|
http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=81 [복사]
which funny story ** really hard when i was trying to do it demo
한가지 재밋는 얘기가 있는데요, 제가 시연하려고 했던 Code Red 는
** code red i manage to after working on me managed *** my demo on day *** still idle.
작업기간이 끝났지만 아직도 완료하질 못했어요.
the other reasons you wanna have good to assembly is that you can reuse the code fragments.
여러분들이 어셈블리를 잘 하고싶어하는 다른이유는 바이너리 내에 있는 코드 조각들을 다시 사용할 수 있게 된다는 거에요.
It's meaning you can actually take pieces out of malicious? code.
이 말은 즉, 악성코드 내에 특정 부분을 꺼내올 수 있다는 말이되죠.
maybe there's a particular function that does some encryption / decryption doesn't communication routine
아마 그중에는 뭔가를 암호화하거나 복호화하는 함수들이 있을 수도 있구요,
and the if neccessary want you disassemble and identify ** piece you can poll **** if there's need to do that.
디스어셈블 하거나 어떤 루틴이 어떤 일을 하는지 알아야 할 경우에도 꺼내 올 수 있죠.
I usually find there's not application we have added? it to pull the piece out and i wanna write it outside the program.
저는 뭔가 쓸만한 루틴을 담고있는 프로그램이 있는지 찾아보곤 합니다.
You can also if you have a need to,
또한 여러분들은 필요하다면,
I hopefully most of time you * , you can actually make modifications to a pieces of malicious code.
여러분들은 악성코드 내 특정 루틴에 수정을 가할 수도 있을겁니다.
and in order to useful research purposes, I ** couple of times or I've taking a worm and i partially *** it?
그리고 연구적인 목적을 위해서, 웜(바이러스) 를 테스트 할 때도
in order to make a little bit safier work with
안전하게 작업하기 위해서 웜의 일부분만 실행 시킬 수도 있습니다.
or so that i could run one piece of it and not have rest of the code and infected?? in the box or
혹은 당신의 시스템을 감염시키는 부분을 제외하고 특정 부분만 수행할 수도 있겠구요.
you know, that sort of things.
뭐, 그런것들이 가능합니다.
so, hopefully most of time you have to do this , one problem to disassembly is often?? time its slowest method to get particular answer but it is most implete?.
여러분들이 이런작업을 할때에, 디스어셈블링의 한가지 문제는 뭔가 답을 얻어내기 위해서 굉장히 오랜 시간이 걸린다는거에요.
Is particular purpose to disassembly and this is un? and for piece of malicious code that's probably just? about the only reason you'll be looking at and you wanna know what it does.
디스어셈블링의 주된 목적은 여러분들이 해당 코드가 어떤 일을 수행하는지 알게되는 것입니다.1
you now actully trying to run it. for example.
아마 그러기 위해서 해당 프로그램을 실행해보겠죠.
you trying to get the binary into you head, you trying to install this worm ** you brain you have some ideas how it works.
여러분들이 해당 바이너리를 머리속에 집어넣고 그걸 설치하면 이 바이너리가 어떻게 동작하는지 알 수 있을꺼에요.
if you work for company that does report to that's sort of things,
만약에 여러분들이 악성코드같은 것들에 대해 레포팅하는 회사에서 일한다면,
you trying to ** you had **** go back and do report? on or hand it off to the guys who wanna write? at this infector?
작성되는 악성코드 관련 레포트들을 공격자한테 넘겨주거나, (???)
or you wanna be able to write some tools that can spot identify maybe some IDS and intrudes?
혹은 침입자를 탐지하는 프로그램을 작성할 수 있을겁니다.
Most of the time you are not trying to modify the binary. find a vulnerability in it. or fix and improve it.
바이너리를 수정하지 않는다면 그 시간에, 여러분들은 취약점을 찾거나 취약점을 고칠 수 있습니다.
this is little bit different from a number of other type true reverse engineering you might do.
이것은 여러분들이 하게 될 다른 리버스 엔지니어링들과 좀 다를겁니다.
this is ** someone's? been talked about someone's? is something else she might do my prefer example.
if you trying to crack the ** scheme or some other protection on a program, typically you can be modifying the binary as you in result.
