Posted Oct 26, 2006 21:38 UTC (Thu) by addw (guest, #1771)
Parent article: Dazuko and the LSM API
System call hooking seems to be to be an excellent way for a bit of malware to hide itself ... make itself invisible to 'ps', etc.
I'm not sure that I would want that on my system.