Get Stoned

No explicit questions like "how do I hack xxx.com" please!
Post Reply
User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Get Stoned

Post by DNR »

http://www.stoned-vienna.com/
■Black Hat USA 2009 Presentation
Download the Stoned Bootkit Paper

■Paper
http://digitalnomad.suck-o.net/DNR/red/stoned_paper.pdf

■Open Source Framework
http://www.stoned-vienna.com/downloads/ ... mework.zip

■Infector file that was used in the Black Hat USA 2009 presentation
http://www.stoned-vienna.com/downloads/Infector.exe

yo kirk, this one is for you - works with USB sticks..
Last edited by DNR on 21 Aug 2009, 11:35, edited 1 time in total.
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

heh, I like how he presents it ^^
It has exciting features like integrated file system drivers, automatic Windows pwning, plugins, boot applications and much much more.
Hmm, I wonder ....

Neighbours crappy wireless security + a customised version of this with a RAT ... (adds to ToDo list)

I need to read all this stuff later
Last edited by ayu on 21 Aug 2009, 11:38, edited 1 time in total.
"The best place to hide a tree, is in a forest"

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

ha sort of the 'Billie Mays" of hackerware :wink:
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
Lundis
Distorter of Reality
Distorter of Reality
Posts: 543
Joined: 22 Aug 2008, 16:00
15
Location: Deadlock of Awesome
Contact:

Post by Lundis »

sounds cool, but does it get 'pwned' if you run fixmbr? ^^

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Lundis wrote:sounds cool, but does it get 'pwned' if you run fixmbr? ^^
Good question ...
"The best place to hide a tree, is in a forest"

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

The paper is a nice read 46 pgs, it explains the very nature of fixed spaces in MBR that will make it hard to hide it, and Stoned makes no attempt ti hide itself unless you call ordinary people trying to find their MBR 'security through obscurity'.

the MS technet site says:
The only time that the FDISK /MBR command is effective against a virus is if it is a boot-sector-only virus (such as the Stoned virus).
http://support.microsoft.com/kb/166454
http://support.microsoft.com/kb/69013

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

Post Reply