2.7 Example of Injection of a Software
199
Fig. 2.50 Modified version of the section of the shellcode responsible for connection to the handler
The problem is that if the connection to the handler is failed, execution of the
putty client will be stopped. As a result of introducing small changes, the shellcode
will reattempt connecting to the handler in case of failure. Moreover, the size of the
shellcode will be slightly reduced (Fig. 2.50).
After making changes within the assembly code, perform compilation using the
nasm-f command bin stager_reverse_tcp_nx.asm command. Now, the reverse tcp
shellcode is ready for use but is not yet placed in a proper location. Our goal is
to implement execution in a separate thread, the creation of which will require a
separate shellcode calling the API function CreateThread. The function will refer
to the initial reverse tcp code. The code for creation of threads from the metasploit
project was also written by Stephen Fever (Fig. 2.51).
After placing shellcode bytes inside the file createthread.asm in 16-bit format,
as shown in the figure above, perform compilation using the command nasm-fbin
createthread.asm. Now, the shellcode is ready to be injected in the code cave;
however, before injection it is necessary to perform encryption in order to bypass the
static/signature analysis of the antivirus. Since all coders from the metasploit project
are known to most antiviruses, it is recommended to use non-standard coding. Here,
we can use a combination of several standard encoders; however, it would be better
to use a combination of several encoders from the metasploit project. After each
coding action, load the shellcode in the raw form into the Virus Total project and
check the verification results (Fig. 2.52).
Fig. 2.51 Shellcode for creation of a separate thread
Précédent

- 220/839

Suivant