Continued with library injection attack

This commit is contained in:
h3xduck
2022-06-09 22:57:25 -04:00
parent a46339e912
commit 1595caa8d0
22 changed files with 957 additions and 311 deletions

View File

@@ -109,7 +109,7 @@
\defcounter {refsection}{0}\relax
\contentsline {chapter}{\numberline {4}Design of a malicious eBPF rootkit}{55}{chapter.4}%
\defcounter {refsection}{0}\relax
\contentsline {section}{\numberline {4.1}Library injection via .GOT hijacking}{55}{section.4.1}%
\contentsline {section}{\numberline {4.1}Library injection via GOT hijacking}{55}{section.4.1}%
\defcounter {refsection}{0}\relax
\contentsline {subsection}{\numberline {4.1.1}Attacks at the stack: buffer overflow}{56}{subsection.4.1.1}%
\defcounter {refsection}{0}\relax
@@ -117,9 +117,15 @@
\defcounter {refsection}{0}\relax
\contentsline {subsection}{\numberline {4.1.3}ROP with eBPF}{62}{subsection.4.1.3}%
\defcounter {refsection}{0}\relax
\contentsline {chapter}{\numberline {5}Results}{65}{chapter.5}%
\contentsline {subsection}{\numberline {4.1.4}The ELF format and Lazy Binding}{64}{subsection.4.1.4}%
\defcounter {refsection}{0}\relax
\contentsline {chapter}{\numberline {6}Conclusion and future work}{66}{chapter.6}%
\contentsline {subsection}{\numberline {4.1.5}Hardening ELF binaries and possible bypasses}{67}{subsection.4.1.5}%
\defcounter {refsection}{0}\relax
\contentsline {chapter}{Bibliography}{67}{chapter.6}%
\contentsline {subsection}{\numberline {4.1.6}Design of our attack}{70}{subsection.4.1.6}%
\defcounter {refsection}{0}\relax
\contentsline {chapter}{\numberline {5}Results}{72}{chapter.5}%
\defcounter {refsection}{0}\relax
\contentsline {chapter}{\numberline {6}Conclusion and future work}{73}{chapter.6}%
\defcounter {refsection}{0}\relax
\contentsline {chapter}{Bibliography}{74}{chapter.6}%
\contentsfinish