r00tkillah / HORSEPILL

HORSEPILL rootkit PoC
BSD 2-Clause "Simplified" License
222 stars 61 forks source link

bypassing hypervisor #3

Open kotee4ko opened 3 years ago

kotee4ko commented 3 years ago

What do you think, if it possible to make a mirror of hot and running kernel and patch some stuff of RO segments, and than swap all pointers to patched one?

Can we talk via... email?

xroot000 commented 3 years ago

What do you think, if it possible to make a mirror of hot and running kernel and patch some stuff of RO segments, and than swap all pointers to patched one?

Can we talk via... email?

contact me via telegram @hexwars