[Full-disclosure] Abusing Windows 7 Recovery Process‏

2013-07-14 Thread whizzbang
You didn't tell us how you cracked the full disc encryption. (There are ways around controls, but that is why we have multiple security layers.) With a bootkit, of course. (That is why we have multiple tools.) ___ Full-Disclosure - We

Re: [Full-disclosure] Abusing Windows 7 Recovery Process‏

2013-07-14 Thread Alex
Mcafee KB 66153 Am 14. Juli 2013 06:40:57 schrieb whizzb...@hush.ai: You didn't tell us how you cracked the full disc encryption. (There are ways around controls, but that is why we have multiple security layers.) With a bootkit, of course. (That is why we have multiple tools.)

Re: [Full-disclosure] Abusing Windows 7 Recovery Process‏

2013-07-14 Thread whizzbang
Genius ! Both McAfee RootKit Detective (http://vil.nai.com/vil/stinger/rkstinger.aspx) and SysInternals RootKitRevealer (http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx), as well as others provide tools to do exactly this kind of detection, and of course, with a reputable