Thank you for this video, it was very informative. I appreciate your taking time to do these videos and hope you will continue to do so in the future.
I always knew that such a 'kit would be feasable, especially when hard drives got big enough that they could stand to lose a couple of sectors at random. In theory you could run a completely undetectable old-skool boot virus if you used direct transfer to the hard drive controller, bypassing the comps interrupts.
Not a job for script kiddies though, you'd have to be bloody good not to blow up your target PCs. Trouble is, the bad guys are getting that professional. Scary to see SF come true!
I've been thinking about how they would do that efficiently myself since I first heard about it a bit back as well. I found it would take me slightly under 5 months to develop the injection platform, although it would be very unstable..
Surprised not to see a lot more botnet activity as well, it seems that attacks have become a lot more malicious in past few months than they have been in the past.
Possibly the Tibet issue has sparked something unusual in the malicious world.
whats with the security lights and tape, is that so people dont connect any usb sticks to any of the test pc's while theyre infected?
Younowkoed 2 years ago
Nice informative videos you're made mikko.
hnhassansunny 2 years ago
F-secure Internet security 2009 Rules!
informative video indeed.
canonpowershotseries 3 years ago
Mikko,
Thank you for this video, it was very informative. I appreciate your taking time to do these videos and hope you will continue to do so in the future.
kanopinay 3 years ago
Windows X64 Can use GUID too. And EFI. But there are few EFI motherboards.
drivojulianrobotnik 3 years ago
The MBR Rootkit wont effect systems with EFI. So for example, mac hardware wont die as they use GUID, not the old MBR.
drivojulianrobotnik 3 years ago
I always knew that such a 'kit would be feasable, especially when hard drives got big enough that they could stand to lose a couple of sectors at random. In theory you could run a completely undetectable old-skool boot virus if you used direct transfer to the hard drive controller, bypassing the comps interrupts.
Not a job for script kiddies though, you'd have to be bloody good not to blow up your target PCs. Trouble is, the bad guys are getting that professional. Scary to see SF come true!
badnewswade 3 years ago
Jesus, Mikko is STILL HOT!
I think I might have to start cyberstalking him or something :-p
badnewswade 3 years ago
MBR attacks aye?
I've been thinking about how they would do that efficiently myself since I first heard about it a bit back as well. I found it would take me slightly under 5 months to develop the injection platform, although it would be very unstable..
Surprised not to see a lot more botnet activity as well, it seems that attacks have become a lot more malicious in past few months than they have been in the past.
Possibly the Tibet issue has sparked something unusual in the malicious world.
70k0 3 years ago
Mikko, this was awesome, thanks!
danstrator 3 years ago 2