2.2 Implants: Types, Ways of Injection, and Methods of Protection
141
As can be seen, the difference between these two scripts lies in the first 512-bit
blocks, which are, in fact, commented garbage. However, the contents of these blocks
are then used in the “if” condition; therefore, the scripts operate differently when
launched. Such files can be used by the creator for malicious purposes.
Backdoors can be built into nearly any hardware piece as well as software. Such
backdoors can be used by hardware manufacturers to embed malicious functions
during the production stage.
Hardware backdoors have a number of advantages over software ones:
– They cannot be detected using antiviruses, code scanners, and other protective
software;
– They cannot be eliminated by means of updating or replacing software.
BIOS firmware can be an example of hardware backdoor. According to the studies,
such firmware can be created on the basis of free firmwares Coreboot and SeaBIOS.
Coreboot is not a full-scale BIOS: it is responsible only for detecting the equipment
present in the machine and transferring control to the BIOS stuff, which can be
represented by SeaBIOS modified by the intruder in accordance with his own needs.
The operating principle of malicious firmware can be briefly described as follows:
immediately after activating the infected computer, even before loading the operating
system, it will attempt to connect to the intruder’s server via the Internet. If such
attempt proves successful, then a bootkit is remotely downloaded, which in turn
allows the intruder to perform malicious actions with the infected computer: data
theft or remote control. If the Internet connection attempt is failed, the operating
Précédent

- 162/839

Suivant