4 ms·
Yep. They come in basically the same flavours. Binary replacement (replacing top, ps, netstat, etc with patched versions) is the oldest trick. Syscall hooking
by fullspectrumdev 3y ago
Yep. They come in basically the same flavours.
Binary replacement (replacing top, ps, netstat, etc with patched versions) is the oldest trick.
Syscall hooking kernel root kits largely only vary in how exactly they hook the syscalls - there’s a few methods, but the underlying principle is the same.
And then you have userland hooks which usually use LD_PRELOAD to intercept system calls/libc calls to get the job done.
Honestly most of the time a full blown root kit is overkill, just name your binary something innocuous and have it not do anything too fucking obvious and nobody will notice.
- CableNinja 3y agoItd be obvious if you really look, but i once discovered in Perl you can make your command look however you want when you run `ps`. I was able to make a process appear to be a kernel process (one with `[]`). It was pretty hard to discover unless you were very familiar with what every kernel process did. Ive discovered other fun ways of hiding things too, such as creating `...` as a directory. The first time i encountered that, it took me a whole day to find that dir.
- matheusmoreira 3y agoNot just Perl. Any Linux process can do it. https://www.man7.org/linux/man-pages/man2/prctl.2.html https://www.man7.org/linux/man-pages/man2/prctl.2.html > PR_SET_NAME > Set the name of the calling thread
- CableNinja 3y agoYeah, it was just that id discovered it when i was using perl.
- Jenda_ 3y ago> Syscall hooking kernel root kits largely only vary in how exactly they hook the syscalls I don't understand how this survives major kernel upgrades. I have problems keeping out-of-tree modules working, intentionally. Do rootkits ship with fancy DKMS these days? Do the authors test with upcoming versions of major distros and push an upgrade to support the new release?
- fullspectrumdev 3y agoMost authors of kernel rootkits target a subset of versions and then give up or are stuck maintaining a codebase that is a mess of ifdefs for different versions. At one of my old jobs we had a kernel rootkit we used on occasional red team exercises that ended up having forks for 2.6, a couple of forks for 3.x, and a couple more forks for 4.x - maintenance of that was an absolute nightmare and frankly, not worth the effort in the long run, so it was not maintained into 5.x and replaced with a few much simpler userland backdoors. That’s why you will see malware such as the one in the article shipping with stuff cobbled together from several different rootkit projects to try obtain some semblance of compatibility.