Vlany – Linux LD_PRELOAD rootkit
github.com
github.com
I read somewhere that it is probably impossible to redirect everything via LD_PRELOAD, because with GCC + glib many system calls get inlined, and there is no place to hook into. You just have ASM syscalls in your executable that AFAIK you cannot redirect easily. I wonder how they did it.
Of course my thoughts quickly turned to the pranks you could play (with a purely non-root rootkit)... put an `export LD_PRELOAD=...` in someones `.profile`, and make the rootkit hide itself and that line when someone tries to view `.profile` :-)