22.03.2013 Views

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Bootkits<br />

Bootkits use a Hybrid Approach<br />

<strong>The</strong>y Use Binary and Runtime Patching<br />

<strong>The</strong>y Execute in Real Mode and Protected Mode<br />

Load & Patch Iterative Technique<br />

Hook INT 0x13 (real-mode disk I/O interrupt)<br />

Scan for byte pattern of a target module<br />

Patch the module after it loads (and before it executes)<br />

Installed patch does the same for some following module<br />

This process repeats itself until startup has completed<br />

© <strong>Below</strong> <strong>Gotham</strong> <strong>Labs</strong>, 2009<br />

24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!