Welcome To My Raspberry Pi Site!

This website is hosted on a RaspberryPI 4, the 8GB version to be exact, and using Nginx as the web engine. All the HTML, CSS, JacaScript and more are hand written by me in an effort to familiarize myself with the world wide web.

You can reach this website from anywhere in the world! The domain, also registered and owned by me, is listed on DNS servers all over the world and, hence, when you search for this domain name they will answer with... MY IP!?!?!?! ISN'T THAT SCARY?

Cyber Security Detour

The reality is I also have yours. I also know when you interact with what file, click what button and which sub-pages you visit. I know what operating system and browser you use and also how much data you transferred. The count of GET requests and the like you do by for example reloading the page or simpy visiting it is alkso tracked for all possible interactions.
How many unique visitors, what protocols for exactly what purpose and intent they use is all recorded.

This is not because I'm a weirdo but because the standard internet traffic requires this data to be known to at least the server. Hence organizing that data and recording it is just a matter of looking at the fundamental building blocks of interne traffic the server must know to function.

Frogicious
meow!
Linux Kernel Modules

Privilege Levels

Modern computers running modern operating systems on modern CPUs are interesting! In the early days CPUs were simpler but functioned identically to our modern ones. Registers for example are small fast to access memory blocks built within the CPU. It started with 8 bits and here I recommend checking out my CHIP-8 emulkator page below! The early days were unregulated and manufacturers built chips in many different ways.

By that I mean the literal silicon was wired differently and hence why different machine code was meccessary to use them. The CHIP-8 emulator provided a platform to program games on a larger set of machines by interpreting byte-code in a virtual machine which translated the easiert to read hexadecimal machine code resembling code into actual machine instructions! Cool!

With 16 bits we start having actual fun. We can built early computers like we know them! Think about registers again. These small memory blocks function as arguments the CPU uses. A hardware analog to software variables is what I like to imagine. A computer uses RAM to store many things including return addresses and function arguments and more. Also CPUs have a designated register which is responsible for indexing into RAM. We need to know where we are in RAM to work with it.

Where I'm trying to get at is that since this hardware variable only has 16 physical bits, this is the limit to how much RAM the CPU can access. On 16-bit architechtures we can access a total of 2^16 bytes = 65536 bytes or 65 kilobytes of memory, right? No! Not in reality.

Memory Safety History (to make modern conventions clear)

Intel produced its famnous Intel 8086 16-bit microprocessor in June 8 of 1979 after beginning developing it in early 1976. In 1972 theyy lauched the Intel 8008 8-bit microprocessor, which you could code games for using the CHIP-8 emulator back in the days!

Linux Kernel Module Implementation

Kernel Module Life Cycle

A kernel module is code the linux kernel may execute in kernel itself. A linux kernel module must include a GLP license to be loaded by the kernel.

To write a simple hello world kernel module we will include linux/module.h as well as linux/kernel.h. Kernel modules function differently from user applications. A module is loaded by the kernel and executed once a trigger occured. The module must contain an init and an exit function.

            #include <linux/module.h>
            #include <linux/kernel.h>

            MODULE_LICENSE("GPL");

            static int __init start_kernel_module(void) {
                printk(KERN_INFO 'Kernel Module Loaded Successfully!');
                return 0;
            }

            static void __exit stop_kernel_module(void) {
                printk(KERN_INFO 'Kernel Module Unloaded Successfully!');
            }

            module_init(start_kernel_module);
            module_exit(stop_kernel_module);
        
This code cant be compiles using a standard C compiler like gcc or clang since they use user space libraries while we're in ring 0. We will write a makefile

            obj-m += <krnel module name>.ko 
            
            all:
                make -C /lib/modules/$(shell uname -r)/build M=$(PWD) modules 

            clean:
                make -C /lib/modules/$(shell uname -r)/build M=$(PWD) clean
        

Kernel Level Malware
On certain Linux distributions, including Arch Linux, the kernel itself is configured to allow loading unsigned kernel modules.
On rolling release distributions software often gets updates or installed irregularly and unique to the user. The software itself is also unique in the sense that is is intended to function on argueably niche operating systems.

To install or update software the user usually provides super user privileges to whatever is seemingly related and asking. In the past year the influx of new users in particular to rolling release dfistributions increases the frequency of installs done in this manner. I am sure new users rarely read the install shell scripts and trust social dynamics on platforms centralizing the availability of free open soource software. An example I think of immediately is the arch user repositoy.

Consider a legitimate application. This application uses a shell script to install dependencies and configure an environment for functioning.
It would be childs play to include even obfuscated shell code which downloads malicious kernel modules from a control and command server, installs and runs them then hide traces of its activity.

I worry that since such a kernel module runs in kernel space which means with the ability to execute virtually all instructions of its instruction unrestricted, that this poses a fruiting ground for far more sophisticated and hidden malware.
Once the malicious kernel module is active it can be configured to make the operating system lie to itself such that for example commercial anti virus software (which usually lives in user mode and checks hashes from databases corresponding to known malware) becomes uselss. Kernel debugers and malware detectors exist and have existed for a while but they're usually unkown hence why we won't concentrate on that here.
Click The Image Above To Get To The Dedicated CHIP-8 Page!
Login

Terms Of Service

By visiting this web site you agree that I am cool.