Top Security News

Spammer Growth Rate Highest Ever
Spammers are stepping up their efforts as the "industry" recovers from the loss of McColo, a web hosting company whose clients generated some 75% of the spam...

Setting Up A Security Plan For Your Enterpirse
A plan to ensure the security of the organization's assets. Contents Organization and Administration Security Procedures Include such things as references...

Implementing Cost Cutting Without Under-Utilizing...
In these uncertain economic times, businesses are being forced to implement crucial cost-cutting measures...

04.22.09

Tool Developed To Hide Malware Within .NET

By Daniele Salatti

Most windows based modern computers come with the .NET Framework installed, so a security flaw in it could be a very dangerous threat - think to Conficker (and, by the way: take a look here and check if you are infected, then move to Linux or buy a Mac).

So, suppose you are a cracker (because hackers don't do such a thing - stop watching those stupid movies) and you find a way to attack the .NET Framework itself. It's an interesting attack vector, a part of the OS that isn't usually targeted.


It gives you a good protection against antivirus software, your piece of malicius code is not likely to be found and you can expect that almost all Windows computers will have the .NET Framework installed.

Thanks to the work of a security researcher now it's possible to execute application level rootkit attacks on the .NET Framework, thus enabling an attacker to hide malicious code inside its core. More on this and a PoC (Proof of Concept) can be found here.

Comments


About the Author:
Daniele Salatti is a 23 years old Italian guy. Informatic Engineering student at the University of Pisa, he is a passionate Linux user. Check out his blog at Salatti.net.
About EnterpriseSecurityNews
Security news and updates for your enterprise





EnterpriseSecurityNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITmanagementNews.com






-- EnterpriseSecurityNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2009 iEntry, Inc. All Rights Reserved Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Enterprise Security News News Archives About Us Feedback EnterpriseSecurityNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact