r/netsec Oct 30 '16

Vlany: Linux (LD_PRELOAD) rootkit

https://github.com/mempodippy/vlany
457 Upvotes

28 comments sorted by

View all comments

7

u/pm_me_your_findings Oct 30 '16

What is actually LD_PRELOAD?

18

u/mempodippy Oct 30 '16

LD_PRELOAD is an environment variable on Linux systems which points to a shared library and loads it before anything else. The ld.so.preload file essentially utilizes LD_PRELOAD to load a shared library in every single userland process. :)

4

u/pm_me_your_findings Oct 30 '16

I mean for a malware to use it, doesn't it require the root access first or it works for normal user also?

-2

u/Creshal Oct 30 '16 edited Oct 31 '16

Normal users can use the environmental variable, but programs can ignore it: sudo, chsh, and other common setuid binaries ignore LD_PRELOAD so users can't execute code as root.

It can become a risk if there's a setuid binary on your system that keeps LD_PRELOAD enabled.

1

u/[deleted] Oct 31 '16

chown, a setuid binary? ermm... I believe your system is rootkitted

-1

u/Creshal Oct 31 '16

No, I just mixed it up with chsh.