Notices where this attachment appears
-
Embed this notice
@r000t The linked source main.c appears to actually be the main.c file from one version of vanguard, but of course that's nothing but a kludge that jumps to the rootkit, which is provided in binary form.
Of course, your typically reddit poster opens the repo and sees the main.c file and assumes that such is "open source".
Seeing that https://raw.githubusercontent.com/RiotVanguard/Vanguard/main/LICENSE is a copy of the GPLv2 and a compiled version of the kernel driver is provided here; https://github.com/RiotVanguard/Vanguard/raw/main/Compiled/AMD64/Vanguard.sys they've given permission to reverse engineer that module (too bad it clearly downloads the rest of the module over the internet, seeing how it's "only" 22.3 KiB) and although it's the downloaders duty to demand the source code of that kernel module under the GPLv2, too bad riot is lying about the license.