5 ms·
It's actually not all that uncommon for well-written rootkits to do just that.
by muoncf 14y ago
It's actually not all that uncommon for well-written rootkits to do just that.
- loeg 14y agoCool, I learned something. I guess the boot partition is likely to be inactive, and with a ffs-derived file system you can simply overwrite some file in place with your own functionality. E.g., replace some unused driver code with your rootkit, which loads itself on probe.