- Jan 29, 2016
- 812
Thanks for watching
and hope you enjoy the video!
As expected, classic malware testing on softwares like SD is futile; to truly test it; MBR-based ransomwares, bioskits/rootkits are the minimum requirements.
Hi Umbra, Would the MBR-based ransomware etc bypass SD? I only ask as I know you have a lot of experience with SD.As expected, classic malware testing on softwares like SD is futile; to truly test it; MBR-based ransomwares, bioskits/rootkits are the minimum requirements.
Great thanks. I'm ashamed to say I've only recently started using SD and it is indeed an amazing piece of software.They won't , this issue was fixed years ago , now the writing to the MBR is also redirected.
Nothing to be ashamed of there all software is new to us all at some time, please now you can enjoy SD like the rest of us users.Great thanks. I'm ashamed to say I've only recently started using SD and it is indeed an amazing piece of software.
It doesn't restrict driver loading so i guess it can't protect any kernel mode malware. I would assume that's one way to bypass any protection it offers.As of today, there's no known bypass to SD?
the malware can load all the drivers it wants, and muck up the windows kernel, and it's all okay. Because all changes to the system will be erased at reboot. that's the form of protection it is designed to offer. Your system gets temporarily infected, and then you wash it all away at reboot.It doesn't restrict driver loading so i guess it can't protect any kernel mode malware. I would assume that's one way to bypass any protection it offers.
If you load your drivers you can disable SD. No? I am no malware expert but it's possible.the malware can load all the drivers it wants, and muck up the windows kernel, and it's all okay. Because all changes to the system will be erased at reboot. that's the form of protection it is designed to offer. Your system gets temporarily infected, and then you wash it all away at reboot.
I don't think it is a problem, because you don't need SD to protect you anymore, at that point. It has done its job already, because it has virtualized your system.If you load your drivers you can disable SD. No? I am no malware expert but it's possible.
It doesn't restrict driver loading so i guess it can't protect any kernel mode malware. I would assume that's one way to bypass any protection it offers.
If you load your drivers you can disable SD. No? I am no malware expert but it's possible.
As of today, there's no known bypass to SD?
Great review!
Some time ago I've tested Petya ( old version ) with SD under VM.
No issues at reboot, SD protects MBR from changes.