LKM rootkits in 2.6.x

From: pg smith
Date: Thu Mar 11 2004 - 13:42:09 EST

Any thoughts on the future of LKM rootkits in the 2.6 kernel branch ? In
the last few years I've become quite interested in them (from a defensive
point of view), but with the 2.6 kernel no longer exporting the syscall
table, intercepting system calls would appear to be a non-starter now. In
a perverse sort of way, i'm actually rather dissapointed: all that
learning gone to waste.



To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at
Please read the FAQ at