Rootkits Flashcards

1
Q

Boot loader rootkit

A

replace boot loader with one controlled by the hacker Ring 0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Kernel level rootkit

A

attack the boot sectors kernel level of the OS replacing kernel code with back-door code. Ring 0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Application level rootkit

A

replace application files with trojan binaries. work within an to apps behavior, user rights and actions Ring 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Library level rootkit

A

use system-level calls to hide their existence Ring 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Ring 0

A

Kernel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Ring 1

A

Drivers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Ring 2

A

Libraries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Ring 3

A

Applications also User mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Some Rootkits

A

Horsepill, grayfish, Sirefef, Azazel, Avatar, Necurs, ZeroAccess

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Hypervisor rootkit

A

Modify the boot sequence of a host system to load a virtual machine as the host OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly