CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Rootkit question

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sun Sep 17, 2006 8:11 pm    Post subject: Rootkit question
Reply with quote

Say I have a folder that contains rootkit cloaked files . I right click that folder , select properties and note the number of files reported to be inside . I then slave that drive to a clean machine and check the properties of that same folder .

Will the rootkit cloak prevent accurate reporting of the file count resulting in a different number being reported ?

Back to top
View users profile Send private message Send email
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Mon Sep 18, 2006 1:17 am    Post subject:
Reply with quote

no you should get a true reading on the files in the folder if its slaved or viewed from a live cd.
because the rootkit loads with the os on the drive that had os on it once its slaved or live cded that os don,t load so the rootkit not loaded so it cannot hide the files.

i have wondered if there are any that can load to clean machine well scanning slaved drive they end up in that machines ram. then install there.

if none yet i would say its not long until there is. and or install on a none slaved drive ie on original machine when scanned by certain apps they block there presence and install.
jmho


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Mon Sep 18, 2006 8:06 am    Post subject:
Reply with quote

What I was getting at was would there be a discrepency in file counts between the live and slave check . It would be a handy way to check for new rootkits . For instance if the driver folder reported 100 files and the same folder reported 102 when slaved this would confirm a rootkit was installed .

My question is do live rootkits also fool file counts (I have not checked this yet) . I know that they don't hide on a slaved drive .

Back to top
View users profile Send private message Send email
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Mon Sep 18, 2006 8:29 am    Post subject:
Reply with quote

I tested this and it does work .

Back to top
View users profile Send private message Send email
wng_z3r0

MRU Teacher


Joined: Mar 21, 2005
Posts: 1248

1st Responders MVP RootKit Detection Hosts Rootkit Experts Team F@H

PostPosted: Mon Sep 18, 2006 12:05 pm    Post subject:
Reply with quote

how can you right click the folder if it is cloaked?


_________________
Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Mon Sep 18, 2006 1:37 pm    Post subject:
Reply with quote

Not a rootkit hidden folder , a folder that contains rootkit hidden files .

This is what I did . First I infected my test machine with a haxdoor rootkit . Then I right clicked the system32 folder and selected properties . It reported 4580 files . RootkitRevealer reported 2 files hidden in that same folder . Finally I slaved the infected drive to my work machine and checked the properties of system32 on that drive . It reported 4582 files .

This could be used to check for unknown rootkits . If a live drive reports xxxxx files and the same drive reports xxxxx+y files when slaved to a clean system then a rootkit is likely .

I just never checked if rootkits also fooled folder properties before . Now I know .

Back to top
View users profile Send private message Send email
wng_z3r0

MRU Teacher


Joined: Mar 21, 2005
Posts: 1248

1st Responders MVP RootKit Detection Hosts Rootkit Experts Team F@H

PostPosted: Mon Sep 18, 2006 8:45 pm    Post subject:
Reply with quote

if a rootkit wanted to fool the file properties, it would just be one more API call to hook...


_________________
Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Mon Sep 18, 2006 10:13 pm    Post subject:
Reply with quote

wng_z3r0 wrote:
if a rootkit wanted to fool the file properties, it would just be one more API call to hook...


Check my post again . Folder properties do indeed misrepresent file counts when the folder contains some cloaked files .

Haxdoor infected live system : system32 = 4580 files + 2 cloaked files reported by RootkitRevealer .

Same drive slaved to a clean system : system32 = 4582 files

This could be a good way to check for unknown rootkits for advanced users and technicians .

Back to top
View users profile Send private message Send email
wng_z3r0

MRU Teacher


Joined: Mar 21, 2005
Posts: 1248

1st Responders MVP RootKit Detection Hosts Rootkit Experts Team F@H

PostPosted: Tue Sep 19, 2006 12:00 pm    Post subject:
Reply with quote

that is simply because hacker defender is not cloaking that api call. It is security through obscurity. If this method becomes popular, then it would only take a slight change in the code to cloak the file properties. Any ADS rootkit (like the current grozomon one) will also hide from this method.


_________________
Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Sep 19, 2006 12:59 pm    Post subject:
Reply with quote

wng_z3r0 wrote:
that is simply because hacker defender is not cloaking that api call. It is security through obscurity. If this method becomes popular, then it would only take a slight change in the code to cloak the file properties. Any ADS rootkit (like the current grozomon one) will also hide from this method.


Are you saying that this will likely not be reliable because rootkits could be coded to give the real file counts even though the folder contains cloaked files ? (I do understand that ADS would fool this BTW)

If this is what you are saying then I was misreading your earlier posts .

I do think that as a final test (when all others come up negative) checking for variations in file count between live and slaved could be useful . Obviously it is not a definitive test or one that I would try first . It is fast and easy so I think that it has its place though .


**Just to make this clear to anyone reading this . I do not recommend this as a way to start looking for a rootkit or as a reliable rootkit test .**

Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer