RE: Backdooring the OpenSSH server 01-29-2018, 09:20 PM
#3
(01-29-2018, 09:12 PM)phyrrus9 Wrote: There is a way to do this even without recompiling openssh binaries. You can make a file containing only that function, then compile it as a .so shared library, then re-execute SSH with
Code:# LD_PRELOAD=/tmp/backdoor.so `which sshd`
The linux dynamic linker will then replace the openssh symbol for that function with your function, essentially patching it at runtime. Doing this will ensure that the binary still passes load time signature and integrity checks, and if you can sign your preload with a valid signature you can even defeat the kernel checks.
Thanks for the information, I should research this.












![[Image: 9H83e18.png]](https://i.imgur.com/9H83e18.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)