194
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.42 Parameters of the detected code caves
themselves), write rights are required in order to make changes inside the section
(Fig. 2.42).
Utilization of several code caves helps bypass the space-related limitations. Additional advantage here is the fact that a software Trojan is assembled from separate
parts. However, alteration of privileges of a section will look suspicious. There are
advanced methods for modification of privileges of memory areas during execution of
an application for the purpose of preventing direct alteration of section flags; however,
since these methods require a specialized shellcode and IAT table encryption and
parsing, this subject will be covered in the following article.
The utility program Cminer helps easily calculate all cold caves of a binary file.
Let us use the ./Cminerputty.exe 300 to find a code cave with a size of over 300 bytes.
In this case, five nice exhibits for further use are found. The starting address sets
the virtual memory address (VMA) of the code cave when the PE file is loaded
into the memory. The offset of the file (measured in bytes) is the address of the
required area within the PE file. The search results revealed that most areas are
located inside the data section. Since these sections contain no flags for execution,
changes will be required. The size of the backdoor is about 400–500 bytes, and the
area Cave 5 will be more than enough. Start address of this area needs to be changed;
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.42 Parameters of the detected code caves
themselves), write rights are required in order to make changes inside the section
(Fig. 2.42).
Utilization of several code caves helps bypass the space-related limitations. Additional advantage here is the fact that a software Trojan is assembled from separate
parts. However, alteration of privileges of a section will look suspicious. There are
advanced methods for modification of privileges of memory areas during execution of
an application for the purpose of preventing direct alteration of section flags; however,
since these methods require a specialized shellcode and IAT table encryption and
parsing, this subject will be covered in the following article.
The utility program Cminer helps easily calculate all cold caves of a binary file.
Let us use the ./Cminerputty.exe 300 to find a code cave with a size of over 300 bytes.
In this case, five nice exhibits for further use are found. The starting address sets
the virtual memory address (VMA) of the code cave when the PE file is loaded
into the memory. The offset of the file (measured in bytes) is the address of the
required area within the PE file. The search results revealed that most areas are
located inside the data section. Since these sections contain no flags for execution,
changes will be required. The size of the backdoor is about 400–500 bytes, and the
area Cave 5 will be more than enough. Start address of this area needs to be changed;
