2.5 Basic Operating Principles of Rootkit Technologies
173
Fig. 2.27 Scheme of interception of functions called by the program [14]
from the import table, the function address (2) is taken, and the function call actions
are carried out (3).
Dynamic binding differs from static binding in the fact that the compiler in this
case is unaware of the list of the functions imported by the program. The library
is loaded dynamically using the API function LoadLibrary. This function is stored
in the file kernel32.dll. The program can use the function LoadLibrary to load the
library at any moment of time. The function kernel32.dll GetProcAddress is used
to obtain real address of the function. Step 4 in Fig. 2.26 demonstrates loading of
the library with the help of LoadLibrary and identification of addresses with the
help of the GetProcAddress function. EXE file import table is not required in this
case. Regardless of the linking method, the system needs to know what functions are
exported by DLL. For this purpose, each DLL has an export table, which contains
the list of exported functions.
Figure 2.27 shows the flow of interception of the import table by a rootkit program.
The rootkit finds the import table in the RAM and replaces the addresses of the
required functions with the addresses of its hooks. When an API function is called,
the program reads its address from the modified import table and transfers control
at this address. In this case, statically imported functions are intercepted, including
GetProcAddress and LoadLibrary of the kernel32.dll library. When the program
requests addresses of the desired functions, it receives addresses of rootkit hooks
instead of the real address of the function.
Thus, when calling statically imported functions, modified addresses are taken
from the import table; when dynamically determining the address, the intercepted
function GetProcAddress is called, which returns addresses of the hooks. As a result,
the program has no way of determining the correct address of the function.
Forewarned is forearmed. Knowing penetration and infection mechanisms, one
can correct the codes of software modules of the operating system. One of the ways
173
Fig. 2.27 Scheme of interception of functions called by the program [14]
from the import table, the function address (2) is taken, and the function call actions
are carried out (3).
Dynamic binding differs from static binding in the fact that the compiler in this
case is unaware of the list of the functions imported by the program. The library
is loaded dynamically using the API function LoadLibrary. This function is stored
in the file kernel32.dll. The program can use the function LoadLibrary to load the
library at any moment of time. The function kernel32.dll GetProcAddress is used
to obtain real address of the function. Step 4 in Fig. 2.26 demonstrates loading of
the library with the help of LoadLibrary and identification of addresses with the
help of the GetProcAddress function. EXE file import table is not required in this
case. Regardless of the linking method, the system needs to know what functions are
exported by DLL. For this purpose, each DLL has an export table, which contains
the list of exported functions.
Figure 2.27 shows the flow of interception of the import table by a rootkit program.
The rootkit finds the import table in the RAM and replaces the addresses of the
required functions with the addresses of its hooks. When an API function is called,
the program reads its address from the modified import table and transfers control
at this address. In this case, statically imported functions are intercepted, including
GetProcAddress and LoadLibrary of the kernel32.dll library. When the program
requests addresses of the desired functions, it receives addresses of rootkit hooks
instead of the real address of the function.
Thus, when calling statically imported functions, modified addresses are taken
from the import table; when dynamically determining the address, the intercepted
function GetProcAddress is called, which returns addresses of the hooks. As a result,
the program has no way of determining the correct address of the function.
Forewarned is forearmed. Knowing penetration and infection mechanisms, one
can correct the codes of software modules of the operating system. One of the ways
