Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Using hashes to find Linux malware is a waste of time. Unfortunately, it's still common to recommend doing it. In this video I'll show you how to trivially change a Linux binary to evade detection using cryptographic hashes with this elite command: echo -ne '\x0'

29,640 Aufrufe • vor 2 Jahren •via X (Twitter)

4 Kommentare

Profilbild von Jaded Yuki
Jaded Yukivor 2 Jahren

Use the fuzz! You can use the hashes on reports to show what you looked at. Fuzzy matching, string comparisons, good yara rules, all better options 👩🏽‍💻

Profilbild von Craig Rowland - Agentless Linux Security
Craig Rowland - Agentless Linux Securityvor 2 Jahren

Sadly, fuzzy hashes are slow/resource intensive doing it across many files.

Profilbild von DJSnackcakes
DJSnackcakesvor 2 Jahren

So outside of the coventional hashing and procedural hashing checks, what would be a better menthod? I get sandboxing malware can be effective but won't that give it a chance to escape the enviroment?

Profilbild von Craig Rowland - Agentless Linux Security
Craig Rowland - Agentless Linux Securityvor 2 Jahren

@WhitfieldsDad Basically they will only work for low-hanging fruit. I think heuristics of malware activity work best.

Ähnliche Videos