Jump to content











Photo
- - - - -

DigitalSignatureTweaker


  • Please log in to reply
1 reply to this topic

#1 joakim

joakim

    Silver Member

  • Team Reboot
  • 912 posts
  • Location:Bergen
  •  
    Norway

Posted 29 November 2011 - 09:58 AM

Posted Image

File Name: DigitalSignatureTweaker
File Submitter: joakim
File Submitted: 28 Nov 2011
File Updated: 01 Dec 2011
File Category: Security

This is a PoC that one can hide data inside an Authenticode signed executable without invalidating the signature. It supports compression, encryption and timestamp manipulation, as well as a separat program to extract hidden data. More explanations inside the readme. Discussion follow at; http://reboot.pro/15889/

Click here to download this file
  • Brito and Holmes.Sherlock like this

#2 joakim

joakim

    Silver Member

  • Team Reboot
  • 912 posts
  • Location:Bergen
  •  
    Norway

Posted 22 June 2012 - 10:25 PM

Turns out there was released a patch from Microsoft (MS12-024) about half a year after the tool was released; https://blog.avast.c...ility-ms12-024/ :)

I don't really know what the patch does, but I remember I could make explorer crash/freeze with certain of my custom made files (only signature was modified), and that could be part of what the patch is for.

Maybe they also should consider making a patch for their WRP since the system protected files can have ADS's injected without triggering any alarms.. ;) Thanks to NTFS.
  • Brito likes this




2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users