Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: InfoSec Handlers Diary Blog - New paper on using kernel hooking to bypass AV InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

New paper on using kernel hooking to bypass AV

Published: 2010-05-10
Last Updated: 2010-05-10 23:00:16 UTC
by Toby Kohlenberg (Version: 1)
2 comment(s)

Matousec has released a new paper (http://www.matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php)detailing their proof of concept for using kernel hooking (specifically what they are calling an "argument switch attack") to bypass antivirus software. The concept isn't new, as they acknowledge but the paper is nicely detailed and the use of a race condition of sorts to bypass security checks made when a kernel hook is requested/handled is cool. It should be noted that PatchGuard should provide some protection against this attack though how much is uncertain.

Keywords:
2 comment(s)
Diary Archives