Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow New attack bypasses virtually all AV protection
EH-Net
May 23, 2013, 06:35:46 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: New attack bypasses virtually all AV protection  (Read 5870 times)
0 Members and 1 Guest are viewing this topic.
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« on: May 08, 2010, 01:06:28 AM »

Researchers at Matousec have devised a new attack technique, called the argument-switch attack or KHOBE attack, that allows malicious code to bypass protection mechanisms of security applications.

The method works by exploiting the driver hooks the anti-virus programs bury deep inside the Windows operating system. In essence, it works by sending them a sample of benign code that passes their security checks and then, before it's executed, swaps it out with a malicious payload.

The exploit has to be timed just right so the benign code isn't switched too soon or too late. But for systems running on multicore processors, matousec's "argument-switch" attack is fairly reliable because one thread is often unable to keep track of other simultaneously running threads. As a result, the vast majority of malware protection offered for Windows PCs can be tricked into allowing malicious code that under normal conditions would be blocked.

All that's required is that the AV software use SSDT, or System Service Descriptor Table, hooks to modify parts of the OS kernel.


ALL the security products tested were vulnerable to this attack. Matusec has listed all the tested products on their website. The attack works even with a limited account.

The complete article can be found here:
http://www.matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php

The Register also covered it in their article:
http://www.theregister.co.uk/2010/05/07/argument_switch_av_bypass/
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #1 on: May 08, 2010, 08:57:14 AM »

That's a very good read.   Thanks!
Logged

~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #2 on: May 08, 2010, 01:25:57 PM »

Great article!
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #3 on: May 10, 2010, 10:24:09 PM »

Just read SANS ISC's take on this subject. Patchguard might provide some protection, but it'll only work with x64 editions of Windows.
http://isc.sans.org/diary.html?storyid=8773&rss
« Last Edit: May 10, 2010, 10:27:51 PM by Equix3n- » Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #4 on: May 11, 2010, 04:10:27 AM »

i did some extra research on this one, and found another article by someone who claims its a relatively old attack:
http://seclists.org/fulldisclosure/2010/May/93

some more info on the TOCTOU binding flaw:
http://nob.cs.ucdavis.edu/bishop/papers/1996-compsys/racecond.pdf
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #5 on: May 11, 2010, 04:53:29 AM »

Paul Ducklin, Sophos's Head of Technology, Asia Pacific published an article on his blog. He argues that the khobe attack is just an overrated vulnerability. According to him, the attack works if the malicious code has already bypassed the antivirus in the first place.
http://www.sophos.com/blogs/duck/g/2010/05/11/khobe-vulnerability-earth-shaker/

The sample "attack" describes a way in which the tamper protection implemented by some anti-malware products might potentially be bypassed. Assuming you can get your malicious code past the anti-malware product in the first place, of course.

The attack needs a multiprocessor CPU, a security product which is using SSDT hooks and a bit of luck. It also requires that you evade detection by the security product in the first place in order to launch your Khobe code.

For what it's worth, only the optional Host Intrusion Prevention System component (HIPS) in Sophos's anti-malware software uses SSDT hooks. This is the behavioural part of our software, used for monitoring processes which we have already allowed to run. And HIPS doesn't even use SSDT hooks on Windows versions after XP, because Vista and Windows 7 include Microsoft's Kernel Patch Protection, which precludes the use of SSDT hooking.


The fuss about Khobe is in my opinion unwarranted, and the claims that it "bypasses virtually all anti-virus software" is scaremongering.

But these blog posts appear nothing more than 'saving face' kind of a thing. Unless other antivirus vendors come up with strong defenses we should believe that attackers have a good method at hand which they can and will use.
« Last Edit: May 16, 2010, 12:07:23 AM by Equix3n- » Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.