> For the complete documentation index, see [llms.txt](https://twentysick.gitbook.io/twentysick/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://twentysick.gitbook.io/twentysick/sharing/series-phat-minh-lai-cai-banh-xe/iis-native-module-nhung-la-backdoor/iis-native-module-la-gi.md).

# IIS Native Module là gì?

Trước khi thực hiện bắt tay vào tạo 1 Backdoor là ***IIS Native Module***, mình cần hiểu được IIS Native Module là gì? Và nó hoạt động như thế nào?

## Khái niệm về IIS Native Module

Trên các máy chủ chạy IIS Services, trong quá trình thực thi, IIS sẽ có sử dụng các modules *(thư viện .dll)* được code bởi ngôn ngữ *C#* và *C/C++*. Được định nghĩa là ***Managed Module (C#)*** và ***Native Module (C/C++)***

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2F7l1aj6B35fp9h3JEoxYk%2Fimage.png?alt=media&amp;token=f81e6107-16a7-473a-8b7c-db46dce8df74" alt=""><figcaption><p><a href="https://learn.microsoft.com/en-us/iis/get-started/introduction-to-iis/iis-modules-overview"><em>https://learn.microsoft.com/en-us/iis/get-started/introduction-to-iis/iis-modules-overview</em></a></p></figcaption></figure>

Không giống như ***Managed Module***, các ***Native Module*** không phụ thuộc vào *ASP.NET,* nên *IIS Service* có thể sử dụng ***Native Module*** ngay sau khi mới cài đặt Service trên server, *miễn là module đó đã được đăng ký*.

So sánh nhanh giữa ***Native Module*** và ***Managed Module***

| Đặc điểm               | Native Module (C/C++)          | Managed Module (C#/.NET)   |
| ---------------------- | ------------------------------ | -------------------------- |
| Môi trường chạy        | Unmanaged, trực tiếp trong IIS | CLR (.NET), cần ASP.NET    |
| Ngôn ngữ               | C/C++                          | C#, VB.NET, F#             |
| Hiệu năng              | Cao, ít overhead               | Thấp hơn do qua CLR        |
| Độ phức tạp            | Khó viết, dễ lỗi bộ nhớ        | Dễ viết, dễ bảo trì        |
| Khả năng dùng thư viện | Thư viện C/C++                 | Toàn bộ .NET Framework     |
| Phụ thuộc              | Không cần ASP.NET              | Phải bật ASP.NET trong IIS |

## Cách IIS sử dụng các Native Module

Trong quá trình tiếp nhận *Request*, server sẽ spawn ra tiến trình *w3wp.exe* để thực hiện xử lý. Các ***Native Module*** này sẽ được tự động load bởi tiến tình *w3wp.exe*, và tham gia vào phần xử lý *Request* từ phía Client cũng như có thể can thiệp vào *Response* trả về từ phía Server

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2Fpc9Pna58N5DF56UfvcA1%2Fimage.png?alt=media&amp;token=134655e8-1b18-49d1-a1e7-feab8e0f22f9" alt=""><figcaption><p><em>w3wp.exe sử dụng các Native Module khi tiến trình được khởi tạo</em></p></figcaption></figure>

Để sử dụng các Native Module, sẽ cần phải đăng ký với *IIS Service*, và cấu hình này sẽ được lưu tại file *`%SystemRoot%\System32\inetsrv\config\application.config`* (Default Path)

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2FUPNWUQZx8LP3v1W2HAEX%2Fimage.png?alt=media&amp;token=82c430ba-fe20-4a28-89b4-e9c0bdfadbe4" alt=""><figcaption><p><em>Thông tin về đường dẫn, tên các Native Module được Service sử dụng</em></p></figcaption></figure>

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2FmQJWFXPW0GPcQ6XDeLWh%2Fimage.png?alt=media&amp;token=7b5fcd74-08bf-4af0-83fc-32092c1d6c60" alt=""><figcaption><p><em>Thông tin về các Native Module được Service sử dụng (Xem trong IIS Manager)</em></p></figcaption></figure>

## Bản chất của mã độc là IIS Native Module

*!!! Đây là ý kiến chủ quan của cá nhân !!!*

Về bản chất, mình thấy đây là 1 biến thể của kỹ thuật *DLL side-loading (CTI bảo nó là "bạch gia hắc" nhóe)*. Do khi tiến trình *w3wp.exe* được khởi tạo, tiến trình sẽ load các ***Native Module*** theo cùng, mà các ***Native Module*** này lại chính là các file thư viện *.dll*

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2F1pRh3rPsarXzUjsmyaXV%2Fimage.png?alt=media&amp;token=fd4a9791-0e7b-44a1-aa67-99093db5a0ae" alt=""><figcaption></figcaption></figure>

Tuy nhiên, việc code 1 thư viện là ***Native Module***, sẽ cần tuân thủ theo format được cung cấp từ Microsoft. *Nếu không tuân thủ, sẽ khiên tiến trình crash liên tục và Service tèo luôn.*

***!*** ***Việc làm Service bị tòe thì rất lồ lộ nên thường thì sẽ không để tình trạng đó xảy ra nhóe !***
