Sponsor Advertisements help keep UGN Security Online.
Sponsor Advertisements help keep UGN Security Online.
Want to earn prizes for clicking online advertisements? Join Rewards1.com.
|
|
|
#15929 - 12/16/05 12:55 AM
Intercepting Windows System Messages
|
Junior Member
Registered: 12/15/05
Posts: 5
Loc: University
|
I've spent the last several days investigating a specific topic and have hit a lot of dead ends. I've been reading a lot of articles and forums at sites such as UGN Security Sec, Packet Storm Security, and Insecure.org and really have not come up with much. I hope someone can help me, here's what I've been looking for: As part of a research project I've been investigating how to intercept System Messages. More specifically, I'm looking for a program that can reside in memory outside of the Windows environment while retaining the potential to intercept and alter any messages passed back and forth between windows and hardware. In essence, it acts like a wrapper, or VM ware, with windows running inside it. (The key is that windows would be unaware of its existance.) It's possible something like this at one point existed and is now obsolete, but if anyone's heard of something like this, or anything fairly similar, I'd love to know. Even if it is really old and out-of-date. Thanks in advance.
|
|
Top
|
|
|
|
Sponsor Advertisements help keep UGN Security Online.
Sponsor Advertisements help keep UGN Security Online.
|
|
#15931 - 12/16/05 08:03 PM
Re: Intercepting Windows System Messages
|
Junior Member
Registered: 12/15/05
Posts: 5
Loc: University
|
Thanks for the info, it's been helpful. It does bring me to other questions though.
When a typical Master Boot Record program fires up it gets dumped into memory address 0000:7c00. It then copies itself into address 0000:0600 and then load the windows boot partion into address 0000:7c00.
The MBR program at 0000:0600 is about 86 bytes, and the partition table resides at 0000:07be to 0000:07fd. This leaves 226 bytes to play with in the MBR program, (0000:06db to 0000:07bd.) I've 'altered and expanded' the MBR program in the past for specific needs.
So here's my question: When Windows XP, Win Server 2003, etc boot-up they start at 0000:7c00. Does the boot sequence wipe the memory at the lower address spaces thus stopping my alterations? Also, any 'keylogger' applications running within windows would be locked out of the 'ctrl+alt+del' login screen. That's why I need something running outside of the Win Enviornment. Any thoughts?
THanks in advance. You've been very helpful.
|
|
Top
|
|
|
|
#15932 - 12/18/05 01:01 AM
Re: Intercepting Windows System Messages
|
UGN Elite Poster
Registered: 03/09/02
Posts: 1041
Loc: Canada eh
|
I think that you already hit on a decent way to go about it. Something like vmware or Xen sounds like the way to go. Xen is even opensource so you can potentially modify it to dump the info you are looking for. So here's my question: When Windows XP, Win Server 2003, etc boot-up they start at 0000:7c00. Does the boot sequence wipe the memory at the lower address spaces thus stopping my alterations? I'm a little outta my element here, but I would theorize the way to go about it would be to write a "bootloader" or simple OS that sits there, and then runs windows on top of itself in higher memory addresses... I have no idea if this is even possible.
|
|
Top
|
|
|
|
#15933 - 12/30/05 10:10 PM
Re: Intercepting Windows System Messages
|
Junior Member
Registered: 12/15/05
Posts: 5
Loc: University
|
Hey, thanks for the information. I've been busy reading through most of the Xen documentation. (I've also been pouring into VMWare too.) For what I plan on building though these two have a lot of overhead, (ie they have way too much functionality for what I'm looking for.)
I think what I'm going to do is build my own custom VM Application. I'll be referencing a lot of books along with Xen and VMWare (withOUT stealing/using their code or intelectual property.) So would you happen to know of any other good sources I might look into?
For instance, WinXP on Xen has a cost metric of over 4600 (and growing) lines for the porting comodity. I'd hate to have to discover and deal with each issues one at a time. So I'm looking for anything that could help expidite this process. Got any ideas?
And thanks so much, you both have been very helpful.
|
|
Top
|
|
|
|
#15934 - 12/31/05 05:30 AM
Re: Intercepting Windows System Messages
|
UGN Super Poster
Registered: 10/08/02
Posts: 955
Loc: Merrill, IA, USA
|
To start off, more specifically, what do you mean by systems messages? There are several applications that can monitor windows behavior inside the operating system, and ways to get around a program showing up in the Task Manager such as using a rootkit method that Sony has recently made headlines with. Even VMware has a host operating system that is was developed for. I would find the attempt to develop a similar program, let alone one that isn't noticeable to an end user, to be an enormously challenging task.
|
|
Top
|
|
|
|
#15935 - 01/03/06 05:42 PM
Re: Intercepting Windows System Messages
|
Junior Member
Registered: 12/15/05
Posts: 5
Loc: University
|
By system messages I mean the communication between hardware and the OS, (such as scancodes from the keyboard.) And you're right, taking on that task would be enormous.
Rootkits seem likely but they do run within the OS environment. Maybe I should spend more time looking into them. Basically here's what I've been researching: I'm looking for as many ways theoretically possible, (a proof of concept,) to capture the "ctrl+alt+del" login sequence for Windows. I don't need to capture keystrokes in a web browser, that's been done to death. Something that runs stealthly would be a nice feature but is not manditory on all concepts.
If I remember correctly, the loging seqence is locked down by Windows so most keyloggers, (the ones I looked into and studied,) don't work. So, would you have any other possible methods/sugestions/theories of how this capture could be acheived?
Thanks again for your time and Good article about Sony's rootkit too. I remember reading about it back in early Nov.
|
|
Top
|
|
|
|
#15937 - 01/05/06 03:35 PM
Re: Intercepting Windows System Messages
|
Junior Member
Registered: 12/15/05
Posts: 5
Loc: University
|
Excellent information guys. I also found a whitepaper published eEye, Remote Windows Kernel Exploitation , that I found to be very useful too. Worth checking out.
|
|
Top
|
|
|
|
|
Registered: 03/01/02
Posts: 505
|
|
2198 Members
46 Forums
24781 Topics
59951 Posts
Max Online: 1567 @ 04/25/10 10:20 AM
|
|
|
0 registered (),
318
Guests and
257
Spiders online. |
|
Key:
Admin,
Global Mod,
Mod
|
|
|