mirror of
https://github.com/milabs/awesome-linux-rootkits.git
synced 2025-02-02 02:55:00 -05:00
Update rkduck.md
This commit is contained in:
parent
4ef5de8bd5
commit
68f41e6771
@ -6,7 +6,33 @@ https://github.com/QuokkaLight/rkduck
|
|||||||
|
|
||||||
- x86, x86_64
|
- x86, x86_64
|
||||||
- Linux kernel 4.x
|
- Linux kernel 4.x
|
||||||
|
- Debian/Ubuntu, RHEL/CentOS/Fedora
|
||||||
|
|
||||||
## Persistency
|
## Persistency
|
||||||
|
|
||||||
|
Boot-time module loading using OS-specific startup files:
|
||||||
|
- /etc/modules (debian/ubuntu)
|
||||||
|
- https://github.com/linux-rootkits/rkduck/blob/master/forever.sh#L29
|
||||||
|
- /etc/rc.modules (redhat/centos/fedora)
|
||||||
|
- https://github.com/linux-rootkits/rkduck/blob/master/forever.sh#L32
|
||||||
|
|
||||||
|
Rootkit module runs `forever.sh` helper script at the moment of module unloading:
|
||||||
|
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/duck.c#L47
|
||||||
|
|
||||||
|
## Detection evasion
|
||||||
|
|
||||||
|
Rootkit is trying to evade from detection by:
|
||||||
|
- hiding rootkit files by name
|
||||||
|
|
||||||
|
## Management interface
|
||||||
|
|
||||||
|
Implemented via in-kernel `netlink` server (`NETLINK_USER`) :
|
||||||
|
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/crumbs_serv.c#L142
|
||||||
|
|
||||||
|
Supported commands are:
|
||||||
|
- hiding/unhiding files
|
||||||
|
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/crumbs_serv.c#L22
|
||||||
|
- hiding/unhiding processes
|
||||||
|
- https://github.com/linux-rootkits/rkduck/blob/master/rkduck/crumbs_serv.c#L32
|
||||||
|
|
||||||
...
|
...
|
||||||
|
Loading…
x
Reference in New Issue
Block a user