TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found in the wild

140 pointsby rmdossalmost 3 years ago

3 comments

28304283409234almost 3 years ago
Seems to only relate to RHEL 6, or derivatives of, such as CentOS 6. Yes: 6. Which is as EOL as enterprise software gets: <a href="https:&#x2F;&#x2F;access.redhat.com&#x2F;support&#x2F;policy&#x2F;updates&#x2F;errata#Life_Cycle_Dates" rel="nofollow">https:&#x2F;&#x2F;access.redhat.com&#x2F;support&#x2F;policy&#x2F;updates&#x2F;errata#Life...</a>
评论 #31807195 未加载
评论 #31807102 未加载
评论 #31809978 未加载
rollcatalmost 3 years ago
OpenBSD has removed loadable kernel modules back in 2014; macOS is aggressively moving in the same direction. Meanwhile - is running a Linux system without module support even viable these days?<p>$ du -sh &#x2F;lib&#x2F;modules&#x2F;$(uname -r)<p>294M &#x2F;lib&#x2F;modules&#x2F;5.10.0-15-amd64
评论 #31811740 未加载
评论 #31810913 未加载
评论 #31810938 未加载
评论 #31809045 未加载
评论 #31809009 未加载
评论 #31829293 未加载
评论 #31810721 未加载
wazari972almost 3 years ago
&gt; To load the rootkit into kernel space, it is necessary to approximately match the kernel version used for compiling; it does not have to be strictly the same.<p>&gt;&gt; vermagic=2.6.32-696.23.1.el6.x86_64 SMP mod_unload modversions<p>do you know why they say &quot;approximately match&quot;? I thought it had to match exactly so that the kernel accepts to load the module
评论 #31807732 未加载
评论 #31810990 未加载