4 ms·
The attacker is not going to keep the SHA256 hashes, but the whole of the original /boot. (Where, you're asking? Anywhere you forgot Ring 0 could store data, an
by rdancer 11y ago
The attacker is not going to keep the SHA256 hashes, but the whole of the original /boot. (Where, you're asking? Anywhere you forgot Ring 0 could store data, and a few places you never even knew about.) Subsequently, he will intercept system calls to open(2) and friends, and serve the saved data. This is a fairly old technique: on the first page of a Google search[1], you can find a Phrack article from 2009[2]. In fact the seminal work I believe is Reflections on Trusting Trust by Ken Thompson, set in print in 1984.
[1] https://www.google.co.uk/search?q=rootkit+intercepting+open+calls https://www.google.co.uk/search?q=rootkit+intercepting+open+...
[2] http://phrack.org/issues/66/16.html http://phrack.org/issues/66/16.html
[3] https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thomp...
- zokier 11y ago> Where, you're asking? Anywhere you forgot Ring 0 could store data, and a few places you never even knew about Could you be bit more specific about this?
- kentonv 11y agoThe BIOS has some flash memory. Various devices have flashable firmware. If the machine is on the network, storage could be remote. Maybe the attacker plugged a flash drive into a USB port. Maybe the attacker left a bluetooth-accessible device nearby. Or the attacker could just use the hard drive. Pick a random block. Chances are decent the corruption won't be noticed anytime soon, especially if the block is, say, at the end of the ext4 journal, which was probably clean at shutdown anyway.
- rdancer 11y agoYou won't likely have the opportunity to ask the attacker either. This uncertainty is an inherent part of the problem.