m0nad / Diamorphine

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
Other
1.79k stars 425 forks source link

Questions about hidden processes and display modules #19

Closed skr-rks closed 3 years ago

skr-rks commented 4 years ago

Centos8 zhōng kernel wèi 4.18. Zhíxíng kill -63 0 hòu biāoqiān yè bèi guānbì, mókuài wèi xiǎnshì. Érqiě kill 31 PID yǐncáng jìnchéng hòu wúfǎ huīfù, tíshì gāi jìnchéng ID bù cúnzài. 80/5000 The kernel in centos8 is 4.18. After executing kill -63 0, the tab page is closed and the module is not displayed. And the kill 31 PID cannot be recovered after hiding the process, indicating that the process ID does not exist.

m0nad commented 4 years ago

At the moment, Diamorphine is not working properly in kernels above 4.16. If you manage to fix this, please send a pull request.

m0nad commented 4 years ago

Commit 4438984 should fix this, please test and report any issues

skr-rks commented 4 years ago

Used after the update, the system crashed, but the test was not successful

m0nad commented 4 years ago

Thanks for the report, I will investigate

m0nad commented 4 years ago

Tested on CentOS 8.2 with kernel 4.18.0-193.14.2.el8_2.x86_64 and everything work as expected. Can you provide the exact CentOS and the kernel version? Screenshot from 2020-08-31 01-29-21