OpenChaos/Malware Linux

From C4 Wiki
< OpenChaos
Revision as of 00:13, 5 November 2004 by Mario Manno (talk | contribs) (added category)
Jump to: navigation, search

Folien unter

runtime kernel patching

  • /dev/kmem - raw i/o capability needed from kernel
  • kmalloc fuer rootkit code
  • suckit aendert pointer auf syscall in der IDT

hide modules by

  • delete module from module list (adore) by changing syscall table
  • modify vfs (adore-ng)
  • parasitic module infection (adore-ng optional), changes the module file
  • runtime-kernel patching (suckit) (copy der syscall table ...idt)
  • static kernel patching - im kernel image code ablegen


  • baut sk_buff struct und schickt sie an device


  • ELF header infection
  • RST.B Virus

rootkit hunter

  • chkrootkit
  • tiger


  • grsec, trusted path execution, benutzer koennen keine programme ausfuehren die sie schreiben koennen

Antivirus Virus Linux

  • f-prot
  • clamav
  • hb-antivirEvents