Free utility tool circumvents Vista kernel defenses

July 30, 2007

Free utility tool circumvents Vista kernel defensesThe security defenses put in place by Microsoft to protect its Windows Vista kernel from non-digitally-signed code can now be easily circumvented with the release of a free utility tool, according to researchers at Symantec.

A new software tool, named Atsiv, released by Australian developer LinchpinLabs, allows the loading of unsigned and legacy drivers into the kernel.

Microsoft earlier ruled out to accept and load only digitally-signed code into its Vista kernel. Drivers must be accompanied by a signed certificate from issuing authorities recognized by Microsoft before they can be loaded properly. However, this doesn’t limit users from loading unsigned or legacy driver under a limited functionality mode.

Ollie Whitehouse, an architect with Symantec’s advanced threats research team, disclosed that they were able to load unsigned code into the Vista kernel using Atsiv.

“[Atsiv's] command line tool loads [its own] appropriate driver, which then in turn allows loading of unsigned drivers due to the implementation of their PE loader,” Whitehouse told Computerworld.

However, in the course of using the tool, Atsiv failed to update the PsLoadedModuleslist to make the newly added unsigned driver visible in the standard drivers list.

“This is rootkit-type behavior,” said Whitehouse.

Whitehouse has suggested that the only way Microsoft can enforce the ban on unsigned kernel code is to revoke the certificate.

But whether or not Microsoft would revoke the certificate used by Atsiv, the big questions still remained. What keep hackers from creating Atsiv-like programs? What keep hackers from making their malicious code digitally sign?



Related Posts:

4 Responses to “Free utility tool circumvents Vista kernel defenses”

  1. nix:

    “What keep hackers from making their malicious code digitally sign?”

    Because they would have to be identified.

  2. Microsoft blocks Vista kernel hacking tool - VISTA.BLORGE.com:

    [...] company has blocked the application Atsiv which bypasses a security feature in the 64-bit version of Vista.  Under normal circumstances, [...]

  3. Purple Pill beats Windows Vista’s 64-bit driver authentication - VISTA.BLORGE.com:

    [...] that’s installed in 50 per cent of laptops, it cannot be address as easy as the case of Atsiv where Microsoft simply revoked LinchpinLabs’ certificate on Atsiv and issued a signature for [...]

  4. Microsoft tightens Vista kernel defenses, updates PatchGuard - VISTA.BLORGE.com:

    [...] Astiv utility bypasses this checking process by loading its own signed driver but then allows the installation of unsigned drivers to be loaded through its portable executable (PE) loader. Astiv digital certificate was later revoked upon the request of Microsoft and the company has released Windows defender updates to remove and block the threat. [...]

Leave a Reply:


Recent stories

Featured stories

Archives

Copyright © 2012 Blorge.com NS