Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...
Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...
Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Hiding processes<br />
‣ DKOM again<br />
‣<br />
‣<br />
‣ man queue(3)<br />
‣ Walk the list<br />
‣<br />
‣<br />
TECHNIQUES<br />
HIDING PROCESSES<br />
Find _allproc with our symbol resolution skillz<br />
LIST_*() from <br />
Find the matching process<br />
Remove it from the list<br />
‣ HARD!<br />
<strong>Defiling</strong> <strong>Mac</strong> <strong>OS</strong> X - <strong>Ruxcon</strong><br />
November, 2011