Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

abuseofthelinuxkernel-phrack50_5-halflife

2025-04-12

Abuse of the Linux Kernel for Fun and Profit

by halflife

Phrack Magazine issue 50 article 5

April 9, 1997

https://phrack.org/issues/50/5#article

https://archives.phrack.org/issues/50/5.txt

Notes
Linux
Linux kernel
for fun and profit
halflife
guild corporation
LKM
device driver
system call
tty hijacker, tty monitor, tty hijacking
tap, ttywatcher – Solaris, SunOS
STREAMS
telnetsnoop
PTY, TTY
LinSTREAMS
TIOCSTI
ioctl
keystroke
write(2)
DOS terminate and stay resident
hacked_setuid.c
insmod
setuid root
sys_call_table
syscall hooking
Linspy
/proc/modules
ltap device
major, minor device numbers
ltread
UID, GID, EUID, EGID

Links to this note

  • Notes
  • hiddenkernelmodulesextremwayreborn_g1inko2024

Recent Posts

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes

Defanging Linux LKM Rootkits With cleanup_module()

2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.