3 ms·
on the other hand, it makes for an interesting rootkit hook.
by dododo 16y ago
on the other hand, it makes for an interesting rootkit hook.
- FooBarWidget 16y agoWhich is more dangerous than all the others things you can do as root - like inserting an arbitrary kernel module - how?
- milkshakes 16y agoit's not (yet) an obvious place to look.
- InclinedPlane 16y agoDangerous: no, but he said interesting, so perhaps. The advantage of using little known features, for rootkits, is that people are less likely to look for them.
- dododo 16y agoi never said more dangerous nor intended it. it's not a very good rootkit by itself, certainly, as typically rootkits will monkey with the kernel to hide processes and network sockets. it's interesting because it's probably the simplest rootkit method i can think of (next to setuid binaries). it's less obvious than a setuid. it's not something that anyone sane would use by itself because like i said--it doesn't hide you.