New Linux Remote Access Trojan targets Thailand with rootkits

Discussion in 'all things UNIX' started by 1PW, Dec 8, 2023.

  1. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    LOL, so basically Linux is just as crappy as Windows. :p

    But all kidding aside, I still don't understand why Windows and apparently also Linux are designed in a way to make rootkits possible in the first place. It's almost like they wanted to built-in a hidden backdoor. I mean no legitimate app needs such functionality.
     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada
    Well, to get some perspective on this kernel rootkit, from the article:

    Latest 2.6x is 2011, while 3.10x is 2012 ;)

    As well from the same article:

    An even somewhat up to date kernel resists the first pathways, while installing updates from only trusted repositories addresses the latter pathway.
     
  4. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    Red Hat Enterprise Linux 7 includes Linux kernel 3.10. Plenty of computers at large enterprises may still use it. I don't understand why they would install package from untrustworthy third-party source in that setting though.
     
  5. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada
    Good point, or why they would still run an older kernel version, unless it's been secured somehow, maybe with SELinux for example.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice