4 ms·
This seems to be different from previous LD_PRELOAD vulnerabilities in that it's using eBPF as part of the mechanism to obfuscate itself.
by farisjarrah 4y ago
This seems to be different from previous LD_PRELOAD vulnerabilities in that it's using eBPF as part of the mechanism to obfuscate itself.
- prvit 4y agoSure, but that’s at best a minor implementation detail. Doesn’t meaningfully increase the difficulty of detection.