Run ANY Linux Program In Memory

Run ANY Linux Program In Memory

Source: YouTube · John Hammond · published Sep 22, 2023 · 1:25:37

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video presents advanced techniques for executing programs directly from memory in Linux systems, particularly in restricted environments like containers 1:28. The researchers demonstrate methods to bypass read-only filesystems and no-exec flags, focusing on their DDXEC technique and other memory execution approaches 2:19.

Key Takeaways:
• DDXEC technique allows executing binaries from memory by creating shell code that prepares memory mappings, loads binaries, and sets up execution environments 14:13
• The method works in restrictive environments like Kubernetes containers with read-only filesystems where traditional execution is blocked 20:53
• Researchers bypassed EDR detection that monitored for DD commands by using alternative "seeker" binaries like tail and hexdump instead of DD 32:56
• Alternative approaches include using Python's memfd_create syscall for memory execution in Python environments 43:10
• For Node.js environments, they demonstrate spawning child processes to execute binaries from memory despite container restrictions 52:00

The research showcases practical evasion techniques for modern containerized environments with security constraints, highlighting how attackers can execute arbitrary code even in highly restricted scenarios.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hey how's it going everyone thanks so much for tuning in I am super excited to be hanging out with Carlos polyp and Yago forgive me I don't know hey last name or whatever but it's great to see you both again we got a chance to hang out over at Defcon uh and hey look you two are presenting some incredible research some really cool stuff you were digging into and I'm flattered I thought you know what hey maybe we could just kind of put this out on YouTube for more folks to be able to see uh and get to see the incredible research um but Carlos Yago I don't know if you need to do any introductions or we should just start the party and dive in well thank you thank you very much for letting us come here to your channel to show our research it's great to be able to share these kind of things with…