Thinking of Linux as an interpreter
Summary
Astrid examines malware that replaces Linux via kexec and interprets the kernel as an interpreter of executable formats. The script examined contains about 20 megabytes of Base64 data. The extracted archive contains a Linux kernel and an init shell script.
Ideas
- A shell script embeds a kernel and initramfs as Base64 data.
- kexec starts a new kernel without a firmware reboot.
- A minimal initramfs can determine its environment entirely by itself.
- Shebangs assign the kernel an interpreter for text programs.
- Dynamic ELF files also name an interpreter: the run-time linker.
- From the kernel's point of view, shell scripts and ELF files are variants of the same decision about execution.
Insights
- Executability arises from protocols between file format, kernel and interpreter.
- Boot mechanisms can be both useful admin tools and powerful attack paths.
- Familiar system boundaries blur as soon as code replaces its own run-time environment.
Facts
- kexec can load a kernel and initramfs and then execute them directly.
- The ELF header can specify the dynamic linker as the program interpreter.
Recommendations
- Only analyse suspicious boot artefacts in isolation and without production privileges.
- Restrict kexec to systems and roles that need this function.
- When execution fails, check the file format, shebang and dynamic linker separately.
References
Links to the original source and the Web Archive open in a new tab.