unix-thrust / beurk

BEURK Experimental Unix RootKit
GNU General Public License v3.0
362 stars 94 forks source link

utmp/wtmp hooking not working on jenkins functionnal tests #84

Open nil0x42 opened 8 years ago

nil0x42 commented 8 years ago

w or who commands, when launched as victim from jenkins functionnal tests, do not show current login shell, unless utmp/wtmp hooks are disabled on the rootkit.

we must investigate in order to find a way to fix it for more informations, ask to @jagu-sayan