
Stephan Berger
@malmoeb
Head of Investigations @InfoGuardAG
infosec.exchange/@malmoeb
ID: 910694455
https://dfir.ch/ 28-10-2012 16:57:26
2,2K Tweet
26,26K Takipçi
1,1K Takip Edilen




As I'm about to present about Linux Rootkits at the 10th edition of EuskalHack (🎉), here’s a nifty trick to detect a userland rootkit that tries to hide its presence by blocking access to /etc/ld.so.preload. We are mounting the filesystem with debugfs (an interactive file




The screenshot below is from a recent Incident Response case, investigated by my colleague Flo Scheiber. The user "printer" suddenly sprang to life because an attacker brute-forced the VPN login (without Multi-Factor Authentication). This was not the first time a "printer"













