Runtime Process Insemination

Presented at THOTCON 0x4 (2013), April 26, 2013, noon (50 minutes)

Writing malware on Linux isn't an easy task. Anonymously injecting shared objects has been a frightful task that no one has publicly implemented. This presentation will show how and why malware authors can inject shared objects anonymously in 32bit and 64bit linux and 64bit FreeBSD. The presenter will be releasing a new version of a tool called libhijack. libhijack aims to make injection of arbitrary code and shared objects extremely easy. There will be a live demo injecting a root shell backdoor into multiple programs during runtime.


Presenters:

  • Shawn "lattera" Webb
    Shawn Webb is a professional security engineer. He has been studying and developing runtime process infection techniques for the past few years.

Similar Presentations: