TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found in the wild

140 点作者 rmdoss将近 3 年前

3 条评论

28304283409234将近 3 年前
Seems to only relate to RHEL 6, or derivatives of, such as CentOS 6. Yes: 6. Which is as EOL as enterprise software gets: <a href="https:&#x2F;&#x2F;access.redhat.com&#x2F;support&#x2F;policy&#x2F;updates&#x2F;errata#Life_Cycle_Dates" rel="nofollow">https:&#x2F;&#x2F;access.redhat.com&#x2F;support&#x2F;policy&#x2F;updates&#x2F;errata#Life...</a>
评论 #31807195 未加载
评论 #31807102 未加载
评论 #31809978 未加载
rollcat将近 3 年前
OpenBSD has removed loadable kernel modules back in 2014; macOS is aggressively moving in the same direction. Meanwhile - is running a Linux system without module support even viable these days?<p>$ du -sh &#x2F;lib&#x2F;modules&#x2F;$(uname -r)<p>294M &#x2F;lib&#x2F;modules&#x2F;5.10.0-15-amd64
评论 #31811740 未加载
评论 #31810913 未加载
评论 #31810938 未加载
评论 #31809045 未加载
评论 #31809009 未加载
评论 #31829293 未加载
评论 #31810721 未加载
wazari972将近 3 年前
&gt; To load the rootkit into kernel space, it is necessary to approximately match the kernel version used for compiling; it does not have to be strictly the same.<p>&gt;&gt; vermagic=2.6.32-696.23.1.el6.x86_64 SMP mod_unload modversions<p>do you know why they say &quot;approximately match&quot;? I thought it had to match exactly so that the kernel accepts to load the module
评论 #31807732 未加载
评论 #31810990 未加载