Announcement
Collapse
No announcement yet.
Turla Trojan Unearthed on Linux
Collapse
This topic is closed.
X
X
-
Turla Trojan Unearthed on Linux
Windows no longer obstructs my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock HolmesTags: None
- Top
- Bottom
-
Pan-Galactic QuordlepleenSo Long, and Thanks for All the Fish
- Jul 2011
- 9524
- Seattle, WA, USA
- Send PM
It's being over hyped. LWN has a good debunking of its supposed "stealthy" nature.
Both Ars Technica and El Reg have now said it is ultra-stealthy. From what the Kaspersky report says, I don't think so: it runs as non-root and thus cannot stop even a simple ps from finding it. Its only 'stealthy' feature that I've heard of is to open a promiscuous socket using libpcap and only open a port when a particular set of packets with specific sequence numbers turn up: that's not very stealthy given that both ss and ip can show who opened that just fine.
The other suspicious feature given is that its symbols are stripped! Oh no! /bin/ls on most distributions has stripped symbols too, does that mean that Linux distributors are distributing dangerous stealthy tools?!
- Top
- Bottom
-
Pan-Galactic QuordlepleenSo Long, and Thanks for All the Fish
- Jul 2011
- 9524
- Seattle, WA, USA
- Send PM
Comment