World's First Standalone Kernel Mode Bot?


A European student has just developed a Proof of Concept for what the developer believes is the world's first kernel mode IRCbot.

The creator, Tibbar ("Rabbit" spelled backwards), says the difference between this innovation and standard Windows rootkits lies in its crossover ability. Most Windows-based rootkits hide in device drivers, then depend on outside, usermode applications to get anything done. Beyond Rootkits: World's First Standalone Kernel Mode Bot?

Linked by shanmuga Saturday, 8th April 2006 8:21AM