Remote Code Execution using ICMP Modified Structured Storage Covert Channels Without Elevation of Privileges
T. Sri Aditya · 2019 International Conference on Computing, Power and Communication Technologies (GUCON) · 2019
This paper discusses the vulnerability of modern anti-malware softwares to covert channel attacks without the need for elevation of privileges by employing an inherent vulnerability of ICMP and Winpcap. A modified form of Network Storage Covert Channels is introduced which is capable of evading the present detection algorithms based on statistical and information-theoretic models. The vulnerability pertaining to bypassing administrator privileges creates a special cause for concern since with the recent emergence of Ransomware, the only line of defence that most novice users usually have is the spurious request for administrator privileges upon executing a malware masquerading as a harmless file but with this bypassed the threat of Ransomware extends to even proficient users. Most users if not all of wireshark and other network virtualization software such as GNS3 depending on Winpcap, select the option to automatically start NPF.sys driver at Windows boot. This default setting is exploited to present an ideal environment for establishing covert channels.