mirror of
https://github.com/milabs/awesome-linux-rootkits.git
synced 2025-01-22 05:21:11 -05:00
Update rkduck.md
This commit is contained in:
parent
e938899b43
commit
23c95e7c68
@ -57,3 +57,17 @@ Hooking of system calls by patching syscall-handlers in `sys_call_table[]`:
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/vfs.c#L157 (vfs_hijacked_proc_iterate)
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/vfs.c#L78 (vfs_hijacked_proc_filldir)
|
||||
|
||||
## Keylogger
|
||||
|
||||
Keylogger is implemented using `register_keyboard_notifier()`:
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/keylogger.c#L204
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/keylogger.c#L72 (keylogger_notify)
|
||||
|
||||
Logged keystrokes are saved in file which periodically being sent to remote hos using `scp`:
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/keylogger.c#L181 (keylogger_init)
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/keylogger.c#L64 (writing to the file...)
|
||||
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/keylogger.c#L32 (sending with `scp`)
|
||||
|
||||
## Backdoor
|
||||
|
||||
...
|
||||
|
Loading…
Reference in New Issue
Block a user