23.12.2014 Views

Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...

Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...

Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

TECHNIQUES<br />

HIDING FILES<br />

Hiding files<br />

‣ This is pretty easy so I won’t give an example<br />

‣ As per BSD rootkits<br />

‣ Hook the getdirentries() syscall<br />

‣ As per “SYSCALL HOOKS” not very many slides ago<br />

‣ Strip the files you want to hide from its output<br />

‣ Yep.<br />

<strong>Defiling</strong> <strong>Mac</strong> <strong>OS</strong> X - <strong>Ruxcon</strong><br />

November, 2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!