<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The BIOS-Embedded Anti-Theft Persistent Agent that Couldn&#8217;t: Handling the Ostrich Defense</title>
	<atom:link href="http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/</link>
	<description>Penetration testing and other topics from the world of IT security.</description>
	<lastBuildDate>Tue, 23 Feb 2010 08:00:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: ivan arce</title>
		<link>http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/comment-page-1/#comment-431</link>
		<dc:creator>ivan arce</dc:creator>
		<pubDate>Wed, 19 Aug 2009 00:13:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.coresecurity.com/?p=5201#comment-431</guid>
		<description>Mary,
Is there anything in particular that makes you think the issues you experienced are related specifically to the computrace agent? Note that the code that was found in BIOS by Anibal and Alfredo only supported dropping a &quot;phone home&quot; executable on Windows operating systems and you mentioned un-removable files on Linux so you may have a different form of malware on your systems.
Python is an interpreted  programming language, Python programs require the runtime execution engine to installed on the system,  so there are many tools or programs  that may use it and be responsible for its presence on your systems. 
The tool to dump the BIOS and detect the computrace agent was written in Python, but not the agent itself. The agent is jsut a windows executable that runs as a service.
A simple way of checking if you have the Computrace agent running on your system is to look for a Windows service running with the name &quot;Remote Procedure Call Net&quot;</description>
		<content:encoded><![CDATA[<p>Mary,<br />
Is there anything in particular that makes you think the issues you experienced are related specifically to the computrace agent? Note that the code that was found in BIOS by Anibal and Alfredo only supported dropping a &#8220;phone home&#8221; executable on Windows operating systems and you mentioned un-removable files on Linux so you may have a different form of malware on your systems.<br />
Python is an interpreted  programming language, Python programs require the runtime execution engine to installed on the system,  so there are many tools or programs  that may use it and be responsible for its presence on your systems.<br />
The tool to dump the BIOS and detect the computrace agent was written in Python, but not the agent itself. The agent is jsut a windows executable that runs as a service.<br />
A simple way of checking if you have the Computrace agent running on your system is to look for a Windows service running with the name &#8220;Remote Procedure Call Net&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mary Anderson</title>
		<link>http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/comment-page-1/#comment-421</link>
		<dc:creator>Mary Anderson</dc:creator>
		<pubDate>Mon, 17 Aug 2009 22:52:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.coresecurity.com/?p=5201#comment-421</guid>
		<description>I am an IT mgr at a school.  I own 3 laptops and 3 pcs at home and he been in support/it since the mid-80&#039;s. (1986+).  I believe I have this issue on my laptop.  I have files -- persistent -- cannot be removed in linux , windows, or a kill disk.  I have had equipment turn on -- run something -- and then shut down incorrectly (while it was off and I was sleeping).

It escaped all antivirus applications (Norton, mcafee, AVG, Trend and Kapersky).  I believe I now have it embedded at the school -- but just have picecs of evidence.  I have an open ticket with Trend and Microsoft and now people are now thinking that this is plausible.  I need some help -- and am willing to work with someone (share the info).......

I have the computrace on my laptop -- my families bioses were flashed (I have evidence of python22 on a laptop where it was not installed.....Any help would be appreciated.

I have been personally hit ....and trying to prove that it exists at work.</description>
		<content:encoded><![CDATA[<p>I am an IT mgr at a school.  I own 3 laptops and 3 pcs at home and he been in support/it since the mid-80&#8217;s. (1986+).  I believe I have this issue on my laptop.  I have files &#8212; persistent &#8212; cannot be removed in linux , windows, or a kill disk.  I have had equipment turn on &#8212; run something &#8212; and then shut down incorrectly (while it was off and I was sleeping).</p>
<p>It escaped all antivirus applications (Norton, mcafee, AVG, Trend and Kapersky).  I believe I now have it embedded at the school &#8212; but just have picecs of evidence.  I have an open ticket with Trend and Microsoft and now people are now thinking that this is plausible.  I need some help &#8212; and am willing to work with someone (share the info)&#8230;&#8230;.</p>
<p>I have the computrace on my laptop &#8212; my families bioses were flashed (I have evidence of python22 on a laptop where it was not installed&#8230;..Any help would be appreciated.</p>
<p>I have been personally hit &#8230;.and trying to prove that it exists at work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ivan arce</title>
		<link>http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/comment-page-1/#comment-401</link>
		<dc:creator>ivan arce</dc:creator>
		<pubDate>Fri, 14 Aug 2009 16:22:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.coresecurity.com/?p=5201#comment-401</guid>
		<description>Steven,

The list of laptops that may ship with the rootkit is provided by the vendor 
&lt;a href=&quot;http://www.absolute.com/partners/bios-compatibility&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt; but will be better of asking before you buy.
Interestingly enough, Sony does not seem to include the rootkit in their computers and they are no strangers to the perils of shipping rootkits to their customers</description>
		<content:encoded><![CDATA[<p>Steven,</p>
<p>The list of laptops that may ship with the rootkit is provided by the vendor<br />
<a href="http://www.absolute.com/partners/bios-compatibility" rel="nofollow">here</a> but will be better of asking before you buy.<br />
Interestingly enough, Sony does not seem to include the rootkit in their computers and they are no strangers to the perils of shipping rootkits to their customers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven H</title>
		<link>http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/comment-page-1/#comment-371</link>
		<dc:creator>Steven H</dc:creator>
		<pubDate>Wed, 12 Aug 2009 21:32:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.coresecurity.com/?p=5201#comment-371</guid>
		<description>Do you know of a PC manufacturer that does not put this crap on the computer? I think I will buy a Mac instead.</description>
		<content:encoded><![CDATA[<p>Do you know of a PC manufacturer that does not put this crap on the computer? I think I will buy a Mac instead.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: golem</title>
		<link>http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/comment-page-1/#comment-351</link>
		<dc:creator>golem</dc:creator>
		<pubDate>Wed, 12 Aug 2009 15:45:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.coresecurity.com/?p=5201#comment-351</guid>
		<description>Ivan:

 We&#039;ve been looking at this for a while now.  I find that such folks are best served boiled in their own snake oil.

/golem</description>
		<content:encoded><![CDATA[<p>Ivan:</p>
<p> We&#8217;ve been looking at this for a while now.  I find that such folks are best served boiled in their own snake oil.</p>
<p>/golem</p>
]]></content:encoded>
	</item>
</channel>
</rss>
