A
arachnid
A much hyped scare or not?
I don't think so. The article also points out that the concept isn't
entirely new and others have created similar rootkits. Here's the "Blue
Pill" article:
http://www.eweek.com/article2/0,1895,1983037,00.asp
Aside from what I've already said, it says this:
"...The idea of a virtual machine rootkit isn't entirely new. Researchers
at Microsoft Research and the University of Michigan have created a
VM-based rootkit called "SubVirt" that is nearly impossible to detect
because its state cannot be accessed by security software running in the
target system."
I see I had it wrong on the target OS. The prototype has been tested on a
Vista beta and is targeted at Vista, not XP.
Whatever, somehow I feel that I'm not gonna loose a night's sleep over
that, for a while.
I don't much worry about it because I check my systems using a bootable
CD. That way the OS doing the checking runs independently of whatever's on
the hard drive. However it's going to be a real PITA for users in general.