VnutZ Domain
Copyright © 1996 - 2018 [Matthew Vea] - All Rights Reserved

2008-05-16
Featured Article

System Management Mode Rootkit Innovation

[index] [2,065 page views]

System Management Mode (SMM) is an often overlooked operating state featured on Intel processors since the 80386. It existed to simplify debugging system code (whether operating system or even firmware) which was previously debugged using an In Circuit Emulator (ICE). System Management Mode allows select software to run completely independent of the running operating system and was intended for both debugging and allowing advanced power management software to execute. The ability to operate outside of the operating system's jurisdiction of control and security monitoring has been the focus of rootkit research by Clear Hat Consulting. By operating a rootkit from within System Management Mode, the software will be undetectable by scanners and does not even require the modification of any core files to exist. While operating within System Management Mode, code can browse through the processing state tables in order to read or write to any desired location within the running, albeit suspended, operating system. A to the host it resides in while allowing an external hacker complete, stealthy access to the compromised host.


More VnutZ.com Content You Might Be Interested In Reading:

Just a simple pondering of whether or not time travel implies fate and defies free will.

Or try your hand at fate - use the Pattern Analysis of the MegaMillions Lottery or the Pattern Analysis of the PowerBall Lottery page to pick "smarter" numbers. Remember, you don't have to win the jackpot to win money from the lottery!

coinbase