
Stephan Berger
@malmoeb
Head of Investigations @InfoGuardAG
infosec.exchange/@malmoeb
ID: 910694455
https://dfir.ch/ 28-10-2012 16:57:26
2,2K Tweet
26,26K Followers
1,1K Following




As I'm about to present about Linux Rootkits at the 10th edition of EuskalHack (๐), hereโs a nifty trick to detect a userland rootkit that tries to hide its presence by blocking access to /etc/ld.so.preload. We are mounting the filesystem with debugfs (an interactive file




The screenshot below is from a recent Incident Response case, investigated by my colleague Flo Scheiber. The user "printer" suddenly sprang to life because an attacker brute-forced the VPN login (without Multi-Factor Authentication). This was not the first time a "printer"













Awesome read & technique - well done ๐ ๐๐ฏ ๐ต๐ฉ๐ช๐ด ๐ฃ๐ญ๐ฐ๐จ ๐ฑ๐ฐ๐ด๐ต, ๐ธ๐ฆ ๐ต๐ข๐ญ๐ฌ๐ฆ๐ฅ ๐ข๐ฃ๐ฐ๐ถ๐ต ๐ข ๐ฉ๐ฐ๐ธ ๐ข ๐ธ๐ฆ๐ญ๐ญ-๐ฌ๐ฏ๐ฐ๐ธ๐ฏ ๐ต๐ฆ๐ค๐ฉ๐ฏ๐ช๐ฒ๐ถ๐ฆ ๐ง๐ฐ๐ณ ๐ฆ๐ฏ๐ฅ๐ฑ๐ฐ๐ช๐ฏ๐ต ๐ฑ๐ฆ๐ณ๐ด๐ช๐ด๐ต๐ฆ๐ฏ๐ค๐ฆ, ๐ค๐ข๐ฏ ๐ฃ๐ฆ ๐ณ๐ฆ-๐ช๐ฏ๐ท๐ฆ๐ฏ๐ต๐ฆ๐ฅ ๐ช๐ฏ ๐ข ๐ค๐ญ๐ฐ๐ถ๐ฅ ๐ฆ๐ฏ๐ท๐ช๐ณ๐ฐ๐ฏ๐ฎ๐ฆ๐ฏ๐ต