$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: reverse a Linux kernel rootkit (malware.ko) that uses ftrace to hook syscalls and filter /dev/kmsg output. Solution: identify dentry-based filename check in hook_read, bypass by creating alternate device node with mknod to read unfiltered kernel logs revealing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar