CVE Tools

LD_PRELOAD Reloaded. Закрепляемся в Linux — от перехвата функций до руткита BEURK

Хакер (xakep.ru)By Моисей Сутулин

ResearchLD_PRELOADBEURK

Our summary

A new technical article details the capabilities of the LD_PRELOAD mechanism in Linux, demonstrating how attackers can use it for advanced persistence techniques such as userland rootkits. The post covers practical examples using the BEURK rootkit and explains how LD_PRELOAD allows intercepting standard library functions. A key example is the exploitation of CVE-2025-32463">CVE-2025-32463 in sudo to bypass restrictions normally placed on LD_PRELOAD. The research highlights potential risks and detection methods for administrators concerned about stealthy malicious behavior.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store