What strings do you see statically in the binary

Assignment Help Other Subject
Reference no: EM132266934

Question 1. Analyze the malware found in the file Lab09-01.exe using OllyDbg and IDA-Pro to answer the following questions.
a. How can you get this malware to install itself?
b. What are the command-line options for this program? What is the password requirement?
c. How can you use OllyDbg to permanently patch this malware, so that it doesn't require the special command-line password?
d. What are the host-based indicators of this malware?
e. What are the different actions this malware can be instructed to take via the network?
f. 6. Are there any useful network-based signatures for this malware?

Question 2. Analyze the malware found in the file Lab09-02.exe using OllyDbg to answer the following questions.
a. What strings do you see statically in the binary?
b. What happens when you run this binary?
c. How can you get this sample to run its malicious payload?
d. What is happening at 0x00401133?
e. What arguments are being passed to subroutine 0x00401089?
f. What domain name does this malware use?
g. What encoding routine is being used to obfuscate the domain name?
h. What is the significance of the CreateProcessAcall at 0x0040106E?

Question 3. Given vulnerableserver.exe, use Windows 10, Windbg, and Kali Linux to write an exploit string. Your final deliverable should be:
a. A screen shot of the corrupted stack

2223_Screen shot.jpg

b. A screenshot of your exploit (from Kali Linux)

Specifics:
1) Please leave your EIP as a "dummy placeholder" (0x42424242 in my screenshot above) (no need to find the address of JMP ESP (or equivalent))
2) Please set a 0xCC as the first character of your payload
3) You must store your student number as the following digits of the payload. Make sure to mask off any illegal characters.

Attachment:- PROG8300 - Assignment.rar

Reference no: EM132266934

Questions Cloud

Do you believe that the structure will change : If your preferences do not fit the current structure of your organization, do you believe that the structure will change? Will you consider leaving.
Build Renovatech Inc pro forma financial statements : Financial statements Analysis Assignment - Build Renovatech Inc.'s pro forma financial statements based on the assumptions
Examine the various applications of the law : Examine the various applications of the law within the health care system. Analyze how such various applications of the law affect decisions in the development.
Analyze cultural and legal challenges the company : Analyze your selected company with micro and macro environmental forces by using SWOT analysis.
What strings do you see statically in the binary : PROG8300 - What strings do you see statically in the binary and What encoding routine is being used to obfuscate the domain name
Intentional discrimination by employer against an employee : Intentional discrimination by an employer against an employee is. Which of the following is true about Kiva.og per the Harvard Case Study?
Discuss overarching duties of health care governing board : Prevailing wisdom reinforces the fact that working in U.S. health care administration in the 21st Century requires knowledge of the various aspects of health.
Research supplier evaluation : Research supplier evaluation. When evaluating supplier's financial stability, what are some key indicators to consider? What are some other characteristics.
Assuming deterministic demand and no shortages : Assuming deterministic demand and no shortages, develop an ordering plan for this company using the Wagner-Whitin algorithm.

Reviews

inf2266934

9/1/2019 2:24:31 AM

Perfectly done work I am surprised to see that how your weritre has managed to write a quality work in such a limited time.

len2266934

3/26/2019 10:21:29 PM

Marking Rubric: Q1: 30% Q2: 30% Q3: 40% Partial marks awarded for partial answers, but all answers must support your observations/conclusions. Standard deductions: 5% for not having name and assignment # in your Word document 10% for zipping submission 25% for submitting screenshots not inserted/formatted into Word document 100% for any question that does not include supporting screenshots 100% for any question whose screenshots do not have date/time stamp or date/time

len2266934

3/26/2019 10:21:08 PM

Please include screen shots(full screen only) of all tool output that supports your answers to the questions. Paste these screenshots into a MS Word document, add required text/explanation/annotations and submit before due date. The required executable files for 1 and 2 are found in the practical malware zipfile and vulnerableServer.exe can be found on eConestoga in a file named PROG8300_W19_Assignment3_files.zip ( have extracted and sent it along with this document)

Write a Review

Other Subject Questions & Answers

  What are the authentic websites about the frontiers

What are the authentic websites about the frontiers of the medical research? By the way, it had better be Chinese.

  Compare between morality and professional ethics

Compare between morality and professional ethics - explain the rationale behind adoption of normative theories and professional codes of conduct.

  Explain whether each stakeholders needs desires and goals

each stakeholder in the selection process - line managers coworkers and applicants - has distinctly different needs

  Power of the person

Which of the following is NOT power of the person?

  Arguments in favor of not making a change

Restate opposition and most significant arguments in favor of not making a change.

  Summarize behavioral and psychological factors

A main body, containing the "meat" of the paper, where you provide the requested information supported by class readings and with your analysis.

  Evaluate potential ethical issues that should be considered

Evaluate potential ethical issues that should be considered or guarded against when developing treatment interventions for children or adolescents. Describe steps that should be followed to ensure that potential ethical issues are addressed proper..

  Discuss nursing management in their unit or facility

How can a nurse improve quality through demonstrating leadership in nursing management in their unit or facility

  What foods and liquids she should avoid

What foods and liquids she should avoid , What changes she should make and Barriers she will face in making these changes and how they can be overcome.

  Describe one journal article findings on validity

For this discussion, describe one journal article's findings on validity. The author's overall interpretation of the results

  Which statements concerning the maintenance of balance

Which of the following statements concerning the maintenance of balance within each risk or rate classification of a life company is (are) correct?

  Different conclusions regarding the topic use particular

Summarize the kinds of evidence typically used for each constructed argument related to the issue. Be sure to discuss the reasons these kinds of evidence are used and/or are most effective.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd