198
2 Computer Viruses, Malicious Logic, and Spyware
2.7.5 Introduction of a Hardware Trojan Code
The first thing that comes to mind during introduction (engineering) of a backdoor
is to save registers before executing a malicious code. Every value inside registers is
extremely important for software execution. By placing the instructions PUSHAD
and PUSHFD in the beginning of a code cave (Fig. 2.48), we can save all registers
and register flags inside a stack. These values will be returned after executing the
malicious code, and the program will continue execution without any problems.
As mentioned earlier, our backdoor is a reverse tcp shellcode for meterpreter,
taken from the metasploit project. However, the shellcode will require certain inside
changes. Usually, reverse tcp shellcode tries to connect to the handler a number of
times; in case of failure to connect, the process is closed by calling the ExitProcess
API function (Fig. 2.49).
Fig. 2.48 Placing the PUSHAD and PUSHFD instructions before the code cave
Fig. 2.49 Section of the shellcode responsible for connection to the handler
Précédent

- 219/839

Suivant