<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet href="/templates/default/atom.css" type="text/css" ?>

<feed 
   xmlns="http://www.w3.org/2005/Atom"
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/">
    <link href="http://www.nvlabs.in/feeds/atom10.xml" rel="self" title="NVlabs | Analyzing Security" type="application/atom+xml" />
    <link href="http://www.nvlabs.in/"                        rel="alternate"    title="NVlabs | Analyzing Security" type="text/html" />
    <link href="http://www.nvlabs.in/rss.php?version=2.0"     rel="alternate"    title="NVlabs | Analyzing Security" type="application/rss+xml" />
    <title type="html">NVlabs | Analyzing Security</title>
    <subtitle type="html"></subtitle>
    <icon>http://www.nvlabs.in/templates/default/img/s9y_banner_small.png</icon>
    <id>http://www.nvlabs.in/</id>
    <updated>2009-05-07T06:18:17Z</updated>
    <generator uri="http://www.s9y.org/" version="1.3.1">Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <dc:language>en</dc:language>

    <entry>
        <link href="http://www.nvlabs.in/archives/8-Vbootkit-2.0-is-now-open-source-under-GPL-license.html" rel="alternate" title="Vbootkit 2.0 is now open-source ( under GPL license)" />
        <author>
            <name>Webmaster</name>
                    </author>
    
        <published>2009-05-07T05:47:32Z</published>
        <updated>2009-05-07T06:18:17Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=8</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=8</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/0-Vbootkit" label="Vbootkit" term="Vbootkit" />
    
        <id>http://www.nvlabs.in/archives/8-guid.html</id>
        <title type="html">Vbootkit 2.0 is now open-source ( under GPL license)</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                Vbootkit 2.0 has now been made open-source under GPL license.<br />
<br />
Vbootkit 2.0 currently only works on Windows 7 ( x64 edition ).<br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.zip" title="Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors source code &amp; binary download" target="_blank"><strong>Download Vbootkit 2.0 source code</strong></a> <br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.0-AttackingWindows7viaBootSectors.odp" title="Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors" target="_blank"><strong>Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors  presentation</strong></a>  
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/7-Hack-in-the-Box-Dubai-2009.html" rel="alternate" title="Hack-in-the-Box Dubai 2009" />
        <author>
            <name>Webmaster</name>
                    </author>
    
        <published>2009-03-04T15:49:26Z</published>
        <updated>2009-04-26T06:39:27Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=7</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=7</wfw:commentRss>
    
    
        <id>http://www.nvlabs.in/archives/7-guid.html</id>
        <title type="html">Hack-in-the-Box Dubai 2009</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <strong>Vbootkit 2.0: Attacking Windows 7 via Boot Sectors</strong><br />
<br />
This talk will introduce a new tool which allows attacks against Windows 7 via boot sectors. In this talk we will demo Vbootkit 2.0 in action and show how to bypass and circumvent security policies / architecture using customized boot sectors for Windows 7 (x64). The talk will cover:<br />
<br />
() Windows 7 Boot architecture<br />
() Vbootkit 2.0 architecture and inner workings<br />
() insight into the Windows 7 minkernel<br />
<br />
We will also demonstrate:<br />
<br />
() The use of Vbootkit in gaining access to a system without leaving traces<br />
() Leveraging normal programs to escalate system privileges<br />
() Running unsigned code in kernel<br />
() Remote command &amp; Control<br />
<br />
All this is done, without having any footprint on the HDD (everything is in memory). It also remains invisible to all existing anti-virus solutions.<br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.0-AttackingWindows7viaBootSectors.odp" title="Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors" target="_blank"><strong>Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors</strong></a>  
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/1-NVbit-Accessing-Bitlocker-volumes-from-linux.html" rel="alternate" title="NVbit :  Accessing Bitlocker volumes from linux" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <published>2008-05-19T11:20:00Z</published>
        <updated>2008-09-25T10:37:48Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=1</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=1</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/3-Bitlocker" label="Bitlocker" term="Bitlocker" />
    
