Skip to content

A simple implementation of a kernel-level rootkit. Includes the functionality to intercept some system calls, as well as the functionality to change the rights of a certain process.

License

Notifications You must be signed in to change notification settings

JubyL3y/Simple-Linux-LKM-Rootkit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Simple-Linux-LKM-Rootkit

A simple implementation of a kernel-level rootkit. Includes the functionality to intercept some system calls, as well as the functionality to change the rights of a certain process. The method of intercepting system calls is implemented based on the method described in the https://xcellerator.github.io/ .

Features

  1. Interception of systemcalls using Ftrace
  2. Intercepted syscalls:
    • Getdents
    • Getdents64
    • Read
    • Mkdir
    • Readdir
  3. Privilege Escalation for process by his pid
  4. Communication with the driver is implemented through channels:
    • Procfs
    • Chardev
    • IOCTL code
  5. Tested at kernel 3.x - 4.x, 5.x not tested
  6. Functional:
    • Hide/Unhide Process
    • Hide/Unhide Network port
    • Hide/Unhide Kernel module
    • Hide/Unhide File
    • Change process credentials ( Privilege escalation to root )

LKM

LKM located in LKM directory. This directory contains 2 folder: src and build. Build folder contains Makefile for building LKM module. Src directory contains full source code of rootkit with main file named as rk_main.c

UM

UM located in LKM directory and has same folder structure as LKM folder.

Build and Install

Use make utility for build LKM and UM. After install ko file using insmod utility.

Warnings

The project was created for informational and educational purposes. The author does not bear consequences for the use of this project for illegal purposes.

About

A simple implementation of a kernel-level rootkit. Includes the functionality to intercept some system calls, as well as the functionality to change the rights of a certain process.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published