How do you detect one?
``` for f in /proc/*/environ ; do sudo strings $f | >/dev/null grep LD_PRELOAD && echo $f; done ```
2. I'd suggest against using `strings` (let alone with sudo) on attacker controlled inputs
However, on my Fedora 36 machine at least, it doesn't do so by default and I'd have to specify the `-d` flag for it to do this.
#include <stdio.h>
#include <stdlib.h>
static void begin() __attribute__((constructor));
void begin() {
unsetenv("LD_PRELOAD");
}
Build with: gcc -shared -fpie -o library.so library.c
Test: LD_PRELOAD=~/library.so env | grep LD_PRELOADUnless the ld_preload patches the process you are using to read the maps file, and gives you a false maps file.
• libinput-gestures has spawned a /usr/lib/libinput/libinput-debug-events process with LD_PRELOAD=/usr/lib/coreutils/libstdbuf.so
• Firefox has spawned many /opt/firefox-nightly/firefox-bin processes with LD_PRELOAD=libmozsandbox.so
LD_PRELOAD=libmozsandbox.so