Join Date : Jun 2010
Bay Area
Posts : 6,768
Windows 7 Home Premium x64
New Version of Stoned Bootkit Said to Bypass Windows 8 Secure Boot
A security researcher who has in the past has created low-level rootkits capable of staying resident on an infected machine after reboots, said he has now accomplished the same feat on Windows 8, which hasn't even hit the shelves yet. Peter Kleissner said he has created a new version of his Stoned bootkit that defeats the pre-boot security checks included in the forthcoming OS and survives reboots.
Kleissner is known in the security community for his creation of the Stoned bootkit, a sophisticated form of rootkit that is designed to load from the master boot record and stay resident in memory throughout the boot process. The previous version of the bootkit was designed to work on Windows XP through Windows 7, but the new one that Kleissner has written also works on Windows 8. He said in a message on Twitter Thursday that Stoned Lite is a small footprint bootkit that can be loaded from either a USB stick or a CD.
He said he may also add some other functionality to the software in the near future.
System Manufacturer/Model Number Custom OS Windows 7 Home Premium x64 CPU INTEL Core i5-750 Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" , SyncMaster P2050 20" Screen Resolution 1920 x 1080 , 1440 x 900
PSU ANTEC TruePower New TP-550, 80 PLUS®, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 3 x 120mm 1 x 140mm Case Hard Drives 2 x SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps
Live Demo of the Bootkit in Windows 8 DP by Peter Kleissner.
Windows 8 Bootkit Live Demonstration
This shows how to use Stoned Lite to get SYSTEM rights on Windows 8 through the cmd privilege escalation (done by a driver loaded by the bootkit). The infector is just 14 KB of size and bypasses the UAC.