<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=5074&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Linux malware - possibly undetectable?]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=5074</link>
		<description><![CDATA[The most recent posts in Linux malware - possibly undetectable?.]]></description>
		<lastBuildDate>Sat, 25 Jun 2022 18:37:38 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Linux malware - possibly undetectable?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36426#p36426</link>
			<description><![CDATA[<p>Right, <br />I wonder if checking your sockets could detect it. I think you are pretty save. </p><div class="codebox"><pre><code>netstat -ao | less</code></pre></div><p>&#160; check your sockets in recovery and in full user mode. <br />Look for anything abnormal. It&#039;s good to get familiar with what your system sockets look like. dbus is pretty busy. If you can minimize sockets you minimize attack surface.<br />Most of the targeted libs are apache or java related. Minimalism is a good bet.<br />Again though a lot of linux vulnerabilities seem to happen early during boot process or in between system upgrades I imagine is when they are the most vulnerable. I am only guessing though that&#039;s when you are dealing with root kit level stuff. <br />Only way to get persistence as well I imagine.</p>]]></description>
			<author><![CDATA[dummy@example.com (czeekaj)]]></author>
			<pubDate>Sat, 25 Jun 2022 18:37:38 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36426#p36426</guid>
		</item>
		<item>
			<title><![CDATA[Re: Linux malware - possibly undetectable?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36260#p36260</link>
			<description><![CDATA[<p>There are some markers for it:</p><p><a href="https://blogs.blackberry.com/en/2022/06/symbiote-a-new-nearly-impossible-to-detect-linux-threat" rel="nofollow">https://blogs.blackberry.com/en/2022/06 … nux-threat</a></p><p>^ See the &quot;Indicators of Compromise (IoCs)&quot; section for details.</p><p>Anyway this is aimed at banks and suchlike so I don&#039;t think desktop users have to worry too much.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Sat, 11 Jun 2022 11:08:32 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36260#p36260</guid>
		</item>
		<item>
			<title><![CDATA[Linux malware - possibly undetectable?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36259#p36259</link>
			<description><![CDATA[<p>Hello:</p><p>Found this early today.</p><p>---<br />Symbiote Linux malware spotted, and infections are &#039;very hard to detect&#039;<br />&#039;Performing live forensics on an infected machine may not turn anything up&#039; warn researchers<br />---</p><p><a href="https://forums.theregister.com/forum/all/2022/06/10/symbiote_linux_malware/" rel="nofollow">https://forums.theregister.com/forum/al … x_malware/</a></p><p>Anyone know about this?</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sat, 11 Jun 2022 11:05:05 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36259#p36259</guid>
		</item>
	</channel>
</rss>
