3 ms·
This doesn't attack gcc or python, it's just a trivial kernel module that interposes SYS_read. There's no germline persistence a la trusting trust. e.g. if I co
by cplease 12y ago
This doesn't attack gcc or python, it's just a trivial kernel module that interposes SYS_read. There's no germline persistence a la trusting trust. e.g. if I compile gcc, compile the Linux kernel, and compile python all on a system with this "rootkit" installed, and put the newly built kernel and toolchains on a new system, that system is clean.
This isn't really anything other than a Hello World kernel module.
- mrrrgn 12y agoHmmm, well, no, it's not a full on "Trusting Trust" attack; though it has a similar outcome insofar as producing dirty binaries from clean source goes. The module is simple, with the only tricky part being replacing a system call. My goal here was to play around with the idea of modifying source code en route to a compiler/interpreter in a sneaky way. Nothing more sophisticated than that. :]
- kazinator 12y ago> if I compile gcc, compile the Linux kernel, and compile python all on a system with this "rootkit" installed, and put the newly built kernel and toolchains on a new system, that system is clean. Umm, not necessarily. Instances of "World!" in your compiled kernel, toolchain and python have been replaced with "Mrrgan".