue will start compiling and distributing to unsuspectng user&#8217;s computers.<br /> I foresee an entire new breed of botnets. This new IRCBot gets major brownie points because it will most likely be undetectable by most of today&#8217;s Anti Virus software.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: weedougie</title>
		<link>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-661</link>
		<pubDate>Sun, 09 Apr 2006 07:26:17 +0000</pubDate>
		<guid>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-661</guid>
					<description>Having read what it is supposed to do it appears to me to breach the European Human Rights Act in so much as it violates the right of privacy in your home and family life. If this becomes commercial who will be the first to take whoever to court?</description>
		<content:encoded><![CDATA[<p>Having read what it is supposed to do it appears to me to breach the European Human Rights Act in so much as it violates the right of privacy in your home and family life. If this becomes commercial who will be the first to take whoever to court?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Eligah Underwood (Rife)</title>
		<link>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-660</link>
		<pubDate>Fri, 07 Apr 2006 08:07:12 +0000</pubDate>
		<guid>http://www.emailbattles.com/2006/04/07/virus_aaddcefedj_d/#comment-660</guid>
					<description>Very interesting - it'll be even more intresting to see a functional animal once in the wild! &lt;br&gt; &lt;br&gt; Only down side I can see - is now my rootkit books are out of date! :)&lt;br&gt; &lt;br&gt; [BTW - is the question Base10?]</description>
		<content:encoded><![CDATA[<p>Very interesting - it&#8217;ll be even more intresting to see a functional animal once in the wild! </p>
<p> Only down side I can see - is now my rootkit books are out of date! <img src='http://www.emailbattles.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p> [BTW - is the question Base10?]
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
