Just got Hacked by a Kernel-Level Rootkit
So yeah, i was on a sunny day, when i used my dummy hard disk to download the crack of Nier:Automata by Baldman, adding random tracker ro the torrent to speed up the process and damn, i got a rootkit (long story of how i could know i get infected). Luckily it’s just kernel level and i was using a dummy hard disk (as usual when i want to download a cracked app). I reformatted the Hard disk to make sure it got terminated.
So I warn you, DO NOT add additional tracker when you want to download this crack, since it’s popular i think it would be usefull to post it here. Or to be safe, Do not download the crack at all and buy it legimately.
Thanks!
Hey @Chronon, still got a copy?
I’d love to reverse it with some other people if you guys are interested :) It would probly be a great learning experience.
There’s no place like 127.0.0.1
@HackingGuy unfortunately no. I have formatted all the content of my dummy harddisk. And it would take a lot of time for me to downlpad it again, since it was 44GB.
And looks like you have some experience with this kind of thing. Is there anyway for me to detect and remove a kernel-level rootkit? Since it blends in with the OS, I have no idea what to do besides wiping it up. Yeah I am inexperienced with this thing.
Thanks
@b1nary well, to recognize it, it’s not a really big thing. But, for my computer detect it, if i want to remove it, is something I would call, almost impossible without wiping the harddisk. That’s why I am always doing a research on how I can eliminate this kind of rootkit, if not, how to detect it. It’s already a really huge deal just to detect it. Atleast for me. You have any idea about it?
http://www.faqs.org/docs/kernel/x204.html
http://es.tldp.org/Presentaciones/200211hispalinux/rusty/seminar.html
https://info.fs.tum.de/images/2/21/2011-01-19-kernel-hacking.pdf
https://w3.cs.jmu.edu/kirkpams/550-f12/papers/linux_rootkit.pdf
http://www.tldp.org/LDP/Linux-Filesystem-Hierarchy/html/proc.html
http://iacoma.cs.uiuc.edu/~nakano/dd/drivertut3.html#IntrotoDevDrv
:)
There’s no place like 127.0.0.1