<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Wed, 04 Jul 2007 15:05:12 -0000</lastBuildDate><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322862</link><description>Is anyone else as excited for blackhat this year as any in recent history?  I'm looking forward to this showdown!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nathan McFeters</dc:creator><pubDate>Wed, 04 Jul 2007 15:05:12 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322861</link><description>No, Joanna's rootkit doesn't persist itself.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Mon, 02 Jul 2007 12:28:39 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322860</link><description>Does the rootkit have to be persistent?  Can the system BIOS be write protected?&lt;br&gt;&lt;br&gt;If so, there is always Yi Min Wang's Ghostbuster trick from Microsoft Research.&lt;br&gt;&lt;br&gt;Persistent stealthy rootkits, in the face of a defender who can reboot the system and has a trusted BIOS and trusted media, are always detectible, unless the rootkit author solves the program-intent-detection problem (aka, the AV version of the Halting problem), gives up on stealth (not a rootkit), or gives up on persistent (reboot clears rootkit)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nicholas Weaver</dc:creator><pubDate>Mon, 02 Jul 2007 00:35:21 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322859</link><description>I'm assuming it's Vista, but don't have a strong opinion.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 28 Jun 2007 20:14:05 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322858</link><description>Will you agree on an OS to use? XP? Vista?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Technocrat</dc:creator><pubDate>Thu, 28 Jun 2007 18:10:59 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322857</link><description>I don't think having our source code is going to help her make Blue Pill less detectable, even in the medium-short term. &lt;br&gt;&lt;br&gt;What I do like is, "you can't peg the CPU for more than a second because it will be a drag for users". Like the performance cost of having SVM/VTX enabled isn't?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 28 Jun 2007 17:08:04 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322856</link><description>I've posted my response to Joanna &lt;a href="http://rdist.root.org/2007/06/28/undetectable-hypervisor-rootkit-challenge/" rel="nofollow"&gt;here&lt;/a&gt;.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nate</dc:creator><pubDate>Thu, 28 Jun 2007 14:59:55 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322855</link><description>Yeah, and she wants you to find sponsors to pay her $384,000 so she can play!  Six months, two developers @ $200/hr per developer to develop blue pill = lame.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">one.miguel</dc:creator><pubDate>Thu, 28 Jun 2007 14:19:52 -0000</pubDate></item><item><title>Re: Joanna: We Can Detect BluePill. Let Us Prove It!</title><link>http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/#comment-2322854</link><description>Looks like Joanna has turned the contest around and given you the short straw, haha. Her blog post pretty much says that it's not even half finished so of course you'll be able to detect it with all your fancy timing tricks. Not to mention she'll get the source code to these tricks after the competition and it's not like you don't already have a similar rootkit so you don't get much out of that transaction.&lt;br&gt;&lt;br&gt;This is interesting indeed!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Fionnbharr Davies</dc:creator><pubDate>Thu, 28 Jun 2007 10:26:57 -0000</pubDate></item></channel></rss>