3 ms·
This particular tool is somewhat unimpressive. From what's shown in the article it's likely only usable on RedHat-derivatives (because of the binary-only kerne
by evilDagmar 9y ago
This particular tool is somewhat unimpressive.
From what's shown in the article it's likely only usable on RedHat-derivatives (because of the binary-only kernel module). There are already "amateur" rootkits out there, with what's almost certainly a better feature set.
I am particularly unimpressed with the documentation's suggestion to rm the module afterwards, as the systems in question are extremely likely to have the shred command installed (which first overwrites the file contents in-place) which would make it impossible for a quick examiner to simply undelete the module for analysis.
I think this was some agent's idea of a PoC more than something they expected to use.
- willstrafach 9y agoIt looks a lot like a basic intern project, as it does technically serve a purpose yet does not use any vulnerabilities or contain anything particularly novel for that matter.
- a3n 9y agoMaybe it's part of a "list of things to do first" when a target has been breached by gaining access. There are mass email-based phishing attacks, there are spear-phishing attackes, and there are likely procedures to follow when a specific group's target has given up physical access via root. As for RH-only, what makes us think that there aren't also Debian and other similar attacks? MS-Word is also "somewhat unimpressive," as it's only usable on Windows.
- kevin_thibedeau 9y agoShred doesn't work as intended on modern filesystems and storage devices. Its only really useful for priming a new drive with random data because its PRNG is faster than dev/random.