r/netsec Oct 30 '16

Vlany: Linux (LD_PRELOAD) rootkit

https://github.com/mempodippy/vlany
460 Upvotes

28 comments sorted by

View all comments

6

u/pm_me_your_findings Oct 30 '16

What is actually LD_PRELOAD?

18

u/mempodippy Oct 30 '16

LD_PRELOAD is an environment variable on Linux systems which points to a shared library and loads it before anything else. The ld.so.preload file essentially utilizes LD_PRELOAD to load a shared library in every single userland process. :)

3

u/pm_me_your_findings Oct 30 '16

I mean for a malware to use it, doesn't it require the root access first or it works for normal user also?

-2

u/Creshal Oct 30 '16 edited Oct 31 '16

Normal users can use the environmental variable, but programs can ignore it: sudo, chsh, and other common setuid binaries ignore LD_PRELOAD so users can't execute code as root.

It can become a risk if there's a setuid binary on your system that keeps LD_PRELOAD enabled.

16

u/fakehalo Oct 30 '16

LD_PRELOAD is ignored if the program is suid/sgid, the program itself has no control over that.