Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...
Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...
Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
TECHNIQUES<br />
HIDING FILES<br />
Hiding files<br />
‣ This is pretty easy so I won’t give an example<br />
‣ As per BSD rootkits<br />
‣ Hook the getdirentries() syscall<br />
‣ As per “SYSCALL HOOKS” not very many slides ago<br />
‣ Strip the files you want to hide from its output<br />
‣ Yep.<br />
<strong>Defiling</strong> <strong>Mac</strong> <strong>OS</strong> X - <strong>Ruxcon</strong><br />
November, 2011