I don't want use LD_PRELOAD mechanism in user mode to hook dlopen, because Malicious Code can bypass user mode hooking.
I want to do this in kernel mode. Hooking 'open' has great side effects. Is there any other better way?
I don't want use LD_PRELOAD mechanism in user mode to hook dlopen, because Malicious Code can bypass user mode hooking.
I want to do this in kernel mode. Hooking 'open' has great side effects. Is there any other better way?