Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # loadable kernel module (LKM)
- # kernel loadable module (kld) in FreeBSD, kernel extension (kext) in macOS,[1] kernel extension module in AIX, kernel-mode driver in Windows NT[2] and downloadable kernel module (DKM) in VxWorks. They are also known as kernel loadable modules (or KLM),
- # and simply as kernel modules (KMOD).
- # They are located in /lib/modules and have had the extension .ko ("kernel object") since version 2.6 (previous versions used the .o extension).[
- ps ax | wc -l
- ls -d /proc/* | grep [0-9]|wc -l
- #compare the results => should be the same
- # If an attacker can change the initramfs, they can change the kernel binary.
- #display modules
- lsmod
- less /proc/modules
- # load driver without reboot
- modprobe cdrom
- MODULES_PATH = "/etc/modprobe.d:/etc/modules-load.d"
- OLD_TYPE_FILE = "/etc/modules"
- # REMOVE MODULE
- sudo rmmod $MODULE_NAME
- sudo modprobe -r $MODULE_NAME
- #Blacklisting Modules
- nano -w /etc/modprobe.d/blacklist
- echo "blacklist e100" >> /etc/modprobe.d/blacklist
- sudo update-initramfs -u
- # all commands
- insmod
- modprobe
- rmmod
- lsmod
- modinfo
- depmod
- #wc - print newline, word, and byte counts for each file
- wc
- w
- #Show who is logged on and what they are doing.
- nc -vn 127.0.0.55 22
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement