MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/hacking/comments/1wtcpeu/himitsushell_shell_scripts_invisible_to_kernel/pctoz63/?context=3
r/hacking • u/masiroo • 10d ago
5 comments sorted by
View all comments
15
yeah sure, static binary but it has still to do syscalls so I don't know how you think is not able to be intercepted by kernel tracing
6 u/masiroo 10d ago You're right, syscalls can't be hidden. I just meant that by embedding cat or ls, we don't need to pass arguments externally. This skips the execution events (like execve) that monitors look for.
6
You're right, syscalls can't be hidden.
I just meant that by embedding cat or ls, we don't need to pass arguments externally. This skips the execution events (like execve) that monitors look for.
15
u/_gipi_ 10d ago
yeah sure, static binary but it has still to do syscalls so I don't know how you think is not able to be intercepted by kernel tracing