Rutkowska releases code for New Blue Pill rootkit
Posted by: Dennis Fisher
Joanna Rutkowska has released the source code for a new version of her Blue Pill hypervisor rootkit. The updated software was written mostly by her collaborator Alexander Tereshkin and New Blue Pill is quite different from the original version, she says. New Blue Pill, which the two researchers described in their presentation at Black Hat on Wednesday, is based on a hardware virtual machine approach, and has a number of unique features:
- A common HVM layer to enable future support for Intel’s VT-x virtualization technology and software virtual machines
- The ability to load and unload on the fly
- RDTSC cheating via tracing
- The ability to avoid trusted time source attacks
- Private page tables
- Support for nested hypervisors
Rutkowska and Tereshkin released the code on Wednesday, the same day that a team of security researchers led by Tom Ptacek of Matasano Security and Nate Lawson of Root Labs gave a talk outlining a number of practical methods for reliably detecting hypervisor rootkits such as Blue Pill. But that was the previous version of Blue Pill. It’s a fair bet that Ptacek, Lawson, Dino Dai Zovi and other researchers around the world will be tearing the New Blue Pill code apart in the coming days, as the attacker-defender carousel continues.



You must be logged-in to post a comment. Log-in/Register