200
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.52 Shellcode injection
Combine the encoders until the shellcode is fully invisible (or wait for the
following article). After valid encryption, shellcode is ready for injection into the code
cave. Select the instruction following PUSHFD and press Ctrl + E in the Immunity
Debugger. The shellcode will be inserted in the 16-bit format.
It is possible to acquire the encrypted 16-bit shellcode by two means: print it
using the command xxd -ps createthread, or open and copy it in a 16-bit editor.
When copying 16-bit values and pasting them into the Immunity Debugger, don’t
forget about limitations on the copied bytes, which are applied during code insertion.
It is necessary to remember the last two inserted bytes, press the button OK, and recopy the following sections. After the shellcode is fully inserted into the code cave,
the injection procedure can be considered done.
2.7.6 Execution Thread Recovery
After creating execution flow for the hardware Trojan, it is necessary to renew execution of the main program. That is, the EIP register must refer to the function that
redirected execution to the code cave. However, before switching to this function, it
is necessary to recover the previously saved registers (Fig. 2.53).
Fig. 2.53 Instructions for the recovery of initial state of registers
Précédent

- 221/839

Suivant