        <id>http://www.nvlabs.in/archives/1-guid.html</id>
        <title type="html">NVbit :  Accessing Bitlocker volumes from linux</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <p>This projects details the Internals/Implementaion of  BitLocker Encryption system for Vista.</p><br />
<p>   NVbit is a linux  fuse driver to access Windows Vista's Bitlocker Volumes from linux, provided you have the right keys.A white-paper and supporting presentation is also available.The research was done around an year ago.Work was stopped prematurely,Don't expect things in clean/finished shape.The code is in alpha state.<br />
Both the paper and presentation are incomplete draft versions. However, missing things can be referred from nvbit source code.NVbit allows read-only access.(Though writing can be done just in reverse order but still it doesn't exist for now).</p><br />
 <a href="http://www.nvlabs.in/uploads/projects/nvbit/nvbit.zip" title="nvbit.zip" target="_blank"><strong>NVbit  source sode</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/nvbit/nvbit_bitlocker_presentation.pdf" title="nvbit_bitlocker_presentation.pdf" target="_blank"><strong>NVbit Bitlocker presentation</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/nvbit/nvbit_bitlocker_white_paper.pdf" title="nvbit_bitlocker_white_paper.pdf" target="_blank"><strong>NVbit Bitlocker white_paper</strong></a>  
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/2-0wning-Vista-from-the-boot-interview-at-SecurityFocus.html" rel="alternate" title="&quot;0wning Vista from the boot&quot;  interview at SecurityFocus" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <published>2007-04-26T17:14:00Z</published>
        <updated>2008-09-25T10:40:23Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=2</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=2</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/0-Vbootkit" label="Vbootkit" term="Vbootkit" />
    
        <id>http://www.nvlabs.in/archives/2-guid.html</id>
        <title type="html">&quot;0wning Vista from the boot&quot;  interview at SecurityFocus</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                    <p><strong>What is Vbootkit?</strong></p><br />
<strong>Nitin &amp; Vipin:</strong> Vbootkit is much like a door or a shortcut to access vista's kernel.<br /><br />
<p>A bootkit is a rootkit that is able to load from a boot-sectors (master<br />
boot record, CD , PXE , floppies etc) and persist in memory all the way<br />
through the transition to protected mode and the startup of the OS.</p><br />
<p><a title="http://www.securityfocus.com/columnists/442" href="http://www.securityfocus.com/columnists/442">http://www.securityfocus.com/columnists/442</a></p><br />
 
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/3-Black-Hat-Europe-2007-HITB-Conf.-2007.html" rel="alternate" title="Black Hat Europe 2007 &amp; HITB Conf. 2007" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <published>2007-04-12T15:39:00Z</published>
        <updated>2008-09-25T10:41:38Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=3</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=3</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/0-Vbootkit" label="Vbootkit" term="Vbootkit" />
    
        <id>http://www.nvlabs.in/archives/3-guid.html</id>
        <title type="html">Black Hat Europe 2007 &amp; HITB Conf. 2007</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                    <p><strong>Vbootkit White-paper and presentation materials</strong></p><br />
<p>The vbootkit white-paper and presentation slides are now online and can be downloaded  below.</p><br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit.ppt" title="nitin_vipin_vista_vbootkit.ppt" target="_blank"><strong>Vbootkit Presentation</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit/vbootkit_nitin_vipin_whitepaper.pdf" title="vbootkit_nitin_vipin_whitepaper.pdf" target="_blank"><strong>Vbootkit White Paper</strong></a><br />
<br />
 
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/4-Vbootkit-in-action-screenshots-and-videos.html" rel="alternate" title="Vbootkit in action  : screenshots and videos" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <published>2007-04-11T09:39:00Z</published>
        <updated>2008-09-26T05:01:52Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=4</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=4</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/0-Vbootkit" label="Vbootkit" term="Vbootkit" />
    
