<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet href="/templates/default/atom.css" type="text/css" ?>

<feed version="0.3" 
   xmlns="http://purl.org/atom/ns#"
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/">
    <link href="http://www.nvlabs.in/rss.php?version=atom0.3" rel="service.feed" title="NVlabs | Analyzing Security" type="application/x.atom+xml" />
    <link href="http://www.nvlabs.in/"                        rel="alternate"    title="NVlabs | Analyzing Security" type="text/html" />
    <link href="http://www.nvlabs.in/rss.php?version=2.0"     rel="alternate"    title="NVlabs | Analyzing Security" type="application/rss+xml" />
    <title mode="escaped" type="text/html">NVlabs | Analyzing Security</title>
    <tagline mode="escaped" type="text/html"></tagline>
    <id>http://www.nvlabs.in/</id>
    <modified>2010-08-30T18:07:00Z</modified>
    <generator url="http://www.s9y.org/" version="1.3.1">Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <dc:language>en</dc:language>
    <info mode="xml" type="text/html">
        <div xmlns="http://www.w3.org/1999/xhtml">You are viewing an ATOM formatted XML site feed. Usually this file is inteded to be viewed in an aggregator or syndication software. If you want to know more about ATOM, please visist <a href="http://atomenabled.org/">Atomenabled.org</a></div>
    </info>

    <entry>
        <link href="http://www.nvlabs.in/archives/8-Vbootkit-2.0-is-now-open-source-under-GPL-license.html" rel="alternate" title="Vbootkit 2.0 is now open-source ( under GPL license)" type="text/html" />
        <author>
            <name>Webmaster</name>
                    </author>
    
        <issued>2009-05-07T05:47:32Z</issued>
        <created>2009-05-07T05:47:32Z</created>
        <modified>2010-08-30T18:07:00Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=8</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=8</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/8-guid.html</id>
        <title mode="escaped" type="text/html">Vbootkit 2.0 is now open-source ( under GPL license)</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                Vbootkit 2.0 has now been made open-source under GPL license.<br />
<br />
Vbootkit 2.0 currently only works on Windows 7 ( x64 edition ).<br />
<br />
SHA1SUM: 1ddc2bc03e47b0251f5f65cb6dce31fb5aa2c86b  vbootkit2.zip<br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.zip" title="Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors source code &amp; binary download" target="_blank"><strong>Download Vbootkit 2.0 source code</strong></a> <br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.0-AttackingWindows7viaBootSectors.odp" title="Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors" target="_blank"><strong>Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors  presentation</strong></a>  
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/7-Hack-in-the-Box-Dubai-2009.html" rel="alternate" title="Hack-in-the-Box Dubai 2009" type="text/html" />
        <author>
            <name>Webmaster</name>
                    </author>
    
        <issued>2009-03-04T15:49:26Z</issued>
        <created>2009-03-04T15:49:26Z</created>
        <modified>2009-04-26T06:39:27Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=7</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=7</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/7-guid.html</id>
        <title mode="escaped" type="text/html">Hack-in-the-Box Dubai 2009</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <strong>Vbootkit 2.0: Attacking Windows 7 via Boot Sectors</strong><br />
<br />
This talk will introduce a new tool which allows attacks against Windows 7 via boot sectors. In this talk we will demo Vbootkit 2.0 in action and show how to bypass and circumvent security policies / architecture using customized boot sectors for Windows 7 (x64). The talk will cover:<br />
<br />
() Windows 7 Boot architecture<br />
() Vbootkit 2.0 architecture and inner workings<br />
() insight into the Windows 7 minkernel<br />
<br />
We will also demonstrate:<br />
<br />
() The use of Vbootkit in gaining access to a system without leaving traces<br />
() Leveraging normal programs to escalate system privileges<br />
() Running unsigned code in kernel<br />
() Remote command &amp; Control<br />
<br />
All this is done, without having any footprint on the HDD (everything is in memory). It also remains invisible to all existing anti-virus solutions.<br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit2/vbootkit2.0-AttackingWindows7viaBootSectors.odp" title="Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors" target="_blank"><strong>Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors</strong></a>  
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/1-NVbit-Accessing-Bitlocker-volumes-from-linux.html" rel="alternate" title="NVbit :  Accessing Bitlocker volumes from linux" type="text/html" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <issued>2008-05-19T11:20:00Z</issued>
        <created>2008-05-19T11:20:00Z</created>
        <modified>2008-09-25T10:37:48Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=1</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=1</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/1-guid.html</id>
        <title mode="escaped" type="text/html">NVbit :  Accessing Bitlocker volumes from linux</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <p>This projects details the Internals/Implementaion of  BitLocker Encryption system for Vista.</p><br />
<p>   NVbit is a linux  fuse driver to access Windows Vista's Bitlocker Volumes from linux, provided you have the right keys.A white-paper and supporting presentation is also available.The research was done around an year ago.Work was stopped prematurely,Don't expect things in clean/finished shape.The code is in alpha state.<br />
Both the paper and presentation are incomplete draft versions. However, missing things can be referred from nvbit source code.NVbit allows read-only access.(Though writing can be done just in reverse order but still it doesn't exist for now).</p><br />
 <a href="http://www.nvlabs.in/uploads/projects/nvbit/nvbit.zip" title="nvbit.zip" target="_blank"><strong>NVbit  source sode</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/nvbit/nvbit_bitlocker_presentation.pdf" title="nvbit_bitlocker_presentation.pdf" target="_blank"><strong>NVbit Bitlocker presentation</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/nvbit/nvbit_bitlocker_white_paper.pdf" title="nvbit_bitlocker_white_paper.pdf" target="_blank"><strong>NVbit Bitlocker white_paper</strong></a>  
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/2-0wning-Vista-from-the-boot-interview-at-SecurityFocus.html" rel="alternate" title="&quot;0wning Vista from the boot&quot;  interview at SecurityFocus" type="text/html" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <issued>2007-04-26T17:14:00Z</issued>
        <created>2007-04-26T17:14:00Z</created>
        <modified>2008-09-25T10:40:23Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=2</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=2</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/2-guid.html</id>
        <title mode="escaped" type="text/html">&quot;0wning Vista from the boot&quot;  interview at SecurityFocus</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                    <p><strong>What is Vbootkit?</strong></p><br />
<strong>Nitin &amp; Vipin:</strong> Vbootkit is much like a door or a shortcut to access vista's kernel.<br /><br />
<p>A bootkit is a rootkit that is able to load from a boot-sectors (master<br />
boot record, CD , PXE , floppies etc) and persist in memory all the way<br />
through the transition to protected mode and the startup of the OS.</p><br />
<p><a title="http://www.securityfocus.com/columnists/442" href="http://www.securityfocus.com/columnists/442">http://www.securityfocus.com/columnists/442</a></p><br />
 
