Joanna’s Shocking Confession: There Exists Some Amount Of Money For Which I Would Agree To See BluePill Detected By Lawson, Ferrie, Dai Zovi and Ptacek.

Thomas Ptacek | June 28th, 2007 | Filed Under: Uncategorized

Joanna will accept our challenge, provided that:

  1. We provide her with 5 laptops, to make a random guess less than 3% likely to win the bet.

  2. Our tests don’t crash or halt the machine.

  3. Our tests don’t peg the CPU for more than 1 second.

  4. We open-source our tools (and she’ll open-source her rootkit).

  5. We arrange to have her paid $384,000.

Our response:

  1. Sure.

  2. Wokay.

  3. Irie! (hat tip: Ryan Naraine)

  4. Yept.

  5. Why would we pay you $384,000 to buy a rootkit we already know we can detect?

Here’s what’s going to happen:

  • We’re going to get up on stage

  • for free

  • at Black Hat

  • for free

  • and explain how our detection techniques work

  • for free

  • and show our code

  • for free

  • whether or not you accept our challenge.

  • and

  • If, by some stroke of luck, you manage to get Blue Pill 2.x to the point where you’re confident it actually works…

  • our challenge stands.

  • You don’t even have to pay us for it!


[Update: 7/5]

Dave Aitel, regarding SysCan ‘07:

Today at lunch: 1300 Singapore time Title of Talk: Detecting BluePill Speaker: Edgar Barbosa (COSEINC)

Viewing 45 Comments

Trackbacks

close Reblog this comment
blog comments powered by Disqus