A penetration tester has successfully compromised a Linux workstation and obtained root privileges. The tester needs to establish a persistent backdoor that can be triggered by a specific HTTP request, even if the primary C2 channel is detected. Which of the following methods would be most effective and stealthy for this purpose?
- ACreating a cron job that periodically checks a remote server for commands.
- BInjecting a malicious `.so` shared library into a frequently accessed legitimate service.
- CReplacing a common system utility like `ls` with a backdoor payload.
- DModifying `/etc/passwd` to add a new root user with a known password.
Show answer & explanationAnswer & explanation
Correct answer: B. Injecting a malicious `.so` shared library into a frequently accessed legitimate service.
Injecting a malicious shared library (.so) into a legitimate service can provide a stealthy and persistent backdoor. When the legitimate service is started or accessed, the malicious library is loaded, which can then trigger a reverse shell or other C2 mechanism based on specific conditions, such as an HTTP request. This is harder to detect than modifying system users or replacing utilities.
Why the other options are wrong
- A. A cron job is detectable by examining cron tables and can be easily identified as suspicious network activity.
- C. Replacing a common utility like `ls` breaks its functionality and is very easily detected by users or integrity checks.
- D. Modifying `/etc/passwd` is easily detectable and not stealthy.
Shared Library Injection for Persistence
A stealthy persistence technique where a malicious shared library (e.g., .so on Linux, .dll on Windows) is injected into a legitimate process, allowing the attacker to execute code within the context of that process.
- Can be triggered by specific events or function calls within the legitimate process.
- Harder to detect than file-based backdoors or user modifications.
- Requires root privileges to modify system libraries or linker configurations.
Memory trick: Shared libraries hide in plain sight.