funsec mailing list archives

Re: eWeek: Government-Funded Startup Blasts Rootkits


From: Technocrat <dj.technocrat.listmail () gmail com>
Date: Tue, 25 Apr 2006 09:45:07 -0500

How would this product handle VM malware. Such this isn't a huge
threat at this time...but it should be looked at.

http://www.eecs.umich.edu/virtual/papers/king06.pdf

I don't see any reason why a VM couldn't cloak a rootkit from a
PCI/Parallel OS device. Comments? Input?

IMHO, no detection method is foolproof and the "good guy" are
currently losing the cat and mouse game...perhaps this will give us
the step ahead for a short time.

-Technocrat

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: