???? from ??? - PowerPoint PPT Presentation

About This Presentation
Title:

???? from ???

Description:

Title: 1 Author: Daisuke Shimamoto Last modified by: Daisuke Shimamoto Created Date: 10/19/2004 1:28:40 PM Document presentation format – PowerPoint PPT presentation

Number of Views:49
Avg rating:3.0/5.0
Slides: 16
Provided by: Daisu
Category:
Tags: hacking | windows

less

Transcript and Presenter's Notes

Title: ???? from ???


1
????????(2)
  • ??4??
  • ?? ??
  • 2004?10?29?

2
??
  • ????
  • ?????

3
????
  • ??????
  • ???? from ???
  • Detours ?????????
  • ??????????

4
????
  • ??????
  • ???? from ???
  • Detours ?????????
  • ??????????

5
???? from ???
  • ?????????? ?????????????
  • ?Windows ?? Portable Executable

6
Portable Executable
  • Windows ?????
  • .exe, .dll, ??
  • ????? VAX/VMS ?Common Object File Format (COFF)
  • Portable ? ????????????
  • Alpha, WindowsCE, ??

7
Portable Executable Format
Unmapped Data
.reloc section
other sections
.data section
.text section
Section Table
PE Header
DOS Header
8
????
  • ??????
  • ???? from ???
  • Detours ?????????
  • ??????????

9
Detours
  • Win32 API ???????
  • Microsoft Researchhttp//www.research.microsoft.c
    om/sn/detours/
  • ??????????????
  • ??????

10
????
  • ??????
  • ???? from ???
  • Detours ?????????
  • ??????????

11
??????????
  • ????????????
  • ?????Sandbox
  • Win32 API???????????
  • Linux ???????????????????(?)
  • ??????????????????????

12
API????
  • Win32 API????????
  • Detours ??????????
  • Windows ???????
  • PE??????

13
Hacking Virus on Windows
  • ???????????
  • ?? exploit code ? Virus code ????
  • Web?????????

14
????(1)
  • An In-Depth Look into the Win32 Portable
    Executable File Format(Part 1 2)
  • http//www.msdn.microsoft.com/msdnmag/issues/02/02
    /PE/default.aspx
  • http//www.msdn.microsoft.com/msdnmag/issues/02/03
    /PE2/default.aspx
  • Process-wide API spying
  • http//www.codeproject.com/system/api_spying_hack.
    asp
  • API Spying Techniques
  • http//www.internals.com/articles/apispy/apispy.ht
    m

15
????(2)
  • detours
  • http//research.microsoft.com/sn/detours/
  • Phrack
  • http//www.phrack.org/
  • packet storm
  • http//www.packetstromsecurity.org/
  • New order
  • http//neworder.box.sk/index.php
  • VX heavens
  • http//vx.netlux.org/
Write a Comment
User Comments (0)
About PowerShow.com