Sada je: 16 lis 2019, 05:49.
Novosti iz Linux svijeta. Komentiranje vijesti s portala.

Moderator/ica: Moderatori/ce

Malware se sakriva u GPU

Rootkit koji skriva u GPU računala i može pročitati u tajnosti sve što pišete.

Jellyfish is a Linux based userland gpu rootkit proof of concept project utilizing the LD_PRELOAD technique from Jynx (CPU), as well as the OpenCL API developed by Khronos group (GPU). Code currently supports AMD and NVIDIA graphics cards. However, the AMDAPPSDK does support Intel as well.

Advantages of gpu stored memory:

-No gpu malware analysis tools available on web
-Can snoop on cpu host memory via DMA
-Gpu can be used for fast/swift mathematical calculations like xor'ing or parsing
-Stubs
-Malicious memory may be retained across warm reboots. (Did more conductive research on the theory of malicious memory still being in gpu after shutdown)


https://github.com/x0r1/jellyfish



Nadam se da je OK

LP b4sh
"The quieter you become, the more you are able to hear...."
Avatar
Postovi: 404
Postovi: 404
Pridružen/a: 04 tra 2012, 21:31
Podijelio/la zahvalu: 11 puta
Primio/la zahvalu: 27 puta
Spol: M
OS: Debian
Na mreži
Trenutno korisnika/ca: / i 1 gost.