Linux malware often uses classic BPF socket programs as stealthy backdoors that stay dormant until receiving a specific 'magic' packet. Manually reverse-engineering these filters is slow and error-prone, especially for programs exceeding 100 instructions. Cloudflare researchers built a tool called filterforge that applies

12m read timeFrom blog.cloudflare.com
Post cover image
Table of contents
The complexity ceilingExhibit A: BPFDoorEmploying Z3 and scapyTry it yourself

Sort: