VBootkit – the beginning of the end for vista DRM.
0wning Vista from the boot
VBootkit, a rootkit that is able to load from Windows Vista boot-sectors. They discuss the "features" of their code, the support of the various versions of Vista, the possibility to place it inside the BIOS (it needs around 1500 bytes), and the chance to use it to bypass Vista's product activation or avoid DRM.
Schneier on Security says
VBootkit Bypasses Vista's Code Signing Mechanisms
Interesting work:
Experts say that the fundamental problem that this highlights is that every stage in Vista's booting process works on blind faith that everything prior to it ran cleanly. The boot kit is therefore able to copy itself into the memory image even before Vista has booted and capture interrupt 13, which operating systems use for read access to sectors of hard drives, among other things.
along with a lovely quote in the comments:
"you are coming to a sad realisation, cancel or allow" ...
Posted by: pointfree at April 3, 2007 04:41 PM












