Yes that’s exactly what I’m saying. In a particular instance, where the
malware author brought his “victim” software back to his build machine for
analysis, and typically ran it using a user mode debugger like ollydbg, then
the technique was successful, as he didn’t realize his driver had been
dumped by the victim software, and this information gleaned, even though he
had gone to extreme lengths to protect it by destroying the DEVICE_OBJECT
header, and hooking calls like MmIsAddressValid, NtLoadDriver, and
implementing a whole host of other nasty hooks and subversions.
I will be awfully glad when only signed drivers can be loaded on both 32bit
and 64bit machines, and there is no bypass whatsoever.
-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Pavel A.
Sent: Thursday, September 11, 2008 17:44
To: Windows File Systems Devs Interest List
Subject: Re:[ntfsd] How to get rid of PDB file name in FREE build of a
driver ?
Crispin Wright wrote:
…
I have known specific malware to be “counter attacked” based on
this path and pdb being found by a “legitimate” product (the specific
target
of the malware itself)
Hmm this is interesting idea. But again, the path part of the pdb
filename is local to the build machine, this path may be meaningless
where the driver is deployed.
All this path is worth for, is to save few motions for a dev who builds
and runs windbg on same machine.
–PA
NTFSD is sponsored by OSR
For our schedule debugging and file system seminars
(including our new fs mini-filter seminar) visit:
http://www.osr.com/seminars
You are currently subscribed to ntfsd as: xxxxx@blocksoft.co.uk
To unsubscribe send a blank email to xxxxx@lists.osr.com
__________ Information from ESET NOD32 Antivirus, version of virus signature
database 3435 (20080911) __________
The message was checked by ESET NOD32 Antivirus.
http://www.eset.com
__________ Information from ESET NOD32 Antivirus, version of virus signature
database 3435 (20080911) __________
The message was checked by ESET NOD32 Antivirus.
http://www.eset.com