Last year, Tom and I worked on a project called Obfuscator for our forensics course. The project was to demonstrate, to our class, that changing file signatures was as easy as changing file extensions and therefore the thoroughness of file signature analysis tools is questionable. When Harlan blogged that anti-forensics , "techniques don't defeat tools...they defeat examiners." I quickly replied alluding to our (Tom and my) conclusion about fully understanding the capabilities of our forensic tools and how file identification (just like people authentication) is HARD.
A while back, Harlan asked a question about a script from Didier Stevens that embeds an executable inside a VBScript.
"What would you look for if you were analyzing a system and trying to determine if something like this had been used?"
Well no one posted a reply to you Harlan... and after thinking about this question since July 2nd, my response is still: I don't know.
Static file analysis could search for binary execution methods ... like Run for wscript ... but that would be impractical, I think. As with identifying a file, identifying a malicious script isn't as easy as it looks.
So rather than really answering Harlan's question, I'll ask one:
Is writing and executing an executable a common scenario in scripting?
Showing posts with label didier. Show all posts
Showing posts with label didier. Show all posts
Thursday, July 10, 2008
Subscribe to:
Posts (Atom)