Re: Re:How To Suspend Thread In Kernel?
- From: "Skywing" <skywing_NO_SPAM_@xxxxxxxxxxxxxxxxxxx>
- Date: Wed, 29 Mar 2006 11:36:23 -0500
It's still just providing an illusion of security through layers of
obscurity.
BTW, antipiracy system != protecting the system from hostile kernel mode
code.
"Scherbina Vladimir" <vladimir.scherbina@xxxxxxxxxxxx> wrote in message
news:u%23Ena4zUGHA.3192@xxxxxxxxxxxxxxxxxxxxxxx
Hello Skywing,
"Skywing" <skywing_NO_SPAM_@xxxxxxxxxxxxxxxxxxx> wrote in message
news:ObcWyxzUGHA.2276@xxxxxxxxxxxxxxxxxxxxxxx
Yes, it does - you can try to make it harder, but the fact of the matter
is, a determined and clever attacker will be able to bypass your
protection schemes and do what they want if they can run code in kernel
mode. It is a simple matter of kernel mode code having unrestricted
access to hardware - part of the core OS design.
correct, all depends on expirience and thus you can't be sure that your
running code in k.m. gives you absolute power, "all is relative".
The only sane course of action after detecting a kernel mode compromise
is a complete rebuild of the box. Saying you can mitigate arbitrary code
being run in kernel mode is only kidding yourself into a false sense of
security, IMO.
http://www.star-force.com/ - a well-know company that intensivly uses
kernel mode protection components, as I said few month ago (AFAIR to you?)
there are a *few* of men in the world that broke their system
--
Vladimir
http://spaces.msn.com/vladimir-scherbina/
.
- Follow-Ups:
- Re: Re:How To Suspend Thread In Kernel?
- From: Scherbina Vladimir
- Re: Re:How To Suspend Thread In Kernel?
- References:
- Re: Re:How To Suspend Thread In Kernel?
- From: Skywing
- Re: Re:How To Suspend Thread In Kernel?
- From: anton bassov
- Re: Re:How To Suspend Thread In Kernel?
- From: Skywing
- Re: Re:How To Suspend Thread In Kernel?
- From: Scherbina Vladimir
- Re: Re:How To Suspend Thread In Kernel?
- From: Skywing
- Re: Re:How To Suspend Thread In Kernel?
- From: Scherbina Vladimir
- Re: Re:How To Suspend Thread In Kernel?
- Prev by Date: Re: COM sample programs
- Next by Date: Re: Re:How To Suspend Thread In Kernel?
- Previous by thread: Re: Re:How To Suspend Thread In Kernel?
- Next by thread: Re: Re:How To Suspend Thread In Kernel?
- Index(es):
Relevant Pages
|