Dailydave mailing list archives

Re: Nitin Kumar & Vipin Kumar: "please remember to give, necessary credit to the authors" PKB.


From: Vipin Kumar <listuser () nvlabs in>
Date: Fri, 27 Apr 2007 12:25:48 +0530

First of all,
           let me introduce myself.
           i am one of the vbootkit author.
           
VBOOTKIT source code was NEVER released !!!!! then how can someone
compare it ????

Secondly, this( bootkit / bootroot discussion) has been previously
discussed with derek soeder(author of bootroot eEye) himself.
here are the few lines cut from the discussion.
You can access the whole discussion at
http://www.rootkit.com/board.php?did=edge614
 
 
-----------------------------------------------------------------------------
 This comment was done by him, after proofs were delivered to him.
 
 
 Not vaporware! But at least partially plagiarized.
(by dereksoeder () Nov 27 2006, 18:10 (UTC+5:30) )

Great work! Sorry for doubting you, and thanks for making the code
available.

------------------------------------------------------------------------------
 Re: Not vaporware! But at least partially plagiarized.
(by nitinkumar (Normal user) Nov 29 2006, 14:21 (UTC+5:30) )

Mr. Soeder,

The BOOTKIT functions more like your BOOTROOT version 2.0 whose source
has not been released by you!!!!

I am once quoting words "..CREDIT is definitely due .."

Moreover, what about the rest 95% stuff in the bootkit.!!!!

Moreover, we are honest.This is shown by the fact that necessary
information such as directory listing was shown in just abt an hour,
after your first post.Therefore, leaving the tendency for making it in hand.

----------------------------------------------------------------------------------------


as far as (Dave Korn's) comment goes "I wondered what was so special
about this that wasn't already
demonstrated by Derek and Ryan from eEye two years ago."

here are the points
  1) Vista was not released 2 years back.
  2) haven't you heard about whole new vista boot process and the
different protections implemented,( there was no security in previous
versions).in previous versions, the ntldr did everything,but in case of
vista there is boot manager,windows loader etc
 
 
 also, 1 more question (for Dave Korn)
 can you suggest any more methods except hooking INT 13 to capture Disk
Request at such level ??
 
 
 I think this will clear the stand.
 
regards,
vipin
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: