2.5 Basic Operating Principles of Rootkit Technologies
167
Fig. 2.20 Modification of the machine code of an application
Regardless of the linking method, the system needs to know what functions are
exported by DLL. For this purpose, each DLL contains an export table, which
includes the lists of the DLL’s exported functions, their numbers (ordinals), and
relative addresses of functions (RVA) (Fig. 2.20).
In this case, the machine code responsible for calling one or another API functions
in an application is modified. This method is difficult to realize, since there are
multiple programming languages and compiler versions, and a programmer can call
API functions using various methods. This is possible if the implant is introduced
into a definite program of a known version. Only in this case it is possible to analyze
its machine code and develop a hook.
This method is one of the classic ones. Its idea is simple: The rootkit finds the
program import table in memory and replaces the addresses of the necessary functions
with addresses of its hooks (of course, it saves the required addresses in advance).
When an API function is called, the program reads its address from the import table
and transfers control at this address. This method is universal; however, it has one
significant disadvantage (which can be clearly seen in the diagram in Fig. 2.21)—only
the statically imported functions are intercepted. However, there is also an advantage:
this method is very simple to implement, and there are numerous examples demonstrating its implementation. Finding an import table in memory is not especially
Fig. 2.21 Modification of the import table
167
Fig. 2.20 Modification of the machine code of an application
Regardless of the linking method, the system needs to know what functions are
exported by DLL. For this purpose, each DLL contains an export table, which
includes the lists of the DLL’s exported functions, their numbers (ordinals), and
relative addresses of functions (RVA) (Fig. 2.20).
In this case, the machine code responsible for calling one or another API functions
in an application is modified. This method is difficult to realize, since there are
multiple programming languages and compiler versions, and a programmer can call
API functions using various methods. This is possible if the implant is introduced
into a definite program of a known version. Only in this case it is possible to analyze
its machine code and develop a hook.
This method is one of the classic ones. Its idea is simple: The rootkit finds the
program import table in memory and replaces the addresses of the necessary functions
with addresses of its hooks (of course, it saves the required addresses in advance).
When an API function is called, the program reads its address from the import table
and transfers control at this address. This method is universal; however, it has one
significant disadvantage (which can be clearly seen in the diagram in Fig. 2.21)—only
the statically imported functions are intercepted. However, there is also an advantage:
this method is very simple to implement, and there are numerous examples demonstrating its implementation. Finding an import table in memory is not especially
Fig. 2.21 Modification of the import table
