« Home | Facebook as a threat to life » | Managing the Human Factor in Information Security » | Cybercrime awareness campain in The Netherlands » | BackTrack ready for use in forensics » | New form of steganography discovered » | Stick your password on a post-it » | Windows and Linux access without knowing the passw... » | Changing MAC addresses in Windows » | Detecting encrypted data » | The daily life of an infosec professional »

Reconstructing Meterpreter sessions from memory

Peter Silberman and Steve Davis (both from Mandiant) found a method to discover the use of Metaspl0it's Meterpreter and how to construct the session, uncovering the attacker's tracks. They will present their findings at Black Hat this summer.

" During this talk we discuss accessing physical memory for the purpose of acquiring a specific processes’ address space. Process address space acquisition includes DLLs, EXEs, stacks and heaps. This includes memory resident modules. We describe in detail how meterpeter operates in memory and specifically how memory looks when meterpreter scripts/commands are executed and the residue these scripts create in the exploited processes’ memory space. Finally, we tie all this knowledge together and discuss how to reconstruct a meterpreter session – completely from memory – and determine what the attacker was doing on the exploited machine. "

Labels:

Post a Comment

Links to this post

Create a Link

About me

  • I'm An Hilven
  • My CV
  • me

Interesting News

My Library


    Shelfari

Disclaimer