4 ms·
What I wonder about is what do they mean by "stealth programming"? I can think of just programming with white text on a white background, but that wouldn't ser
by starev 17y ago
What I wonder about is what do they mean by "stealth programming"? I can think of just programming with white text on a white background, but that wouldn't serve any security related purpose.
From reading that, it's clear that the shellcode was obfuscated ('encrypting' it three times, though, would be unnecessary), but that's just a good way to muddle things up. Although from reading that it's obvious that it was a sophisticated attack in this day and age of cybercriminals who go for the easiest target available, nothing mentioned there hasn't been possible for almost any buffer overflow attack. Code obfuscation has been used for years for copy protection and to prevent static reverse engineering in general, and although nonstandard in exploitation, by no means unheard of. In my opinion a more impressive exploit would be one which used all printable ascii (which also is possible).
On a side note, some of the terms used are either misused or just wrong: although the payload may have been obfuscated, 'encryption' at least to me implies separate key/decryption schemes, which don't really work well from a shellcode point of view. You'd be better off using a static 'encryption' scheme like ROT13, but that seems more like obfuscation in this day and age, particularly since the code to deobfuscate it would have to be built in.
TL;DR: I think they throw around 'encryption' in places where it doesn't make sense to use it because it makes it sound scary, and it doesn't seem like any of the techniques used were 'new' or somehow more sophisticated then what was previously possible.
For simple IDS evasion, at least, so that you aren't throwing up flags: it could've been done to make forensics much harder.
- brown9-2 17y agoThis is something I had a hard time understanding and which I thought the article did a poor job of explaining. In exploiting a remote system, which part of your attack would benefit from being encrypted?
- gregcmartin 17y agoOk so they use what's called packers to not only obfuscate the malware code to bypass signature based A/V but also hide inside other binaries or Dll's to further evade heuristic defenses. Then a reverse encrypted tunnel for control of infected machine was routed over normal HTTPS also undetectable by IDS. It was to dynamic dns domains such as yahoo1.dyndns.org. Reverse meaning it connects back to the attacker to allow ssh like access to the compromised host via the trojan. There are all extremely advanced (but known) evasion steps for a very targeted attack. It's rare to see all of them successfully used in one attack because of the complexity and skill required.
- starev 17y agoIf you encrypted or otherwise obfuscated the payload of the attack, it would make log analysis (particularly on the network level) difficult, and may help get around things like an IDS. It'd also make some forms of forensics much harder.