bk99.de entertain the web since 1997

Thinking of Linux as an interpreter

Summary

Astrid examines malware that replaces Linux via kexec and interprets the kernel as an interpreter of executable formats. The script examined contains about 20 megabytes of Base64 data. The extracted archive contains a Linux kernel and an init shell script.

Ideas

  • A shell script embeds a kernel and initramfs as Base64 data.
  • kexec starts a new kernel without a firmware reboot.
  • A minimal initramfs can determine its environment entirely by itself.
  • Shebangs assign the kernel an interpreter for text programs.
  • Dynamic ELF files also name an interpreter: the run-time linker.
  • From the kernel's point of view, shell scripts and ELF files are variants of the same decision about execution.

Insights

  • Executability arises from protocols between file format, kernel and interpreter.
  • Boot mechanisms can be both useful admin tools and powerful attack paths.
  • Familiar system boundaries blur as soon as code replaces its own run-time environment.

Facts

  • kexec can load a kernel and initramfs and then execute them directly.
  • The ELF header can specify the dynamic linker as the program interpreter.

Recommendations

  • Only analyse suspicious boot artefacts in isolation and without production privileges.
  • Restrict kexec to systems and roles that need this function.
  • When execution fails, check the file format, shebang and dynamic linker separately.

References

Read the original article

Search the Web Archive