Mark Russinovich

From Wikipedia, the free encyclopedia

Jump to: navigation, search

Mark E. Russinovich is a software engineer and author who works for Microsoft as a Technical fellow. He is a regular contributor to TechNet Magazine and Windows IT Pro magazine (previously called Windows NT Magazine) on the subject of the Architecture of Windows 2000 and was co-author of Inside Windows 2000 (3rd edition). Russinovich is the author of many tools used by Windows NT and Windows 2000 kernel-mode programmers, and of the NTFS file system driver for DOS. He is widely regarded as a Windows expert.

Some of his work was done in collaboration with David A. Solomon and under the banner of Sysinternals which is also used by Bryce Cogswell. The commercial part of his work partly spun off to the company Winternals Software.

Contents

[edit] Earlier work

In 1996, Russinovich discovered that the alteration of two registry values in the Windows Registry of the Workstation edition of Windows NT 4 would allow the installation of Microsoft BackOffice products which were licensed only for the Server edition[1].

In 2005, Russinovich discovered rootkits in Sony DRM products, the function of the rootkit was to prevent users from copying their media.

In 2006, Russinovich discovered a rootkit in a product of security software company Symantec, Symantec directly removed the rootkit.

[edit] Windows Metafile vulnerability

In January 2006, Russinovich again came to public attention when he analyzed the Windows Metafile vulnerability in Windows and concluded that it was not a deliberate backdoor. This possibility had been raised — albeit tentatively — by Steve Gibson after a cursory investigation of the nature of the exploit and its mechanism.[2]

[edit] Bibliography

Books

  • Solomon, David; Mark Russinovich (September 16, 2000). Inside Microsoft Windows 2000 ((Third Edition) ed.). Microsoft Press. ISBN 0-7356-1021-5. 
  • Russinovich, Mark; David Solomon (December 8, 2004). Microsoft Windows Internals ((Fourth Edition) ed.). Microsoft Press. ISBN 0-7356-1917-4. 
  • Russinovich, Mark; David Solomon, Alex Ionescu (June 17, 2009). Microsoft Windows Internals ((Fifth Edition) ed.). Microsoft Press. ISBN 0-7356-2530-1. 

Articles

Videos

[edit] References

  1. ^ Andrew Schulman (1996-09-16). "Differences Between NT Server and Workstation Are Minimal". O'Reilly and Associates. http://www.oreilly.com/news/differences_nt.html. Retrieved 2005-11-16. 
  2. ^ Steve Gibson (2006-01-12). "grc.news.feedback". Gibson Research Corporation. http://12078.net/grcnews/article.php?group=grc.news.feedback&id=60006. Retrieved 2007-11-06.  "The only conclusion that can reasonably be drawn is that this was a deliberate backdoor put into all of Microsoft's recent editions of Windows."

[edit] External links