Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 21 Feb 2008 12:26:50 -0500
From:      ari edelkind <edelkind-freebsd-hackers@episec.com>
To:        freebsd-hackers@freebsd.org
Subject:   Re: encrypted executables
Message-ID:  <20080221172650.GK79355@episec.com>
In-Reply-To: <86hcg25kk5.fsf@ds4.des.no>
References:  <86068e730802181718s1ad50d3axeae0dde119ddcf92@mail.gmail.com> <47BA3334.4040707@andric.com> <86068e730802181954t52e4e05ay65e04c5f6de9b78a@mail.gmail.com> <20080219040912.GA14809@kobe.laptop> <f8e3d83f0802200451r463f188bn881268b9b2768846@mail.gmail.com> <47BCD34F.7010309@freebsd.org> <20080221023902.GI79355@episec.com> <86hcg25kk5.fsf@ds4.des.no>

next in thread | previous in thread | raw e-mail | index | archive | help
des@des.no wrote:
> ari edelkind <edelkind-freebsd-hackers@episec.com> writes:
> > Keep in mind that ptrace(PT_ATTACH,...) will fail if a process is
> > already being traced.  As for core files, a process can use
> > setrlimit(RLIMIT_CORE,...) to disable core dumps, and individual memory
> > pages may be encrypted or unloaded, to be decrypted or loaded on
> > demand.
> 
> The person running the application can trivially replace ktrace(),
> ptrace() and setrlimit() with non-functional stubs using LD_PRELOAD.

And any application that executes its own code before running the
system's dynamic loader -- or is statically linked, for that matter --
is free to unset LD_PRELOAD.

There are many attack vectors.  There are plenty of countermeasures.
There are numerous attacks on each countermeasure.  It goes on.  This is
all common knowledge, even among those creating anti-reverse-engineering
techniques; in fact, it's usually prominently stated in an included
disclaimer.

It's unfortunate to note that, in many countries these days, the most
effective deterrent against attacks on binary encryption is legal
action.  Some corporations add just-in-time page decryption to their
binaries specifically for this recourse (e.g., against a competitor who
creates applications that hook into the original software).

ari




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20080221172650.GK79355>