Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

100 percent undetectable rootkit

Featured Replies

i don't beleive this one little bit... because u would think that a data recovery tool would help find this file...

"The idea behind Blue Pill is simple: your operating system swallows the Blue Pill and it awakes inside the Matrix controlled by the ultra thin Blue Pill hypervisor. This all happens on-the-fly (i.e. without restarting the system) and there is no performance penalty and all the devices," she explained.

Seems like it's a new variant of MDMA, like extasy.

++

i actually don't think this will end up being that revolutionary.

AV heuristics in the future will likely have an option to monitor virtualization, just as there are options now to restrict registry activity and scripts within documents.

though it may be undetectable once it's installed, the process of installation and the installer executable itself will certainly give it away.

Edited by Nazi Moderation

From an academic standpoint, it is true that the OS itself wouldn't be able to detect the rootkit planted from the hypervisor.

However, from a practical standpoint, it will still be possible to detect the presence of an unrecognized (and therefore suspicious) hypervisor.

How? Well obviously it's possible for the installation of a hypervisor to be started from within the OS. That's how the Blue Pill would get installed in the first place. Therefore, it would be possible to launch the installation of a second hypervisor from within the same OS. Now either the first hypervisor (the Blue Pill in this case) will block the installation of the second, in which case you will know something is wrong, or the second hypervisor will succeed and become capable of detecting the rootkit.

With this in mind, the second hypervisor doesn't actually need to be a full-fledged permanently-installed hypervisor. It just needs to go through the same motions that a hypervisor installation would go through. Therefore, antimalware programs could include an "agent" or module which performs this task as part of every scan. This wouldn't be trivial for the major vendors to add, but still possible.

Hmm...the virus reminds me of the movie "The Matrix" for some reason...dunno why though.

Hmm...the virus reminds me of the movie "The Matrix" for some reason...dunno why though.
Same thought here... :lol:

She also published the "Red Pill". ;)

1- yes, she !

2- it is probably serious. imho the main reason it should not work is some rights should be needed to use virtualization.

thats not entirely true, as Kernel mode (run as system service) oculd also do the trick... a simple jepeg bug could than be Extremely Critical ....

one way of prenting this COULD be lying in the UEFI (if im correct) standard.

for example it could be possible to tell the BIOS chip how many Vertial Instances the cpu is allowed to handle....

even though this may require a reboot with every new-installed OS-instance

it would help...

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.