2.7 Example of Injection of a Software
189
Microsoft has held similar cyberdrills for several years. The advantages of such
events are evident: they can help reveal holes in the protection and new security
issues that can be fixed in advance. Moreover, such tests can reveal ways of publication of confidential information, unconventional exploitation schemes, and other
undocumented possibilities of the system.
Address Space Layout Randomization (ASLR)
ASLR is a security technique aimed at protection from attacks associated with buffer
overflow. To prevent the attacker from correctly switching to a specific function within
the memory, the ASLR randomly places the positions of key information areas in
the process address space. This also includes the base address of the executable file
and the positions of the stack, heap, and libraries.
Code Cave
Code Cave is a piece of code written by another programs into the memory of an
external process. This code can be executed by creating a remote stream inside the
target process. Code cave is often a link to the section of script functions of a code,
where virtually any instructions can be injected. For example, if the memory of a
script contains five bytes, and three of these bytes are used, it is possible to add an
external code into the remaining two bytes.
Checksum
Checksum is a small portion of information from the block of digital data for the
detection of errors that can emerge during transmission or storage of a file. As a rule,
checksum is used to verify the installation file after it is received from the server.
Frankly speaking, even though checksums are used to verify data integrity, they don’t
take into account authenticity of information.
Let us consider the main intrusion methods in detail. The examples in this section
will be demonstrated on the basis of an executable file of the SSH client named putty.
There are several reasons for using this exact application as a test sample. Putty is
written in C++ and uses many libraries and API functions. Moreover, the introduction
of malware into the ssh client is attracting less attention, since the program is already
executing a tcp connection and, thus, it will be easier to avoid monitoring by the
security system.
Backdoor code [17] will be taken from the shellcode used for reverse TCP connection and written by Stephen Fever for meterpreter. The main goal is to inject the
shellcode into the target PE file without affecting functionality of the application.
The injected shellcode will run in a dedicated stream and constantly try to connect to
the handler. The second task is to remain as stealthy as possible during performance
of all these operations.
General approach to injection of a Trojan into a PE file includes four steps.
1. Identification of available space for the Trojan code;
2. Interception of the execution thread;
3. Trojan injection;
Précédent

- 210/839

Suivant