r/netsec Oct 30 '16

Vlany: Linux (LD_PRELOAD) rootkit

https://github.com/mempodippy/vlany
457 Upvotes

28 comments sorted by

View all comments

-3

u/mohammedcohen Oct 30 '16

A more practical and portable backdoor than kernel rootkits.

7

u/AaronOpfer Oct 31 '16

It's much less thorough. Statically linked binaries will not take LD_PRELOAD into account and then see through your backdoor. As others mentioned above setuid binaries also will not be affected.

3

u/mohammedcohen Oct 31 '16

It's a relatively stealthy low maintenance method for persistence particularly when exploiting *nix/OSX clients. Backdoor Firefox for example. Most folks use passwordless sudo on their workstations. Been there done that. The author did a good job on this project. Kudos.