Anthony Lineberry on /dev/mem Rootkits
“Malicious Code Injection via /dev/mem” by Anthony Lineberry: dtors.org/papers/malicious-code-injection-via-dev-mem.pdf
“Alice in Kernel Land: Malicious Code Injection via /dev/mem” (slides to Anthony Lineberry's Black Hat Europe 2009 presentation): dtors.org/papers/injection-via-dev-mem.pdf
“Runtime Kernel kmem Patching” by Silvio Cesare: doc.bughunter.net/rootkit-backdoor/kmem-patching.html
“Linux on-the-fly kernel patching without LKM” by sd and devik, Phrack 58 (December 28, 2001): www.trust-us.ch/phrack/show.php@p=58&a=7
“Linux Kernel Rootkits” by Rainer Wichmann: www.la-samhna.de/library/rootkits/index.html
“Who needs /dev/kmem?” by Jonathan Corbet: lwn.net/Articles/147901
“The details on loading rootkits via /dev/mem” by Jonathan Corbet: lwn.net/Articles/328695
Mick Bauer (email@example.com) is Network Security Architect for one of the US's largest banks. He is the author of the O'Reilly book Linux Server Security, 2nd edition (formerly called Building Secure Servers With Linux), an occasional presenter at information security conferences and composer of the “Network Engineering Polka”.
Fast/Flexible Linux OS Recovery
On Demand Now
In this live one-hour webinar, learn how to enhance your existing backup strategies for complete disaster recovery preparedness using Storix System Backup Administrator (SBAdmin), a highly flexible full-system recovery solution for UNIX and Linux systems.
Join Linux Journal's Shawn Powers and David Huffman, President/CEO, Storix, Inc.
Free to Linux Journal readers.Register Now!
- Server Hardening
- BitTorrent Inc.'s Sync
- Download "Linux Management with Red Hat Satellite: Measuring Business Impact and ROI"
- New Container Image Standard Promises More Portable Apps
- The Humble Hacker?
- The Death of RoboVM
- The US Government and Open-Source Software
- Open-Source Project Secretly Funded by CIA
- EnterpriseDB's EDB Postgres Advanced Server and EDB Postgres Enterprise Manager
- ACI Worldwide's UP Retail Payments