<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>NVlabs | Analyzing Security</title>
    <link>http://www.nvlabs.in/</link>
    <description></description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Thu, 07 May 2009 06:18:17 GMT</pubDate>

    <image>
        <url>http://www.nvlabs.in/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: NVlabs | Analyzing Security - </title>
        <link>http://www.nvlabs.in/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Vbootkit 2.0 is now open-source ( under GPL license)</title>
    <link>http://www.nvlabs.in/archives/8-Vbootkit-2.0-is-now-open-source-under-GPL-license.html</link>
            <category>Vbootkit</category>
    
    <comments>http://www.nvlabs.in/archives/8-Vbootkit-2.0-is-now-open-source-under-GPL-license.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=8</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=8</wfw:commentRss>
    

    <author>nospam@example.com (Webmaster)</author>
    <content:encoded>
    Vbootkit 2.0 has now been made open-source under GPL license.&lt;br /&gt;
&lt;br /&gt;
Vbootkit 2.0 currently only works on Windows 7 ( x64 edition ).&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.zip&quot; title=&quot;Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors source code &amp;amp; binary download&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Download Vbootkit 2.0 source code&lt;/strong&gt;&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.0-AttackingWindows7viaBootSectors.odp&quot; title=&quot;Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors  presentation&lt;/strong&gt;&lt;/a&gt;  
    </content:encoded>

    <pubDate>Thu, 07 May 2009 05:47:32 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/8-guid.html</guid>
    
</item>
<item>
    <title>Hack-in-the-Box Dubai 2009</title>
    <link>http://www.nvlabs.in/archives/7-Hack-in-the-Box-Dubai-2009.html</link>
    
    <comments>http://www.nvlabs.in/archives/7-Hack-in-the-Box-Dubai-2009.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=7</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=7</wfw:commentRss>
    

    <author>nospam@example.com (Webmaster)</author>
    <content:encoded>
    &lt;strong&gt;Vbootkit 2.0: Attacking Windows 7 via Boot Sectors&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
This talk will introduce a new tool which allows attacks against Windows 7 via boot sectors. In this talk we will demo Vbootkit 2.0 in action and show how to bypass and circumvent security policies / architecture using customized boot sectors for Windows 7 (x64). The talk will cover:&lt;br /&gt;
&lt;br /&gt;
() Windows 7 Boot architecture&lt;br /&gt;
() Vbootkit 2.0 architecture and inner workings&lt;br /&gt;
() insight into the Windows 7 minkernel&lt;br /&gt;
&lt;br /&gt;
We will also demonstrate:&lt;br /&gt;
&lt;br /&gt;
() The use of Vbootkit in gaining access to a system without leaving traces&lt;br /&gt;
() Leveraging normal programs to escalate system privileges&lt;br /&gt;
() Running unsigned code in kernel&lt;br /&gt;
() Remote command &amp;amp; Control&lt;br /&gt;
&lt;br /&gt;
All this is done, without having any footprint on the HDD (everything is in memory). It also remains invisible to all existing anti-virus solutions.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.0-AttackingWindows7viaBootSectors.odp&quot; title=&quot;Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors&lt;/strong&gt;&lt;/a&gt;  
    </content:encoded>

    <pubDate>Wed, 04 Mar 2009 15:49:26 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/7-guid.html</guid>
    
</item>
<item>
    <title>NVbit :  Accessing Bitlocker volumes from linux</title>
    <link>http://www.nvlabs.in/archives/1-NVbit-Accessing-Bitlocker-volumes-from-linux.html</link>
            <category>Bitlocker</category>
    
    <comments>http://www.nvlabs.in/archives/1-NVbit-Accessing-Bitlocker-volumes-from-linux.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=1</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=1</wfw:commentRss>
    

    <author>nospam@example.com (Administrator)</author>
    <content:encoded>
    &lt;p&gt;This projects details the Internals/Implementaion of  BitLocker Encryption system for Vista.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;   NVbit is a linux  fuse driver to access Windows Vista&#039;s Bitlocker Volumes from linux, provided you have the right keys.A white-paper and supporting presentation is also available.The research was done around an year ago.Work was stopped prematurely,Don&#039;t expect things in clean/finished shape.The code is in alpha state.&lt;br /&gt;
Both the paper and presentation are incomplete draft versions. However, missing things can be referred from nvbit source code.NVbit allows read-only access.(Though writing can be done just in reverse order but still it doesn&#039;t exist for now).&lt;/p&gt;&lt;br /&gt;
 &lt;a href=&quot;http://www.nvlabs.in/uploads/projects/nvbit/nvbit.zip&quot; title=&quot;nvbit.zip&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;NVbit  source sode&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/nvbit/nvbit_bitlocker_presentation.pdf&quot; title=&quot;nvbit_bitlocker_presentation.pdf&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;NVbit Bitlocker presentation&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/nvbit/nvbit_bitlocker_white_paper.pdf&quot; title=&quot;nvbit_bitlocker_white_paper.pdf&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;NVbit Bitlocker white_paper&lt;/strong&gt;&lt;/a&gt;  
    </content:encoded>

