CSS logical pixels, SMS encoding and some metamorphic malware
Notes on how CSS pixels map to displays, why a single character can shrink an SMS, and how metamorphic malware changes shape.
CSS logical pixels
There are physical pixels and “logical” pixels.
These logical pixels that CSS uses, are a unit of measurement, it’s not “real”. The browser maps logical pixels to real physical pixels using the device’s DPR (Device Pixel Ratio). With DPR mapping, an element will appear roughly the same size on different screens, even if the underlying numbers of physical pixels used to render it is different.
SMS encoding
SMS uses either GSM-7 or UCS-2 encoding.
If your message only contains GSM-7 characters (mostly modern-latin alphabet and common symbols), you have 160 characters per SMS. If you use just one GSM-7 unsupported character like an emoji or most non-latin characters, then the whole message switches to UCS-2 encoding, and the limit drops to 70 characters because each character takes more space.
Of course you can send longer SMS thanks to SMS concatenation “protocol” => the long message is splitted into segments, each segments includes a User Data Header (UDH) with msg ref, nb of segments and current segments, this way the receiving phone can recognize that the segments belong together, order them, and it reconstructs everything into a single message.
But these headers take space so a multipart SMS char limit is 153 instead of 160.
The Simile metamorphic malware
In the early 2000’s, a guy who calls himself “The Mental Driller” wrote a very famous metamorphic malware (Virus type) called Win32/Simile (also called Etap or MetaPHOR).
It contains a metamorphic engine that reads its own instructions, transforms it, and generates a new version that behaves the same but looks different, so byte-pattern antivirus signatures are not (or less) reliable here.
The engine can replace Assembly instructions with equivalent ones. Example technique used:
- Picking equivalent instructions into a list
- Rename registers
- Insert/update/remove no-op instructions
- Reorder independent blocks and rewrite jumps while fixing addresses
For example, ‘xor eax, eax’ can become ‘mov eax, 0’, both leaving eax at zero.
Interesting read about this malware here by Symantec. It’s a good read.