Invisible Reverse Shells: How gsocket Backdoors Hide in Plain Sight
The crontab looked empty. The .profile had a system comment. The .bashrc seemed normal. All three were hiding gsocket reverse shells using ANSI escape codes that erase themselves from terminal output.
Read Article