Show HN: A simple, highly commented, rootkit which attacks GCC and Python
github.com
github.com
This isn't really anything other than a Hello World kernel module.
The module is simple, with the only tricky part being replacing a system call. My goal here was to play around with the idea of modifying source code en route to a compiler/interpreter in a sneaky way. Nothing more sophisticated than that. :]
Umm, not necessarily. Instances of "World!" in your compiled kernel, toolchain and python have been replaced with "Mrrgan".
The name is clearly a nod to the classic "Reflections on Trusting Trust" by Ken Thompson (http://cm.bell-labs.com/who/ken/trust.html).
I feel the presentation in the video would be clearer if it just cat'd the source files before running/compiling them, to keep the source on-screen.
If you're looking for deeper case studies on Linux rootkits, the Suterusu rootkit is an interesting PoC: http://poppopret.org/2013/01/07/suterusu-rootkit-inline-kern...
On the other hand, if you're looking for a guide on understanding LKMs from the ground up and how they can apply to rootkits, I strongly recommend Joseph Kong's excellent book Designing BSD Rootkits. It's FreeBSD-specific and dates to 2007, but it's not still outdated AFAIR: http://www.nostarch.com/rootkits.htm
- Unlocked access to ->comm
- What if buf is less than 6 bytes or not NULL terminated?
- Only searching for sys_close() is not enough, it will also find any function pointer to sys_close() and then return a false syscall table.
Anyway, a nice hack. :-)