3 ms·
Fileless ELF Execution via Kernel Keyring
- matheuzsec_ 25d ago[dead]
- westurner 25d agoCan a process loaded this way be reverified once loaded?
- mitxela 23d agoWhat does reverified mean?
- josephcsible 25d agoThis looks to me like you're copying the contents of an ELF binary from userspace memory into a kernel keyring, and then immediately copying it back from the kernel keyring to userspace memory, followed by userland exec the usual way. What's the point of the keyring steps, rather than just doing userland exec alone?
- matheuzsec_ 25d agoThe keyring separates staging from execution, payload can be written by a different process at a different time with no file, no memfd, no open fd in /proc/pid/fd, by the time the loader runs, the payload only exists in kernel memory, direct userland exec still needs to read from somewhere visible
- josephcsible 23d agoBut then why mention execution at all, rather than just saying this is a place you can store arbitrary data?
- mitxela 23d agoAn LLM must have told them it was honestly a genuinely unique idea.
- tosti 22d ago> So we load the ELF manually Hold it right there. You mean if you've got a thread and a chunk of memory, you can use it? Who knew, except everyone?