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/3-Black-Hat-Europe-2007-HITB-Conf.-2007.html" rel="alternate" title="Black Hat Europe 2007 &amp; HITB Conf. 2007" type="text/html" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <issued>2007-04-12T15:39:00Z</issued>
        <created>2007-04-12T15:39:00Z</created>
        <modified>2008-09-25T10:41:38Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=3</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=3</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/3-guid.html</id>
        <title mode="escaped" type="text/html">Black Hat Europe 2007 &amp; HITB Conf. 2007</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                    <p><strong>Vbootkit White-paper and presentation materials</strong></p><br />
<p>The vbootkit white-paper and presentation slides are now online and can be downloaded  below.</p><br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit.ppt" title="nitin_vipin_vista_vbootkit.ppt" target="_blank"><strong>Vbootkit Presentation</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit/vbootkit_nitin_vipin_whitepaper.pdf" title="vbootkit_nitin_vipin_whitepaper.pdf" target="_blank"><strong>Vbootkit White Paper</strong></a><br />
<br />
 
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/4-Vbootkit-in-action-screenshots-and-videos.html" rel="alternate" title="Vbootkit in action  : screenshots and videos" type="text/html" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <issued>2007-04-11T09:39:00Z</issued>
        <created>2007-04-11T09:39:00Z</created>
        <modified>2008-09-26T05:01:52Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=4</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=4</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/4-guid.html</id>
        <title mode="escaped" type="text/html">Vbootkit in action  : screenshots and videos</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <table width="100%25"><br />
<TD align="CENTER"  ><br />
<a class='serendipity_image_link' href='http://www.nvlabs.in/uploads/projects/vbootkit/screen_bootmgr.JPG' onclick="F1 = window.open('/uploads/projects/vbootkit/screen_bootmgr.JPG','Zoom','height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes'); return false;"><!-- s9ymdb:15 --><img class="serendipity_image_right" width="150" height="110" style="float: right; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_bootmgr.thumbnail.nvlabs.JPG" alt="Vbootkit in action at BootMgr (Windows Vista Boot Manager)" /></a><br />
<br />
<br />
</td><br />
<TD align="CENTER"><br />
<br />
<a class='serendipity_image_link' href='http://www.nvlabs.in/uploads/projects/vbootkit/screen_system_cmd.jpg' onclick="F1 = window.open('/uploads/projects/vbootkit/screen_system_cmd.jpg','Zoom','height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes'); return false;"><!-- s9ymdb:15 --><img class="serendipity_image_right" width="150" height="110" style="float: right; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_system_cmd.thumbnail.nvlabs.jpg" alt="Windows Vista CMD.exe screenshot privilege escalation" /></a><br />
</td><br />
<TD align="CENTER"><br />
<br />
<a class='serendipity_image_link' href='http://www.nvlabs.in/uploads/projects/vbootkit/screen_system_procexp.jpg' onclick="F1 = window.open('/uploads/projects/vbootkit/screen_system_procexp.jpg','Zoom','height=615,width=815,top=0,left=-82.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes'); return false;"><!-- s9ymdb:16 --><img class="serendipity_image_right" width="150" height="110" style="float: right; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.nvlabs.in/uploads/projects/vbootkit/thumbs/screen_system.thumbnail.nvlabs.jpg" alt="Process explorer  showing TCB Trusted Computing Base" /></a><br />
</td><br />
</table><br />
<br />
<a href="http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit_poc_RC1_edited_video.avi" title="Vbootkit POC in action on Vista RC1" target="_blank"><strong>nitin_vipin_vista_vbootkit_poc_RC1_edited_video.avi</strong></a><br/><a href="http://www.nvlabs.in/uploads/projects/vbootkit/nitin_vipin_vista_vbootkit_poc_RC2_video.avi" title="Vbootkit POC in action on Vista RC2" target="_blank"><strong>nitin_vipin_vista_vbootkit_poc_RC2_video.avi</strong></a> 
