forensicsmedium

Suspicious Threat Challenge

hackthebox

Task: Linux server s userland rootkit cherez LD_PRELOAD, skryvayushchim fajly/direktorii. Solution: Analiz malicious library (libc.hook.so.6), obnaruzhenie hooked funkcij readdir/readdir64, bypass cherez pryamoj syscall getdents64 dlya poiska skrytoj direktorii s flagom.

$ ls tags/ techniques/
binary_analysisld_preload_detectionsyscall_bypassgetdents64

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]