The 2016 Pwnie Nominee For Best Backdoor

PoC||GTFO 0x08: Deniable Backdoors via Compiler Bugs

Credit: Scott Bauer, Pascal Cuoq, & John Regehr

The illustrious PoC||GTFO zine included a particularly brain-bending deniable backdoor in the form of a bug in clang/LLVM 3.3 that was used to modifed the sudo binary such a local user could retain unrestricted root access to the system. This backdoor was impressive in that it can survive a manual code review and even formal verification methods.

PoC||GTFO 0x08: Deniable Backdoors via Compiler Bugs