    <pubDate>Mon, 19 May 2008 11:20:00 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/1-guid.html</guid>
    
</item>
<item>
    <title>&quot;0wning Vista from the boot&quot;  interview at SecurityFocus</title>
    <link>http://www.nvlabs.in/archives/2-0wning-Vista-from-the-boot-interview-at-SecurityFocus.html</link>
            <category>Vbootkit</category>
    
    <comments>http://www.nvlabs.in/archives/2-0wning-Vista-from-the-boot-interview-at-SecurityFocus.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=2</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=2</wfw:commentRss>
    

    <author>nospam@example.com (Administrator)</author>
    <content:encoded>
        &lt;p&gt;&lt;strong&gt;What is Vbootkit?&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;
&lt;strong&gt;Nitin &amp;amp; Vipin:&lt;/strong&gt; Vbootkit is much like a door or a shortcut to access vista&#039;s kernel.&lt;br /&gt;&lt;br /&gt;
&lt;p&gt;A bootkit is a rootkit that is able to load from a boot-sectors (master&lt;br /&gt;
boot record, CD , PXE , floppies etc) and persist in memory all the way&lt;br /&gt;
through the transition to protected mode and the startup of the OS.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;&lt;a title=&quot;http://www.securityfocus.com/columnists/442&quot; href=&quot;http://www.securityfocus.com/columnists/442&quot;&gt;http://www.securityfocus.com/columnists/442&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 26 Apr 2007 17:14:00 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/2-guid.html</guid>
    
</item>
<item>
    <title>Black Hat Europe 2007 &amp; HITB Conf. 2007</title>
    <link>http://www.nvlabs.in/archives/3-Black-Hat-Europe-2007-HITB-Conf.-2007.html</link>
            <category>Vbootkit</category>
    
    <comments>http://www.nvlabs.in/archives/3-Black-Hat-Europe-2007-HITB-Conf.-2007.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=3</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=3</wfw:commentRss>
    

    <author>nospam@example.com (Administrator)</author>
    <content:encoded>
        &lt;p&gt;&lt;strong&gt;Vbootkit White-paper and presentation materials&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;The vbootkit white-paper and presentation slides are now online and can be downloaded  below.&lt;/p&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit.ppt&quot; title=&quot;nitin_vipin_vista_vbootkit.ppt&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Vbootkit Presentation&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/vbootkit_nitin_vipin_whitepaper.pdf&quot; title=&quot;vbootkit_nitin_vipin_whitepaper.pdf&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Vbootkit White Paper&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 12 Apr 2007 15:39:00 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/3-guid.html</guid>
    
</item>
<item>
    <title>Vbootkit in action  : screenshots and videos</title>
    <link>http://www.nvlabs.in/archives/4-Vbootkit-in-action-screenshots-and-videos.html</link>
            <category>Vbootkit</category>
    
    <comments>http://www.nvlabs.in/archives/4-Vbootkit-in-action-screenshots-and-videos.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=4</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=4</wfw:commentRss>
    

    <author>nospam@example.com (Administrator)</author>
    <content:encoded>
    &lt;table width=&quot;100%25&quot;&gt;&lt;br /&gt;
&lt;TD align=&quot;CENTER&quot;  &gt;&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://www.nvlabs.in/uploads/projects/vbootkit/screen_bootmgr.JPG&#039; onclick=&quot;F1 = window.open(&#039;/uploads/projects/vbootkit/screen_bootmgr.JPG&#039;,&#039;Zoom&#039;,&#039;height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:15 --&gt;&lt;img class=&quot;serendipity_image_right&quot; width=&quot;150&quot; height=&quot;110&quot; style=&quot;float: right; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_bootmgr.thumbnail.nvlabs.JPG&quot; alt=&quot;Vbootkit in action at BootMgr (Windows Vista Boot Manager)&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;/td&gt;&lt;br /&gt;
&lt;TD align=&quot;CENTER&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://www.nvlabs.in/uploads/projects/vbootkit/screen_system_cmd.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/projects/vbootkit/screen_system_cmd.jpg&#039;,&#039;Zoom&#039;,&#039;height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:15 --&gt;&lt;img class=&quot;serendipity_image_right&quot; width=&quot;150&quot; height=&quot;110&quot; style=&quot;float: right; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_system_cmd.thumbnail.nvlabs.jpg&quot; alt=&quot;Windows Vista CMD.exe screenshot privilege escalation&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/td&gt;&lt;br /&gt;
&lt;TD align=&quot;CENTER&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://www.nvlabs.in/uploads/projects/vbootkit/screen_system_procexp.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/projects/vbootkit/screen_system_procexp.jpg&#039;,&#039;Zoom&#039;,&#039;height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:16 --&gt;&lt;img class=&quot;serendipity_image_right&quot; width=&quot;150&quot; height=&quot;110&quot; style=&quot;float: right; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_system.thumbnail.nvlabs.jpg&quot; alt=&quot;Process explorer  showing TCB Trusted Computing Base&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/td&gt;&lt;br /&gt;
&lt;/table&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit_poc_RC1_edited_video.avi&quot; title=&quot;Vbootkit POC in action on Vista RC1&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;nitin_vipin_vista_vbootkit_poc_RC1_edited_video.avi&lt;/strong&gt;&lt;/a&gt;&lt;br/&gt;&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit_poc_RC2_video.avi&quot; title=&quot;Vbootkit POC in action on Vista RC2&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;nitin_vipin_vista_vbootkit_poc_RC2_video.avi&lt;/strong&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Wed, 11 Apr 2007 09:39:00 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/4-guid.html</guid>
    
