reveng007 / reveng_rtkit

Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.

Home Page:https://reveng007.github.io/blog/2022/03/08/reveng_rkit_detailed.html

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Bypassing chkrootkit antirootkit

reveng007 opened this issue · comments

Goal:
Our reveng_rtkit is getting detected by chkrootkit antirootkit. till now, under chkproc section.
To evade/bypass that, we have to manipulate or get around the mechanism present in chkproc.c file, ig!?