Skip to content

Comment on An obscure kernel feature to get more info about dying processesparent

Comments

on the other hand, it makes for an interesting rootkit hook.

Which is more dangerous than all the others things you can do as root - like inserting an arbitrary kernel module - how?

Dangerous: no, but he said interesting, so perhaps. The advantage of using little known features, for rootkits, is that people are less likely to look for them.

i never said more dangerous nor intended it.

it's not a very good rootkit by itself, certainly, as typically rootkits will monkey with the kernel to hide processes and network sockets.

it's interesting because it's probably the simplest rootkit method i can think of (next to setuid binaries). it's less obvious than a setuid. it's not something that anyone sane would use by itself because like i said--it doesn't hide you.

it's not (yet) an obvious place to look.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.