
by Giorgos Poulios & Christoforos Ntantogian & Christos Xenakis
The downside of current polymorphism techniques lies to the fact that they require a writeable code section, either marked as such in the corresponding Portable Executable (PE) section header, or by changing permissions during runtime. Both approaches are identified by AV software as alarming characteristics and/or behavior, since they are rarely found in benign PEs unless they are packed. In this paper we propose the use of Return-Oriented Programming (ROP) as a new way to achieve polymorphism and evade AV software. To this end, we have developed a tool named ROPInjector which, given any piece of shellcode and any non-packed 32-bit Portable Executable (PE) file, it transforms the shellcode to its ROP equivalent and patches it into (i.e. infects) the PE file. After trying various combinations of evasion techniques, the results show that ROPInjector can evade nearly and completely all antivirus software employed in the online VirusTotal service. The main outcome of this research is: A) the developed algorithms for analysis and manipulation of assembly code on the x86 instruction set, and B) the release and demonstration of the ROPInjector tool.
ROPInjector: Using Return Oriented Programming For Polymorphism And Antivirus Evasion blackhat 2015 |
| 8 Likes | 8 Dislikes |
| 1,611 views views | 117K followers |
| People & Blogs | Upload TimePublished on 29 Dec 2015 |
Related keywords
- infosec news
- information security manager
- blackhat asia 2019
- blackhat 2019
- infosec twitter
- blackhat 2018
- black hat seo technique
- blackhat europe
- blackhat badger sekiro
- black hat x reader
- black hat cartoon
- black hat x dr flug
- cyber securityとは
- blackhat conference 2019
- cyber security cloud
- black hat full movie
- blackhat badger
- blackhat forum
- information security foundation 勉強
- infosec rotkreuz
- cyber security framework
- information security policy template
- infosecurity utrecht
- infosec ups system
- cyber security news
- cyber security act
- infosecurity
- blackhat full movie
- infosec blog
- black hat badger
- information security foundation 参考書
- information security management system
- cyber security conference
- black hat seo
- cyber security pro
- black hat movie
- blackhat imdb
- infosec podcast
- black hat cast
- cyber security pro 新しいネットワークが検出されました
- cyber security cloud managed rules
- cyber security measures
- information security governance
- infosec global
- infosecurity europe 2020
- infosec health
- infosec magazine
- information security 日本語
- infosec 19
- black hat anime
- information security foundation
- infosecurity magazine
- cyber security tokyo
- black hat meaning
- black hatch
- information security definition
- information security pdf
- infosec europe 2019
- cyber security market
- infosec institute
- infosec 2019 london
- information security foundation 難易度
- black hatch gamefowl
- cyber security management system
- information security certifications
- blackhat film
- cyber security pro アンインストール
- information security specialist
- cyber security 意味
- cyber security analyst
- information security policy
- black hat usa 2019
- information security forum
- information security news
- infosec conferences
- information security officer
- infosekta
- cyber security japan
- blackhat trailer
- information security analyst
- cyber security university
- black hat hacker
- black hat forum
- cyber security company
- black hat hacking
- black hat villainous
- blackhat conference
- information security foundation based on iso/iec 27001
- blackhat usa
- cyber security report
- blackhatworld
- black hat x demencia
- information security management
- blackhat cast
- black hat 2019
- infosec reactions
Không có nhận xét nào:
Đăng nhận xét