-
Notifications
You must be signed in to change notification settings - Fork 24
0x09. Forensics
liyansong2018 edited this page Feb 13, 2025
·
1 revision
There are various motivations for infecting binary files. On the positive side, Blue Army can achieve binary protection through binary patching; On the contrary, the Red Army can achieve viruses, botnets, and backdoors through binary infections. Elfspirit has initially implemented the function of checking whether binary files have been modified. For deeper checks, readers need to use reverse engineering or our written IDA plugin to directly check dangerous instructions such as trampoline functions.
- 0x01. Play with Symbol
- 0x02. Implement ELF Static Hook by Injecting .got.plt
- 0x03. ELF Virus Technology: ELF Infection
- 0x04. Transform EXE into LIB
- 0x05. Analyze Binary Protection Flags
- 0x06. Obfuscate ELF
- 0x07. Inject Shared Libraries into Executables
- 0x08. Infect ELF Interpreter
- 0x09. Forensics
- 0x10. Other Topics