Feeds

New tool enables loading of unsigned drivers in Vista

Use at your own risk

Choosing a cloud hosting partner with confidence

A new software tool has been released by Linchpin Labs that allows the loading of unsigned and legacy drivers on Windows XP, 2003, and most importantly Vista.

One of the system management and control methods that Microsoft implemented with Windows Vista is requiring system drivers to be digitally signed before they will load properly within the system. If a user or administrator wishes to load an unsigned or legacy driver, they will either need to reboot into a limited functionality mode or just do without the functions that the driver would have provided.

As others have pointed out, this step will do nothing to prevent malware authors from being able to load their drivers into the system. Either they will exploit the lax jurisdiction and corporate oversight of various countries to establish a corporate shell and gain legitimate digitally signed driver certification, or they will just exploit weaknesses in already-signed drivers.

The process of digitally signing drivers risks becoming like that used to issue SSL certificates - only providing a moderate distraction for those with malicious intent on their way to obtaining accreditation, but a significant obstacle for the amateur developers without the necessary resources.

Into this environment, the developers at Linchpin Labs have released their Atsiv command line tool that allows for the loading of unsigned and legacy drivers into 32 and 64 bit versions of Windows XP, 2003, and Vista.

As the developers have acknowledged, this isn't the first tool to allow for the loading of unsigned drivers, but it is one of the first (if not the first) to use a signed system component to load an unsigned component.

To gain access to the full features of Atsiv, the user operating the tool is required to have Administrator privileges before starting the tool.

While Atsiv appears to be a top quality tool for the loading of unsigned drivers, it won't add the newly loaded driver to the standard drivers list, nor is it completely loaded into memory (for example, the DOS header is not loaded). This isn't necessary a drawback, depending on the intent of the person who is using it to load a driver.

Atsiv also ignores any dependencies that a driver might have, so it is necessary to ensure any dependencies are preloaded before attempting to load a driver that requires them. It also allows the same driver to be loaded multiple times in memory, potentially leading to interesting cases where multiple instances of a driver are fighting over the same information.

As with any other system modification and administration tool, system instability, failure or unresponsiveness may be encountered when using Atsiv - so use is at the user's own risk.

This article originally appeared at Sûnnet Beskerming

© 2007 Sûnnet Beskerming Pty Ltd

Sûnnet Beskerming is an independent Information Security firm operating from the antipodes. Specialising in the gap between threat emergence and vendor response, Sûnnet Beskerming provides global reach with a local touch.

Providing a secure and efficient Helpdesk

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
Redmond top man Satya Nadella: 'Microsoft LOVES Linux'
Open-source 'love' fairly runneth over at cloud event
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.