Re: Link time manipulation of kernel symbols like read/write

From: Leonidas .
Date: Sun May 09 2010 - 11:19:47 EST


>
> lkml is not rootkit-help-for-free ;-)

I promise that I am not going to write a root kit :-). But you gave me
a good start, I will
have to check some of the root kits in order to see how things happen there.

Actually, I want to see similarities between user space way of
linking/loading compared to
kernel space. Have not been able to figure out completely yet at
conceptual level. I have
gone through module.c file and insmod utility.

Any pointers to earlier such attempts would be helpful.

-Leo.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/