Fileless ELF Execution via Kernel Keyring

(matheuzsecurity.github.io)

9 points | by matheuzsec_ 2 days ago

3 comments

  • josephcsible 2 days ago
    This looks to me like you're copying the contents of an ELF binary from userspace memory into a kernel keyring, and then immediately copying it back from the kernel keyring to userspace memory, followed by userland exec the usual way. What's the point of the keyring steps, rather than just doing userland exec alone?
    • mitxela 1 hour ago
      An LLM probably told them it was honestly a genius idea.
    • matheuzsec_ 2 days ago
      The keyring separates staging from execution, payload can be written by a different process at a different time with no file, no memfd, no open fd in /proc/pid/fd, by the time the loader runs, the payload only exists in kernel memory, direct userland exec still needs to read from somewhere visible
      • josephcsible 5 hours ago
        But then why mention execution at all, rather than just saying this is a place you can store arbitrary data?
  • westurner 2 days ago
    Can a process loaded this way be reverified once loaded?
    • mitxela 1 hour ago
      What does reverified mean?
  • matheuzsec_ 2 days ago
    [dead]