Hacker News new | ask | show | jobs
by CUViper 4499 days ago
Yes, as long as dlopen and dlsym aren't also hooked.

You could also use asm to directly invoke sys_ptrace, since this rootkit doesn't have any kernel components.