A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #3216  by ARCHANGEL
 Mon Oct 25, 2010 11:55 am
Hello, during the rootkit analizing I found RKU bug, that allows to hide hooks from that fonderful antirootkit, that 's not a joke! I reversed the great peice of code that parsed VadRoot in EPROCESS, and I'm ready to contact with the developers and report them where the problem is. It is quite easy to fix that, but for now I tested the last version of RKU and that version had that bug. By the way, if it's possible, I wuold like to communicote with RKU developers in russian...
 #3234  by ARCHANGEL
 Wed Oct 27, 2010 5:52 am
Nobody answed. Maybe the project is not supported already, I don't know. But maybe developers prefer to fix bugs after exploits are avaliable or maybe my bad english is the reason.
 #3235  by a_d_13
 Wed Oct 27, 2010 6:25 am
ARCHANGEL wrote:Nobody answed. Maybe the project is not supported already, I don't know. But maybe developers prefer to fix bugs after exploits are avaliable or maybe my bad english is the reason.
The project is currently supported - perhaps wait a couple more days for a response? Maybe EP_X0FF has not yet read your Private Message.

Thanks,
--AD
 #3239  by EP_X0FF
 Wed Oct 27, 2010 8:44 am
@ARCHANGEL

I've contacted with you via PM, native language should be accessible.