Rutkowska releases code for New Blue Pill rootkit - Security Bytes
» VIEW ALL POSTS Aug 2 2007   3:05PM GMT

Rutkowska releases code for New Blue Pill rootkit



Posted by: Dennis Fisher
Information Security Threats, Platform Security

Joanna Rutkowska has released the source code for a new version of her Blue Pill hypervisor rootkit. The updated software was written mostly by her collaborator Alexander Tereshkin and New Blue Pill is quite different from the original version, she says. New Blue Pill, which the two researchers described in their presentation at Black Hat on Wednesday, is based on a hardware virtual machine approach, and has a number of unique features:

  • A common HVM layer to enable future support for Intel’s VT-x virtualization technology and software virtual machines
  • The ability to load and unload on the fly
  • RDTSC cheating via tracing
  • The ability to avoid trusted time source attacks
  • Private page tables
  • Support for nested hypervisors

Rutkowska and Tereshkin released the code on Wednesday, the same day that a team of security researchers led by Tom Ptacek of Matasano Security and Nate Lawson of Root Labs gave a talk outlining a number of practical methods for reliably detecting hypervisor rootkits such as Blue Pill. But that was the previous version of Blue Pill. It’s a fair bet that Ptacek, Lawson, Dino Dai Zovi and other researchers around the world will be tearing the New Blue Pill code apart in the coming days, as the attacker-defender carousel continues.

Technorati Tags: , , ,

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Alain G  |   Aug 3 2007   1:48PM GMT

Rutkowska will always be one step ahead until the day she “hops off” the “attacker-defender carousel” and let the defenders “catch up”…