mempodippy / vlany

Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)
GNU General Public License v3.0
935 stars 193 forks source link

lsrootkit GID bruteforcing and readdir code #30

Open therealdreg opened 6 years ago

therealdreg commented 6 years ago

Hi, my lsrootkit should detect your rootkit, but first cause a proces crash: your readdir code.

https://github.com/David-Reguera-Garcia-Dreg/lsrootkit

Left: normal rootkit without your readdir code.

Right: your rootkit.

evidence