여러분들이 프로그램상에 걸려있는 어떤 보호장치를 크랙하려고 한다면, 결과적으로 바이너리 자체를 수정해야된다는 것을 의미합니다.
we're not trying to do that with the worm as usually.
보통 웜에 대해서 수정작업을 하진 않죠.
for vulnerability researching , trying to find particular function calls , and the program trying check buffer sizes.
취약점 연구를 위해서는 특정한 함수호출를 찾거나 버퍼사이즈를 계산하거나 할겁니다.
all those sort of things she was due to fuck find vulnerability in program or not trying to usually do that with the worm.
이러한 작업은 취약점을 찾기위해서 수행되는 것이지 일반적으로 바이너스에 대해 수행되는 작업은 아닙니다.
[ **** ] you've been some interesting
A buffer overflows in the worms move * one of the worm took advantage of a overflow on ftp server of a previous worm.
웜에서의 오버플로우가 의미하는 것은, 이전 웜에서 다른 웜으로 옮겨갈때 ftp 서버에서의 오버플로우 취약점을 이용하거나 해서 더 효율적일 수 있다는 것이다.
You are not trying to bug *** , you are not trying to make work better.
어떤 코드에서 버그를 찾아내지 않는다면, 그 코드는 더 안정적으로 만들어질 수 없다는 것을 의미합니다.
I'm giving example,
예를 하나 들어볼께요.
In the * nimda worms * couple years back,
몇년전에 님다 바이러스가 유행한적이 있었습니다.
there was a routine in it where it would go through
이 님다바이러스는 어떤 루틴을 가지고 있었는데,
and infect the bunch of the files or move the bunch of the files , drop itself , that sort of things.
이 루틴은 파일들을 감염시켜서 이 파일들을 옮기거나 스스로 지워버리거나 하는 등의 악성코드였죠.
This aim routine was used to go through and delete everything on your hard drive.
이 루틴은 결과적으로 하드드라이브의 모든것을 지워버리는 일을 수행했습니다.
** called nimda ** actually did that that's because they was a fly-crew **** just dont do this
I guess the [ virus*** ] have nervous ** that particular feature off.
아마 그런 이유로 특정한 Virus머시기 가 해당 기능을 꺼버렸죠.
we're not neccesary trying to debug it and fix it turn the features back on .
우리는 이걸 다시 키기 위해서 디버깅하거나 수정할 필요는 없습니다.
We are not trying to do usually for a piece of malicious code analyze it ** purposes of polling out * algorithms,
우리는 특정한 알고리즘을 뽑아내기 위해서 악성코드를 분석할 필요가 없습니다.
we're not trying to reverse engineer so that we can inner-operate? properly.
리버스 엔지니어링 할 필요도 없죠.
we are not trying to figure out the legal? algorithms that it does so that we can [ ****** program ].
and these are some of reasons why malicious code analysis is easy.
지금 보시는 것들은 악성코드 분석이 쉬운 이유입니다.
I think easy **** easier than , for example, reverse engineering attendendy? ask ***
we dont need to patch the binary typically
우리는 기술적으로, 바이너리를 패치할 필요가 없습니다.
we already knows some of what it does this isn't important features.
왜냐하면 우리는 이미 어떤일을 수행하는지 부분적으로라도 알고있고, 그것들은 크게 중요한 부분이 아니기 때문이죠,
you have a suspicion ** that this piece of code we're looking at has ** charactors she knows piece of maliicious code or have strong suspicion in it is.
우리는 바이너리 내에 의심스러운 부분들을 이미 알고있으며, 이 부분들은 몇가지 악성코드가 전형적으로 갖게되는 문자열들을 포함하고 있습니다.
and often times the way you got it tell you ** about how *** already , for example , if you aware of this worm out there, *** honey pot to ***** analyze it
you are ** that worm you know how spead someone *** what port number they uses , that sort of thing
so we can make big sweeping assumptions allow the time we ** malicious code. and this being step when we looking through steps into the binary
you can say 'oh ok i can see this routine looks like mailer?? ask HTTP client and talk gonna assume that allow the code below at [*******]
and the only *** by need to *** not piece |
Hit : 2135 Date : 2011/08/02 04:10
|