3 ms·
But in theory could something similar have been developed for OpenBSD?
by hiphopyo 13y ago
But in theory could something similar have been developed for OpenBSD?
- kryptiskt 13y agoThere is even a book about designing FreeBSD rootkits: http://www.amazon.com/Designing-BSD-Rootkits-Introduction-Hacking-ebook/dp/B002MZAR6I/ http://www.amazon.com/Designing-BSD-Rootkits-Introduction-Ha...
- marios 13y agoOpenBSD does not have loadable kernel modules, so the techniques described for FreeBSD most likely do not apply. As for the Azazel rootkit, it uses LD_PRELOAD. According to the ld.so manpage[1] it is ignored for setuid/setgid executables. This looks like the behaviour is not exactly that of the Linux ld.so so perhaps this limits the rootkit's impact. [1] http://www.openbsd.org/cgi-bin/man.cgi?query=ld.so§ion=1 http://www.openbsd.org/cgi-bin/man.cgi?query=ld.so§ion=1
- throwaway2048 13y agoopenbsd does have loadable kernel modules http://www.openbsd.org/cgi-bin/man.cgi?query=lkm http://www.openbsd.org/cgi-bin/man.cgi?query=lkm LD_PRELOAD and friends are also ignored on linux for setuid/setgid binaries, otherwise privilege escalation would be trivial, just start any dynamicly linked setuid binary with LD_PRELOAD and go to town.
- dmm 13y agoOpenBSD's kernel modules are for development only. They require a securelevel change and a reboot to enable.
- weland 13y agoIn theory, something similar can be developed for any operating system IMHO, OpenBSD or otherwise. What varies is the amount of technical difficulty involved.