22.03.2013 Views

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>The</strong> Four Evil Masters<br />

Media Analysis countermeasures fall into four categories<br />

Data Destruction (file wiping, scrubbing file system metadata)<br />

Data Hiding<br />

In-Band (file system structures, e.g. FISTing)<br />

Out-of-Band (slack space)<br />

Application Layer (hiding data in the registry)<br />

Data Transformation (encryption, direct alteration, code morphing)<br />

Data Fabrication (VERSIONINFO, introduce a known bad file)<br />

© <strong>Below</strong> <strong>Gotham</strong> <strong>Labs</strong>, 2009<br />

37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!