3 ms·
Hey OP, im not much of a math guy, I'm getting hung up on this part: SHA1(P1+C1+X) = SHA1(P2+C2+X) for any X. The example above seems like SHA1(GOOD_DRIVER)
by dickjocke 7y ago
Hey OP,
im not much of a math guy, I'm getting hung up on this part:
SHA1(P1+C1+X) = SHA1(P2+C2+X) for any X.
The example above seems like SHA1(GOOD_DRIVER) == SHA1(BAD_DRIVER+C2+X) somehow.
How does the C1 and X get appended to the signature of the good driver.
- cjm42 7y agoThe good driver consists of P1+C1+X. That's what gets sent to the signing authority. They verify it doesn't do anything bad and return a signature listing SHA1(P1+C1+X). But that signature is also valid for the malicious driver P2+C2+X.
- nneonneo 7y agoMost executable file formats (including drivers) put the code first followed by the data. So you could construct your drivers thusly: GOOD_DRIVER = P1 (good code and some data) + C1 (data) + X (more data) BAD_DRIVER = P2 (bad code and some data) + C2 (data) + X (more data) You'd disguise the random-looking block of C1 data in the middle of the good driver as e.g. a cryptographic key to avoid suspicion. The "more data" part couldn't be modified in the bad driver, but since you can arbitrarily modify P2 this wouldn't be a severe restriction.
- dickjocke 7y agothank you OP and everyone. I have that shaky initial understanding but makes much more sense.
- air7 7y agoHe said "innocent-looking device driver". The good driver is actually padded so that it can be later replaced with the bad driver. I.E This doesn't allow the attacker to replace any driver, but only one they prepared in advance to look innocent but have the right structure.
- dickjocke 7y agothat makes a lot more sense, thank you