<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Rootkits: The &#8220;r00t&#8221; of Digital Evil</title>
	<atom:link href="http://www.exploitx.com/141/rootkits-the-r00t-of-digital-evil/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.exploitx.com/141/rootkits-the-r00t-of-digital-evil/</link>
	<description>Technology &#38; Security Tips &#38; Guides</description>
	<pubDate>Wed, 07 Jan 2009 09:35:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Matt Richard</title>
		<link>http://www.exploitx.com/141/rootkits-the-r00t-of-digital-evil/#comment-30</link>
		<dc:creator>Matt Richard</dc:creator>
		<pubDate>Thu, 01 Dec 2005 21:31:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.exploitx.com/141/rootkits-the-r00t-of-digital-evil/#comment-30</guid>
		<description>Interesting and thorough analysis.  As far as detecting and preventing certain types of kernel level in-memory rootkits I came across a great paper from a couple of Stanford researchers that uses virtual machine technology to monitor to detect and prevent rootkits.  The idea is to monitor the state of the kernel and mark certain memory pages as read only at the "virtual hardware" level.</description>
		<content:encoded><![CDATA[<p>Interesting and thorough analysis.  As far as detecting and preventing certain types of kernel level in-memory rootkits I came across a great paper from a couple of Stanford researchers that uses virtual machine technology to monitor to detect and prevent rootkits.  The idea is to monitor the state of the kernel and mark certain memory pages as read only at the &#8220;virtual hardware&#8221; level.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
