I-Microsoft yethule isevisi yokuthola i-rootkit ye-Linux

Microsoft kwethulwe isevisi entsha ye-inthanethi yamahhala Freta, okuhlosiwe ukuze kuqinisekiswe ukuthi izithombe zendawo ye-Linux ziskenwa ukuze kutholwe ama-rootkits, izinqubo ezifihliwe, uhlelo olungayilungele ikhompuyutha, nomsebenzi osolisayo njengokudunwa kwezingcingo zesistimu kanye nokusetshenziswa kwe-LD_PRELOAD ukuze konakalisa imisebenzi yelabhulali. Isevisi idinga ukulayisha isifinyezo sesithombe sohlelo kuseva ye-Microsoft yangaphandle futhi ihloselwe ukuhlola okuqukethwe kwendawo ebonakalayo.

Okukhiphayo kwakhiwa umbiko, okubonisa isimo samatafula esistimu, amamojula e-kernel, ukuxhumeka kwenethiwekhi, imisebenzi yokulungisa iphutha nezinqubo, ezingasetshenziswa phakathi nokuhlaziywa kwe-forensic yemiphumela yokugebenga. Isekela ukuhlaziywa kwezinhlobo ezingaphezu kuka-4000 ze-Linux kernel. Kungenzeka ukulayisha izifinyezo zezindawo ezibonakalayo kumafomethi we-VMRS (Hyper-V) kanye ne-CORE (isithombe esifinyeziwe se-VMware), kanye nokulahlwa kwenkumbulo yohlelo lokusebenza oludalwe kusetshenziswa amathuluzi. I-AVML ΠΈ Eluhlaza. Ikhodi yesevisi ibhalwe ngoRust.

I-Microsoft yethule isevisi yokuthola i-rootkit ye-Linux

Source: opennet.ru

Engeza amazwana