<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Stoned Bootkit</title>
	<atom:link href="http://voipsa.org/blog/2009/09/09/stoned-bootkit/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog/2009/09/09/stoned-bootkit/</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<lastBuildDate>Sat, 03 Dec 2011 12:02:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Chris John Riley</title>
		<link>http://voipsa.org/blog/2009/09/09/stoned-bootkit/comment-page-1/#comment-342319</link>
		<dc:creator>Chris John Riley</dc:creator>
		<pubDate>Wed, 09 Sep 2009 15:28:18 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=794#comment-342319</guid>
		<description>Just to clarify, the Stoned Bootkit doesn&#039;t actually attack Truecrypt. This is a common mis-conception (and one that unfortunately cost Peter his job from my understanding).

From talking to Peter recently, the stoned bootkit simple uses hooks to intercept INT13H calls and as such doesn&#039;t need to concern itself with the Full-Disk Encryption on the device. The user will still be prompted to enter the encryption password before booting. Any system that doesn&#039;t check the validity of the MBR when booting, is by design vulnerable to the bootkit style attack. Peter has spoken to the TrueCrypt people about checking the MBR (http://peterkleissner.com/?p=11) however it doesn&#039;t look like they will fix the issue.</description>
		<content:encoded><![CDATA[<p>Just to clarify, the Stoned Bootkit doesn&#8217;t actually attack Truecrypt. This is a common mis-conception (and one that unfortunately cost Peter his job from my understanding).</p>
<p>From talking to Peter recently, the stoned bootkit simple uses hooks to intercept INT13H calls and as such doesn&#8217;t need to concern itself with the Full-Disk Encryption on the device. The user will still be prompted to enter the encryption password before booting. Any system that doesn&#8217;t check the validity of the MBR when booting, is by design vulnerable to the bootkit style attack. Peter has spoken to the TrueCrypt people about checking the MBR (<a href="http://peterkleissner.com/?p=11" rel="nofollow">http://peterkleissner.com/?p=11</a>) however it doesn&#8217;t look like they will fix the issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

