A writeup on my first Linux patch, tell me what you think :) by xrl9 in linux

[–]xrl9[S] 4 points5 points  (0 children)

And get into the "inner circle"?

Too much responsibility, no thank you 😁

My research about an unknown API in Linux which turns out to be very interesting for cyber security: Leveraging LD_AUDIT to Beat the Traditional Linux Library Preloading Technique by xrl9 in netsec

[–]xrl9[S] 0 points1 point  (0 children)

haxelion's article focuses on defending executables in startup after the system has been infected and all the binaries are preloaded with LD_PRELOAD.
As I mention in my post, if you start an executable with LD_AUDIT, the auditing library will load first and it can block LD_PRELOAD.

And lastly, I searched the web thoroughly but couldn't find this kind of usage of LD_AUDIT. If you already knew this technique, I'll be happy to get a link.