Bruce Schneier had an interesting blog "VBootkit Bypasses Vista's Code Signing Mechanisms" that is definitely worth reading. It refers to story about a paper presented at the recent Black Hat Conference in Amsterdam. The paper shows how how a special bootloader gets around Vista's code signing mechanisms.
If you can control the hardware, you can control the software. This code allows for control of the operating kernel. Thus it's a powerful rootkit attack.
Guy
www.authenticationworld.com
guy.huntington@authenticationworld.com

del.icio.us