        <id>http://www.nvlabs.in/archives/4-guid.html</id>
        <title type="html">Vbootkit in action  : screenshots and videos</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <table width="100%25"><br />
<TD align="CENTER"  ><br />
<a class='serendipity_image_link' href='http://www.nvlabs.in/uploads/projects/vbootkit/screen_bootmgr.JPG' onclick="F1 = window.open('/uploads/projects/vbootkit/screen_bootmgr.JPG','Zoom','height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes'); return false;"><!-- s9ymdb:15 --><img class="serendipity_image_right" width="150" height="110" style="float: right; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_bootmgr.thumbnail.nvlabs.JPG" alt="Vbootkit in action at BootMgr (Windows Vista Boot Manager)" /></a><br />
<br />
<br />
</td><br />
<TD align="CENTER"><br />
<br />
<a class='serendipity_image_link' href='http://www.nvlabs.in/uploads/projects/vbootkit/screen_system_cmd.jpg' onclick="F1 = window.open('/uploads/projects/vbootkit/screen_system_cmd.jpg','Zoom','height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes'); return false;"><!-- s9ymdb:15 --><img class="serendipity_image_right" width="150" height="110" style="float: right; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_system_cmd.thumbnail.nvlabs.jpg" alt="Windows Vista CMD.exe screenshot privilege escalation" /></a><br />
</td><br />
<TD align="CENTER"><br />
<br />
<a class='serendipity_image_link' href='http://www.nvlabs.in/uploads/projects/vbootkit/screen_system_procexp.jpg' onclick="F1 = window.open('/uploads/projects/vbootkit/screen_system_procexp.jpg','Zoom','height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes'); return false;"><!-- s9ymdb:16 --><img class="serendipity_image_right" width="150" height="110" style="float: right; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_system.thumbnail.nvlabs.jpg" alt="Process explorer  showing TCB Trusted Computing Base" /></a><br />
</td><br />
</table><br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit_poc_RC1_edited_video.avi" title="Vbootkit POC in action on Vista RC1" target="_blank"><strong>nitin_vipin_vista_vbootkit_poc_RC1_edited_video.avi</strong></a><br/><a href="http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit_poc_RC2_video.avi" title="Vbootkit POC in action on Vista RC2" target="_blank"><strong>nitin_vipin_vista_vbootkit_poc_RC2_video.avi</strong></a> 
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/5-BOOT-KIT-Custom-boot-sector-based-Windows-2000XP2003-Subversion.html" rel="alternate" title="BOOT KIT: Custom boot sector based Windows 2000/XP/2003 Subversion" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <published>2007-02-04T15:18:00Z</published>
        <updated>2008-09-25T10:45:56Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=5</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=5</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/1-Projects" label="Projects" term="Projects" />
    
        <id>http://www.nvlabs.in/archives/5-guid.html</id>
        <title type="html">BOOT KIT: Custom boot sector based Windows 2000/XP/2003 Subversion</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <p>BOOT KIT is a project related to custom boot sector code subverting<br />
Windows NT Security Model.The sample presented currently keeps on<br />
escalating cmd.exe to system privileges every 30 secs.</p><br />
<p>It has several features</p><ol><li>It's very small.The basic framework is just about 100 lines of assembly code.It supports 2000,XP,2003</li><li>It patches the kernel at runtime(no files are patched on disk).</li><li>BOOT KIT is PXE-compatible.</li><li>It can even lead to first ever PXE virus</li><li>It also enables you to load other root kits if you have physical<br />
access(Normally root kits can only be loaded by the administrator</li></ol><br />
<p>The bootkit has been tested with a number of kernel mode shell codes such as Loading Native Applications and drivers from the shell code<br /><br />
another shellcode ,which periodically raises every CMD.EXE to system privileges.</p><br />
<p>The Source code will contain 4 levels of BOOT KITs(showcasing different payloads)</p><ol><li>Basic framework ( Kernel patching has to be done later on)  ( available for download )</li><li>Privilege escalation framework(demonstrates creating new system<br />
threads and how to escalate privileges easily) (available for download)</li><li>Loading drivers and native applications from kernel mode without touching registry</li><li>PXE compatible code(Basic framework).</li></ol><a href="http://www.nvlabs.in/uploads/projects/bootkit/bootkitbasic.zip" title="bootkitbasic.zip" target="_blank"><strong>Bootkit Basic framework Source Code</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/bootkit/bootkitprivilege.zip" title="bootkitprivilege.zip" target="_blank"><strong>Boot Kit Advance Version(support Privilege escalation) Source Code</strong></a> 
            </div>
        </content>
        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html" rel="alternate" title="Loading drivers and Native applications from kernel mode, without touching registry" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <published>2007-02-01T17:12:00Z</published>
        <updated>2008-09-25T10:50:16Z</updated>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=6</wfw:comment>
    
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom1.0&amp;type=comments&amp;cid=6</wfw:commentRss>
    
            <category scheme="http://www.nvlabs.in/categories/0-Vbootkit" label="Vbootkit" term="Vbootkit" />
    
        <id>http://www.nvlabs.in/archives/6-guid.html</id>
        <title type="html">Loading drivers and Native applications from kernel mode, without touching registry</title>
        <content type="xhtml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                    &quot;How to load driver without touching registry from kernel mode&quot;, this is asked almost always.Today, <br />
I will give you an insight into how Windows loads its driver and then will document a new method to load a driver without touching registry.</p><br />
<p>This is required because even if you exploit kernel vulnerabilities, you still cannot load any driver because almost all existing Antivirus solutions hijack the NTOSkrnl API's ( which let you write to specific registry locations, load drivers etc).</p><br />
 <br /><a href="http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html#extended">Continue reading "Loading drivers and Native applications from kernel mode, without touching registry"</a>
            </div>
        </content>
        
    </entry>

</feed>