• About
  • Privacy Policy
  • Contact us
  • Submit a story
Linux-News Linux news from the Blogosphere
  • Article
  • Howto
  • News
  • Opinion
  • Review
  • RSS Feed
  • Twitter
  • Facebook

New Linux Rootkit Emerges

By
News
– November 22, 2012Posted in: Article, News, Submitted

A new Linux rootkit has emerged and researchers who have analyzed its code and operation say that the malware appears to be a custom-written tool designed to inject iframes into Web sites and drive traffic to malicious sites for drive-by download attacks. The rootkit is designed specifically for 64-bit Linux systems, and while it has some interesting features, it does not appear to be the work of high-level programmer or be meant for use in targeted attacks.

The new Linux rootkit is loaded into memory and once there, it pulls out some memory addresses and then stores them for use later. It also then hooks into several kernel functions as a way to hide some of its files on the machine.

“To hook private functions that are called without indirection (e.g., through a function pointer), the rootkit employs inline code hooking. In order to hook a function, the rootkit simply overwrites the start of the function with an e9 byte. This is the opcode for a jmp rel32 instruction, which, as its only operand, has 4 bytes relative offset to jump to,” Georg Wicherski of CrowdStrike wrote in a detailed analysis of the new Linux malware

 

Complete Story



Tags: indirection, kernel functions, linux, linux rootkit, malware, memory addresses, opcode, pointer, private functions

About News

No Comments

Start the ball rolling by posting a comment on this article!

Leave a Reply Cancel reply

Your email address will not be published.

  • Suggested Sites
    http://linuxaria.com everything about Linux http://linuxaria.com everything about Linux
  • Curated topic
  • Recent Posts
    • The Ultimate Guide to Compressing PDF Files: Shrink Size, Save Space
    • Master Parliamentary Procedure: A Guide to Robert’s Rules of Order (PDF)
    • Optimize Your D&D Experience: The Essential Guide to the “D&D 5e Character Sheet PDF”
    • How to Get Your Free Printable 2021 PDF Calendar Today!
    • Unlock Deeper Learning: A Comprehensive Guide to Situated Learning Theory Process PDF
    • Discover the Ultimate Guide to Reading Juice for Kids PDF Free Download
    • Effortless PDF to Word Conversion: A Comprehensive Guide
    • Download the Latest “Approved Medical Abbreviations 2023 PDF” for Error-Free Healthcare Communication
    • Ace Your NY Permit Test: A Comprehensive Practice with Our 20-Question PDF
    • How to Delete Pages of a PDF: A Comprehensive Guide for PDF Editing
  • Ranking

About Arras WordPress Theme

All site content, except where otherwise noted, is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.