{"id":6516,"date":"2019-07-05T23:05:23","date_gmt":"2019-07-05T23:05:23","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=6516"},"modified":"2019-07-05T23:05:25","modified_gmt":"2019-07-05T23:05:25","slug":"bring-your-own-lolbas","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2019\/07\/05\/bring-your-own-lolbas\/","title":{"rendered":"Bring your own lolbas?"},"content":{"rendered":"\n<p>Recently, I was wondering what is the best term for binaries\/scripts that are signed, can do the <a href=\"https:\/\/lolbas-project.github.io\/\">Lolbas<\/a> thing, but are not necessarily installed on the system.<\/p>\n\n\n\n<p>So far I have been covering many of these using a generic term &#8216;Re-usigned binaries&#8217; (portmanteau of \u2018reuse\u2019 and \u2018signed\u2019). But it&#8217;s not catchy enough. Could a better term be &#8216;Bring your own lolbas\/lolbin&#8217;? BYOL? Kinda similar to Bring Your Own Vulnerability (BYOV)? In fact a BYOL is a subset of BYOV.<\/p>\n\n\n\n<p>I have covered many BYOL examples <a href=\"https:\/\/www.hexacorn.com\/blog\/category\/living-off-the-land\/reusigned-binaries\/\">before<\/a>. And I believe there will be a lot more in the future. After a very fertile research period lolbin fans explored most of the native OS executables, DLLs, scripts. It&#8217;s a natural course of events that their eyes will eventually turn to the other stuff.<\/p>\n\n\n\n<p>The other stuff can be e.g. 7Zip program signed by legitimate companies. <a href=\"https:\/\/twitter.com\/Oddvarmoe\/\">@Oddvarmoe<\/a> <a href=\"https:\/\/twitter.com\/Oddvarmoe\/status\/1123249551756935169\">posted<\/a> about it on Twitter in April:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"566\" height=\"416\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/07\/7z_1.png\" alt=\"\" class=\"wp-image-6517\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/07\/7z_1.png 566w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/07\/7z_1-300x220.png 300w\" sizes=\"(max-width: 566px) 100vw, 566px\" \/><\/figure>\n\n\n\n<p>It triggered my interest and I set on a path to discover more instances of various 7zip components signed by legitimate companies. The results of a very basic research are very promising: there are plenty of these:<\/p>\n\n\n\n<ul><li>ASUSTeK Computer Inc.<\/li><li>HUAWEI Technologies Co., Ltd.<\/li><li>NVIDIA Corporation<\/li><li>Samsung Electronics CO., LTD.<\/li><li>Trend Micro, Inc.<\/li><\/ul>\n\n\n\n<p>I won&#8217;t be posting hashes, because&#8230; well&#8230; why burning them&#8230; The other less obvious bit is that these signed components are often old and could contain unpatched vulnerabilities as well. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, I was wondering what is the best term for binaries\/scripts that are signed, can do the Lolbas thing, but are not necessarily installed on the system. So far I have been covering many of these using a generic term &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2019\/07\/05\/bring-your-own-lolbas\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[56,64,59],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6516"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=6516"}],"version-history":[{"count":1,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6516\/revisions"}],"predecessor-version":[{"id":6518,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6516\/revisions\/6518"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=6516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=6516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=6516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}