5 ms·
> any that execute code at boot. Boot-sector virii died off in the late 90 Are you sure? It looked like rootkits/bootkits are still pretty rampant?
by shadowfox 14y ago
> any that execute code at boot. Boot-sector virii died off in the late 90
Are you sure? It looked like rootkits/bootkits are still pretty rampant?
- sophacles 14y agoThe security world is as driven by fashion and old-concepts-with-new-names as the rest of the software industry. The general treadmill is basically 1. Look at this bug! lolz,pwnd 2. Script kiddie tools made around it and lots of variants are popular 3. Security improves as prevention tools get better 4. 0day experts look in other systems. (aka goto 1 with a different subsystem argument). 5. Eventually, as techniques in all subsystems improve, the original area of exploration is again the lowest hanging fruit, with a slightly different guise. For example - SQL injection is just a variant of the old pipe injection attack (also, pipe injection is coming back a bit, because newer programmers haven't seen it, and older programmers have forgotten about it). Another example you're starting to see more of again: IP stack attacks - as ip is being offloaded into the NIC you're starting to see a revival of "lets see what we can do to the ip stack" but this time it's in the card itself. (Actually there is some really cool stuff going on here...) So yeah, boot time attacks are pretty common and in these days, but not necessarily in the main boot path, but in cards with firmware, especially those that have DMA. Additionally with tools like metasploit, you can keep around a huge toolkit of root-kits and so on, so if a system is vulnerable to known boot-time exploits, you can use them even if you'd forgotten them.
- asdfs 14y agoCan you elaborate on "pipe injection"? I can't find references to the term after brief searching, and I'm curious.
- sophacles 14y agoSure, you know how SQL injection is just adding extra SQL statements to user input, and taking advantage of improper escaping to get the database to do your bidding? Pipe injection is the same thing but in cases where shell commands are called with arguments taken from user input. It was very common in older Unix systems to have various bits of a complicated system actually just be the result of another standard command with proper args/input. So you find a place where something like system is used, or there is a call to sh -c , or so on, and if the input is improperly escaped, add: |adduser ... or change the password, or so on to get a root shell or account. This has actually come back into style in certain places again, because so many devices are just linux boxes with busybox utils on constrained systems (think home routers for example a lot of those just display the output from various linux commands in their firewall stuff). But programmers don't always think about "what if someone is going to try and do pipe on this..." and you end up with a pipe injection. It also can be used for privilege escalation if you have a lot of custom setuid stuff available for your sysadmins and someone manages to get a local account. (unfortunately more common than one would hope).
- asdfs 14y agoAh, I see. Thanks for the explanation.
- pmh 14y agoYou'll find it under the slightly more general 'command injection'[1] which includes the use of other shell operators as well [1] https://www.owasp.org/index.php/Command_Injection https://www.owasp.org/index.php/Command_Injection
- kunai 14y agoNot on Linux. And in my 10+ years of Windows computing, I have never once gotten a bootkit. It's simple: install a myriad of security applications, and don't visit any suspicious websites. It's common sense, really.
- jiggy2011 14y agoHow do you know if you have a bootkit? I could have one running on my system right now syphoning off data, I probably don't but I can't think of any way that I could prove that I didn't even if I ran every anti-malware program in the world.
- rjbond3rd 14y agoNot proof, I guess, but possible countermeasures: * run the OS from (known good) media mounted read-only (in the olden days, some websites ran off Knoppix CD's and rebooted often :) * (Red Hat): rpm -Va to verify the package database, binaries, config files etc. (after verifying the original package database hasn't changed, by checksumming / diffing with an offline copy) * iptables rules which drop (and log) all traffic on all interfaces (then selectively add minimalist rules)
- DanBC 14y ago> in the olden days, some websites ran off Knoppix CD's and rebooted often That sounds horrific for performance.
- beagle3 14y agoNot at all. Once the OS and webserver (and whatever apps you need) are in memory, it's just as fast as a hard-drive. Non executable data (the majority of data served by webservers) can still reside on magnetic media or on a NAS.
- anonymfus 14y agoDid you hear about TDL/TDSS bootkit? http://www.nobunkum.ru/analytics/en-tdss-botnet http://www.nobunkum.ru/analytics/en-tdss-botnet 16 millions were infected. Distributed via partner programs with download sites, including bundling with installers Oracle-way. Do you think that because you were not affected such cases must not be prevented?