forensicsmedium
Suspicious Threat Challenge
hackthebox
Task: Linux server s userland rootkit cherez LD_PRELOAD, skryvayushchim fajly/direktorii. Solution: Analiz malicious library (libc.hook.so.6), obnaruzhenie hooked funkcij readdir/readdir64, bypass cherez pryamoj syscall getdents64 dlya poiska skrytoj direktorii s flagom.
$ ls tags/ techniques/
binary_analysisld_preload_detectionsyscall_bypassgetdents64
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]