Linux Backdoor Deep Dive (Part 3)

Опубликовано: 18 Апрель 2026
на канале: LaurieWired
3,649
169

In this [RE]laxing new series, I fully reverse a Linux Backdoor (BPFDoor) from start to finish. In Part 3, we start examining the iptables commands and discover the code for binding the socket.

These extensive "Deep Dive" segments concentrate on dissecting malware specimens and delving into the individual approaches employed to fully reverse them. Throughout the journey, I attempt to provide explanations of my techniques as much as possible, however, if any ambiguities arise, please feel free to post a comment below.

---

Timestamps:
00:00 Intro
00:40 IPtables
03:35 Fixing Strings
05:57 More IPtables Strings!
09:49 snprintf
10:54 Marking up Local Vars
12:17 system
13:34 Mystery Function
16:30 Passing socket return
19:20 Naming Conventions
20:45 Recap

---

Software Links Mentioned in Video:
Ghidra: https://ghidra-sre.org/
---
Malware Examined in the video (BPFDoor):
sha256:fd1b20ee5bd429046d3c04e9c675c41e9095bea70e0329bd32d7edd17ebaf68a

MalwareBazaar Link:
https://bazaar.abuse.ch/sample/fd1b20...

---
laurieWIRED Twitter:
  / lauriewired  

laurieWIRED Website:
http://lauriewired.com

laurieWIRED Github:
https://github.com/LaurieWired

laurieWIRED HN:
https://news.ycombinator.com/user?id=...

laurieWIRED Reddit:
  / lauriewired