Okay, that's interesting - how would you remove this hook?
Okay, that's interesting - how would you remove this hook?
As someone else points out, all statically linked binaries are immune to this technique since they don't load preloads.
Another warning is don't muck around with /etc/ld.so.preload unless you know what you're doing. It's possible to get in a state that everything you executes segfaults.
$ ldd /usr/bin/busybox not a dynamic executable
$ ls -l /usr/bin/busybox -rwxr-xr-x 1 root root 1795976 Jan 20 14:21 /usr/bin/busybox*
$ file /usr/bin/busybox /usr/bin/busybox: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, for GNU/Linux 2.6.32, BuildID[sha1]=76e26ac5c916fc1e715c9a49c10db3405b26a22c, stripped
$ busybox BusyBox v1.22.1 (2014-01-20 17:20:52 MSK) multi-call binary. BusyBox is copyrighted by many authors between 1998-2012. Licensed under GPLv2. See source distribution for detailed copyright notices.
Usage: busybox [function [arguments]...] or: busybox --list[-full] or: busybox --install [-s] [DIR] or: function [arguments]...
BusyBox is a multi-call binary that combines many common Unix
utilities into a single executable. Most people will create a
link to busybox for each function they wish to use and BusyBox
will act like whatever it was invoked as.
Currently defined functions:
[, [[, addgroup, adduser, adjtimex, ar, arp, arping, ash, awk, base64,
basename, beep, blkid, blockdev, bootchartd, brctl, bunzip2, bzcat,
bzip2, cal, cat, catv, chat, chattr, chgrp, chmod, chown, chpasswd,
chpst, chroot, chrt, chvt, cksum, clear, cmp, comm, cp, cpio, crond,
(...)
uudecode, uuencode, vconfig, vi, vlock, volname, wall, watch, watchdog,
wc, wget, which, who, whoami, whois, xargs, xz, xzcat, yes, zcat, zcipAs these rootkits are designed by rather smart people to overcome all existing tools, there simply cannot be generic tools that catch them all. If you get hit by a bunch of script kiddies using outdated tools, things like rkhunter and chkrootkit can help. Modern rootkits are almost by definition undetectable by them. If it's actually new, the way you find out about it is typically either a separate NID box between the machine and the wall that alerts, or the behaviour of the box changing.
End user here: I just have a Linux laptop, interested in servers on the 'wild' web
You could also use asm to directly invoke sys_ptrace, since this rootkit doesn't have any kernel components.