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/5-BOOT-KIT-Custom-boot-sector-based-Windows-2000XP2003-Subversion.html" rel="alternate" title="BOOT KIT: Custom boot sector based Windows 2000/XP/2003 Subversion" type="text/html" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <issued>2007-02-04T15:18:00Z</issued>
        <created>2007-02-04T15:18:00Z</created>
        <modified>2008-09-25T10:45:56Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=5</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=5</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/5-guid.html</id>
        <title mode="escaped" type="text/html">BOOT KIT: Custom boot sector based Windows 2000/XP/2003 Subversion</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                <p>BOOT KIT is a project related to custom boot sector code subverting<br />
Windows NT Security Model.The sample presented currently keeps on<br />
escalating cmd.exe to system privileges every 30 secs.</p><br />
<p>It has several features</p><ol><li>It's very small.The basic framework is just about 100 lines of assembly code.It supports 2000,XP,2003</li><li>It patches the kernel at runtime(no files are patched on disk).</li><li>BOOT KIT is PXE-compatible.</li><li>It can even lead to first ever PXE virus</li><li>It also enables you to load other root kits if you have physical<br />
access(Normally root kits can only be loaded by the administrator</li></ol><br />
<p>The bootkit has been tested with a number of kernel mode shell codes such as Loading Native Applications and drivers from the shell code<br /><br />
another shellcode ,which periodically raises every CMD.EXE to system privileges.</p><br />
<p>The Source code will contain 4 levels of BOOT KITs(showcasing different payloads)</p><ol><li>Basic framework ( Kernel patching has to be done later on)  ( available for download )</li><li>Privilege escalation framework(demonstrates creating new system<br />
threads and how to escalate privileges easily) (available for download)</li><li>Loading drivers and native applications from kernel mode without touching registry</li><li>PXE compatible code(Basic framework).</li></ol><a href="http://www.nvlabs.in/uploads/projects/bootkit/bootkitbasic.zip" title="bootkitbasic.zip" target="_blank"><strong>Bootkit Basic framework Source Code</strong></a><br />
<a href="http://www.nvlabs.in/uploads/projects/bootkit/bootkitprivilege.zip" title="bootkitprivilege.zip" target="_blank"><strong>Boot Kit Advance Version(support Privilege escalation) Source Code</strong></a> 
            </div>
        </content>

        
    </entry>
    <entry>
        <link href="http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html" rel="alternate" title="Loading drivers and Native applications from kernel mode, without touching registry" type="text/html" />
        <author>
            <name>Administrator</name>
                    </author>
    
        <issued>2007-02-01T17:12:00Z</issued>
        <created>2007-02-01T17:12:00Z</created>
        <modified>2008-09-25T10:50:16Z</modified>
        <wfw:comment>http://www.nvlabs.in/wfwcomment.php?cid=6</wfw:comment>
        <slash:comments>0</slash:comments>
        <wfw:commentRss>http://www.nvlabs.in/rss.php?version=atom0.3&amp;type=comments&amp;cid=6</wfw:commentRss>
    
        <id>http://www.nvlabs.in/archives/6-guid.html</id>
        <title mode="escaped" type="text/html">Loading drivers and Native applications from kernel mode, without touching registry</title>
        <content type="application/xhtml+xml" xml:base="http://www.nvlabs.in/">
            <div xmlns="http://www.w3.org/1999/xhtml">
                    &quot;How to load driver without touching registry from kernel mode&quot;, this is asked almost always.Today, <br />
I will give you an insight into how Windows loads its driver and then will document a new method to load a driver without touching registry.</p><br />
<p>This is required because even if you exploit kernel vulnerabilities, you still cannot load any driver because almost all existing Antivirus solutions hijack the NTOSkrnl API's ( which let you write to specific registry locations, load drivers etc).</p><br />
 <br /><a href="http://www.nvlabs.in/archives/6-Loading-drivers-and-Native-applications-from-kernel-mode,-without-touching-registry.html#extended">Continue reading "Loading drivers and Native applications from kernel mode, without touching registry"</a>
            </div>
        </content>

        
    </entry>
</feed>