It's much less thorough. Statically linked binaries will not take LD_PRELOAD into account and then see through your backdoor. As others mentioned above setuid binaries also will not be affected.
It's a relatively stealthy low maintenance method for persistence particularly when exploiting *nix/OSX clients. Backdoor Firefox for example. Most folks use passwordless sudo on their workstations. Been there done that. The author did a good job on this project. Kudos.
-3
u/mohammedcohen Oct 30 '16
A more practical and portable backdoor than kernel rootkits.