Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

Linux x86 run time process manipulation

[------------------------------------------------------------------------]
[-- Uninformed Research -- informative information for the uninformed. --]
[------------------------------------------------------------------------]
[-- Genre : Development --]
[-- Name : needle --]
[-- Desc : Linux x86 run-time process manipulation --]
[-- Url : http://www.uninformed.org/ --]
[-- Use : EVILNESS --]
[------------------------------------------------------------------------]
[-- Author : skape (mmiller@hick.org) --]
[-- Date : 01/19/2003 --]
[------------------------------------------------------------------------]
[-- Table of contents: --]
1) Overview
1.1) Topics
1.2) Techniques
1.3) Execution Diversion
2) Memory Allocation
3) Memory Management
4) Library Injection
5) Code Injection
5.1) Forking
5.2) Threading
5.3) Function Trampolines
6) Conclusion
7) References
[-- 1) Overview --]
So, you want to be evil and modify the image of an executing
process? Well, perhaps you've come to the right place. This
document deals strictly with some methodologies used to to
alter process images under Linux. If you're curious about how
to do something similar to the things listed in this document in
Windows, please read the ``References`` section.
[-- 1.1) Topics --]
The following concepts will be discussed in this document as they
relate t


Ïà¹ØÎĵµ£º

(ת)LINUX ÐźŻúÖÆ¡¾ÁÐ±í¡¿

Ðźű¾ÖÊ
ÐźÅÊÇÔÚÈí¼þ²ã´ÎÉ϶ÔÖжϻúÖÆµÄÒ»ÖÖÄ£Ä⣬ÔÚÔ­ÀíÉÏ£¬Ò»¸ö½ø³ÌÊÕµ½Ò»¸öÐźÅÓë´¦ÀíÆ÷ÊÕµ½Ò»¸öÖжÏÇëÇó¿ÉÒÔ˵ÊÇÒ»ÑùµÄ¡£ÐźÅÊÇÒì²½µÄ£¬Ò»¸ö½ø³Ì²»±ØÍ¨¹ýÈκβÙ×÷À´µÈ´ýÐźŵĵ½´ï£¬ÊÂʵÉÏ£¬½ø³ÌÒ²²»ÖªµÀÐźŵ½µ×ʲôʱºòµ½´ï¡£
ÐźÅÊǽø³Ì¼äͨÐÅ»úÖÆÖÐΨһµÄÒ첽ͨÐÅ»úÖÆ£¬¿ÉÒÔ¿´×÷ÊÇÒ첽֪ͨ£¬Í¨Öª½ÓÊÕÐźŵĽø³Ì ......

Linux ¹ØÓÚ¶¯Ì¬Á´½Ó¿âÒÔ¼°¾²Ì¬Á´½Ó¿âµÄһЩ¸ÅÄî

¿âÓж¯Ì¬Ó뾲̬Á½ÖÖ£¬¶¯Ì¬Í¨³£ÓÃ.soΪºó׺£¬¾²Ì¬ÓÃ.aΪºó׺¡£ÀýÈ磺libhello.so libhello.a
ΪÁËÔÚͬһϵͳÖÐʹÓò»Í¬°æ±¾µÄ¿â£¬¿ÉÒÔÔÚ¿âÎļþÃûºó¼ÓÉϰ汾ºÅΪºó׺,ÀýÈ磺 libhello.so.1.0,ÓÉÓÚ³ÌÐòÁ¬½ÓĬÈÏÒÔ.soΪÎļþºó׺Ãû¡£ËùÒÔΪÁËʹÓÃÕâЩ¿â£¬Í¨³£Ê¹Óý¨Á¢·ûºÅÁ¬½ÓµÄ·½Ê½¡£
ln -s libhello.so.1.0 libhello.so.1 ......

linuxÎļþϵͳÌåϵ½á¹¹ ºÍ ÐéÄâÎļþϵͳ(VFS)

ͼ 1. Linux Îļþϵͳ×é¼þµÄÌåϵ½á¹¹
 
Óû§¿Õ¼ä°üº¬Ò»Ð©Ó¦ÓóÌÐò£¨ÀýÈ磬ÎļþϵͳµÄʹÓÃÕߣ©ºÍ GNU C ¿â£¨glibc£©£¬ËüÃÇΪÎļþϵͳµ÷Ó㨴ò¿ª¡¢¶ÁÈ¡¡¢Ð´ºÍ¹Ø±Õ£©ÌṩÓû§½Ó¿Ú¡£ÏµÍ³µ÷ÓýӿڵÄ×÷ÓþÍÏñÊǽ»»»Æ÷£¬Ëü½«ÏµÍ³µ÷ÓôÓÓû§¿Õ¼ä·¢Ë͵½Äں˿ռäÖеÄÊʵ±¶Ëµã¡£
VFS ÊǵײãÎļþϵͳµÄÖ÷Òª½Ó¿Ú¡£Õâ¸ö×é¼þµ¼³öÒ» ......

ÓÃSource Insight½¨Á¢Ò»¸öLinuxÄں˴úÂ빤³Ì


¾ßÌå²½ÖèÈçÏ£º
£¨Ò»£©´ò¿ªSource Insight£¬µ¥»÷¡¾ÏîÄ¿¡¿°´Å¥£¬µ¯³öÏÂÀ­²Ëµ¥¡£
£¨¶þ£©µ¥»÷¡¾ÐÂÏîÄ¿¡¿°´Å¥£¬µ¯³ö¡¾ÐÂÏîÄ¿¡¿¶Ô»°¿ò£¬ÊäÈëÏîÄ¿ÃûºÍ´æ·Å·¾¶£¬µ¥»÷¡¾È·¶¨¡¿°´Å¥¡£Èçͼ1Ëùʾ¡£
 
ͼ1 ÐÂÏîÄ¿¶Ô»°¿ò
ÎÄÕÂÀ´Ô´£ºhttp://top-e.org/jiaoshi/html/539.html
£¨Èý£©µ¯³ö¡¾Ìí¼Óɾ³ýÎļþ¡¿¶Ô»°¿ò£¬ÔÚÄÚºËÔ´´ú ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