Old hacker tells us about reverse analysis: What is the loading process of Shell and shell?

Source: Internet
Author: User

BKJIA ziming Series

In the previous course, I mainly introduced what pe is. In this course, we mainly talk about shells. This is also a required course for cracking software and a required course for reverse analysis.

In some computer software, there is a program dedicated to protecting the software from unauthorized modification or decompilation. They generally run programs before they get control and then complete their tasks to protect the software. Because this program has many similarities in functionality with the shell of nature, such a program is called a "shell" based on naming rules. Shells are divided into private shells and compressed shells.

Shell

498) this. style. width = 498; "border = 0>

Shell Loading Process

1) obtain the API address required by the Shell

If you use the PE editing tool to view the files after shelling, you will find that the files without shelling are different from the input table of the files after shelling, the input table after shelling generally introduces very few DLL and API functions, and even only the Kernel32.dll and GetProcAddress API functions.

Shell actually requires other API functions to complete its work. To hide these APIs, it generally only dynamically loads these API functions in explicit link mode in shell code.

2) decrypt the data of each Section of the original program

For the purpose of protecting the original program code and data, the shell usually encrypts each block of the original program file. During program execution, the shell decrypts the block data so that the program can run normally.

The shell is generally encrypted by block. In this case, the block data is also decrypted by block, and the decrypted block data is placed in the appropriate memory location according to the block definition.

If compression technology is used when shelling, there is another process before decryption, that is, decompression. This is also one of the characteristics of some shells, such as when the original program file is not shelled 1 ~ 2 m size, but only several hundred K after shelling.

3) Relocation

The initial memory address is called the base address (ImageBase ).

For EXE program files, Windows system will try to meet the requirements. For example, the base address of an EXE file is 0x400000, while the base address provided by Windows to the program during runtime is also 0x400000. In this case, address "relocation" is not required. Because you do not need to "relocate" the EXE file, the shelling software simply deletes the block used in the original program file to save the relocation information, which makes the file after shelling more compact. Some tools provide the "Wipe Reloc" function.

However, Windows cannot guarantee that the same base address is provided for each DLL running. In this way, "relocation" is very important. At this time, the code for "relocation" must also be provided in the shell. Otherwise, the code in the original program cannot run normally. From this point, the shell DLL is more difficult to modify than the shell EXE.

4) HOOK-API

The input table in the program file is used to provide the actual API address for the program when the Windows system is running. Before the first line of the program code is executed, the Windows system completes this job.

Generally, the input table of the original program file is modified, and then the data in the input table is filled by imitating the work of the Windows system. During the filling process, the shell can populate the address of the HOOK-API code so that you can indirectly gain control of the program.

5) Jump to the original entry point of the Program (OEP)

From this point on, the shell will return the control to the original program. The general shell will have an obvious "Demarcation Line" here ". But now the fierce shell has no such limit, there is meat in the shell, there is shell in the meat.

General Shell Loading Process

498) this. style. width = 498; "border = 0>

Introduction to shelling Software

Based on the purpose and function of shelling, the software can be divided into two types: Packers and Protectors ). The main purpose of compressing such shells is to reduce the program volume, such as ASPacK, UPX, and PECompact. Another type is the protection program. Various anti-tracking technologies are used to protect the program from debugging and shelling. The volume size after shelling is not the main factor, such as ASProtect, Armadillo, and EXECryptor.

With the development of shelling technology, the boundaries between these two types of software become increasingly blurred. Many shelling software have strong compression performance and protection performance.

The compression algorithms of various shell software are generally not self-implemented, and most of them call other compression engines. At present, there are many types of compression engines, and different compression engines have different characteristics, such as some which have good effects on Image Compression and some which have good effects on data compression. However, the compression engine selected for shelling software has a feature that the compression speed is not too slow when the compression ratio is ensured, but the decompression speed must be fast, in this way, the running speed of the shell EXE file will not be greatly affected.

Introduction to common compression Shells

1). ASPacK
Home: http://www.aspack.com/
ASPack is a Win32 Executable File compression software that can compress 32-bit Windows executable files (.exe) and library files (. dll,. ocx). The File compression ratio is as high as 40% ~ 70%.

2). UPX
Home: http://upx.sourceforge.net/
UPX is a classic free compression program for executable files operated in the command line mode. The compression algorithm is implemented by itself, and the speed is extremely fast.

3). PECompact
Home: http://www.bitsum.com/
PECompact is also a tool that can compress executable files (supporting files such as EXE, DLL, SCR, and OCX ). Compared with similar software, PECompact provides a variety of compression projects, allowing you to determine which internal resources need to be compressed as needed. The software also provides a plug-in interface for encryption and decryption.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.