</item>
<item>
    <title>BOOT KIT: Custom boot sector based Windows 2000/XP/2003 Subversion</title>
    <link>http://www.nvlabs.in/archives/5-BOOT-KIT-Custom-boot-sector-based-Windows-2000XP2003-Subversion.html</link>
            <category>Projects</category>
    
    <comments>http://www.nvlabs.in/archives/5-BOOT-KIT-Custom-boot-sector-based-Windows-2000XP2003-Subversion.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=5</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=5</wfw:commentRss>
    

    <author>nospam@example.com (Administrator)</author>
    <content:encoded>
    &lt;p&gt;BOOT KIT is a project related to custom boot sector code subverting&lt;br /&gt;
Windows NT Security Model.The sample presented currently keeps on&lt;br /&gt;
escalating cmd.exe to system privileges every 30 secs.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;It has several features&lt;/p&gt;&lt;ol&gt;&lt;li&gt;It&#039;s very small.The basic framework is just about 100 lines of assembly code.It supports 2000,XP,2003&lt;/li&gt;&lt;li&gt;It patches the kernel at runtime(no files are patched on disk).&lt;/li&gt;&lt;li&gt;BOOT KIT is PXE-compatible.&lt;/li&gt;&lt;li&gt;It can even lead to first ever PXE virus&lt;/li&gt;&lt;li&gt;It also enables you to load other root kits if you have physical&lt;br /&gt;
access(Normally root kits can only be loaded by the administrator&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;
&lt;p&gt;The bootkit has been tested with a number of kernel mode shell codes such as Loading Native Applications and drivers from the shell code&lt;br /&gt;&lt;br /&gt;
another shellcode ,which periodically raises every CMD.EXE to system privileges.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;The Source code will contain 4 levels of BOOT KITs(showcasing different payloads)&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Basic framework ( Kernel patching has to be done later on)  ( available for download )&lt;/li&gt;&lt;li&gt;Privilege escalation framework(demonstrates creating new system&lt;br /&gt;
threads and how to escalate privileges easily) (available for download)&lt;/li&gt;&lt;li&gt;Loading drivers and native applications from kernel mode without touching registry&lt;/li&gt;&lt;li&gt;PXE compatible code(Basic framework).&lt;/li&gt;&lt;/ol&gt;&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/bootkit/bootkitbasic.zip&quot; title=&quot;bootkitbasic.zip&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Bootkit Basic framework Source Code&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.nvlabs.in/uploads/projects/bootkit/bootkitprivilege.zip&quot; title=&quot;bootkitprivilege.zip&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Boot Kit Advance Version(support Privilege escalation) Source Code&lt;/strong&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Sun, 04 Feb 2007 15:18:00 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/5-guid.html</guid>
    
</item>
<item>
    <title>Loading drivers and Native applications from kernel mode, without touching registry</title>
    <link>http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html</link>
            <category>Vbootkit</category>
    
    <comments>http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html#comments</comments>
    <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=6</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.nvlabs.in/rss.php?version=2.0&amp;type=comments&amp;cid=6</wfw:commentRss>
    

    <author>nospam@example.com (Administrator)</author>
    <content:encoded>
        &amp;quot;How to load driver without touching registry from kernel mode&amp;quot;, this is asked almost always.Today, &lt;br /&gt;
I will give you an insight into how Windows loads its driver and then will document a new method to load a driver without touching registry.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;This is required because even if you exploit kernel vulnerabilities, you still cannot load any driver because almost all existing Antivirus solutions hijack the NTOSkrnl API&#039;s ( which let you write to specific registry locations, load drivers etc).&lt;/p&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html#extended&quot;&gt;Continue reading &quot;Loading drivers and Native applications from kernel mode, without touching registry&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 01 Feb 2007 17:12:00 +0000</pubDate>
    <guid isPermaLink="false">http://www.nvlabs.in/archives/6-guid.html</guid>
    
</item>

</channel>
</rss>