Linux

Posts tagged "Linux"

8 posts found

Anti-Debugging for Noobs, Part 1: How a Program Notices the Debugger

First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.

First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.

15 min read
2,838 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Keylogging on Linux, Part 1: From Kernel Key Handling to the X Server

How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.

How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.

48 min read
9,418 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Security Architecture of Authorisation and Authentication UIs on the Linux Desktop

A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.

A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.

20 min read
3,830 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Wayland Compositor Security Architecture and Privileged Client Management

A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.

A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.

20 min read
3,868 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Modern Linux Binary Exploitation: Memory Layout, Compiler Mitigations, and Gadget Mechanics

An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.

An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.

16 min read
3,101 words
İS

ibrahimsql

Cybersecurity Engineer

Read More