2.5 Basic Operating Principles of Rootkit Technologies
169
Fig. 2.24 Modification of the software code of an API function
This method is more difficult to implement than address replacement. In this
method, rootkit finds the machine code of the necessary API functions in memory
and modifies this code. If such method of function interception is used, there is no
need to modify the import table of launched programs and send distorted address
to programs when GetProcAddress addresses. From the point of view of function,
everything remains unchanged with one exception: the correct address inside the
correct DLL now contains the rootkit machine code.
As a rule, interference into machine code of the intercepted functions is minimal.
The beginning of a function contains a maximum of 2–3 machine commands transferring control over the main function to the hook. In order to call modified functions,
the rootkit needs to save the source machine code for each modified function (of
course, only the bytes of the machine code altered during interception are saved).
This interception method is implemented in the widely known HackerDefender and
the library AFX Rootkit (www.rootkit.com).
We can also mention the popular method of modification of DLL libraries on
the drive. This method consists in modification of the system library on the disk.
Modification methods are similar to the ones described above, except for the fact
that modification is performed on the disk and not in memory. However, this method
failed to gain popularity.
2.5.3 Methods of Interception of Rootkit Functions in Kernel
Mode
In order to understand the standard method for interception of functions in kernel
mode, it is necessary to consider the principles of interactions between libraries of
user mode and kernel. Let us consider this interaction with the help of a simplified
diagram shown in Fig. 2.25.
The main interaction with the kernel is done via ntdll.dll, most of the functions
of which are adapters that access the kernel via INT 2Eh interrupt, although nothing
prevents the application program from directly calling INT 2Eh.
Précédent

- 190/839

Suivant