Rootkits Flashcards
1
Q
Boot loader rootkit
A
replace boot loader with one controlled by the hacker Ring 0
2
Q
Kernel level rootkit
A
attack the boot sectors kernel level of the OS replacing kernel code with back-door code. Ring 0
3
Q
Application level rootkit
A
replace application files with trojan binaries. work within an to apps behavior, user rights and actions Ring 3
4
Q
Library level rootkit
A
use system-level calls to hide their existence Ring 2
5
Q
Ring 0
A
Kernel
6
Q
Ring 1
A
Drivers
7
Q
Ring 2
A
Libraries
8
Q
Ring 3
A
Applications also User mode
9
Q
Some Rootkits
A
Horsepill, grayfish, Sirefef, Azazel, Avatar, Necurs, ZeroAccess
10
Q
Hypervisor rootkit
A
Modify the boot sequence of a host system to load a virtual machine as the host OS