Hacker News new | ask | show | jobs
by farisjarrah 1470 days ago
This seems to be different from previous LD_PRELOAD vulnerabilities in that it's using eBPF as part of the mechanism to obfuscate itself.
1 comments

Sure, but that’s at best a minor implementation detail. Doesn’t meaningfully increase the difficulty of detection.