1603, 1/81 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ÇØÅ·ÀßÇÏ°í½Í´Ù
   http://¾øÀ½
   screenshot.png (190.8 KB), Download : 3     [¿À¸¥ÂÊ ¹öÆ° ´­·¯ ´Ù¿î ¹Þ±â]
   ½Ã½ºÅÛ ÄÝ ÃßÀû È®ÀåÆÇ

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=8597 [º¹»ç]



#include <sys/ptrace.h>
#include <sys/types.h>
#include <sys/wait.h>
#include <sys/user.h>
#include <unistd.h>
#include <stdio.h>

// ½Ã½ºÅÛ ÄÝ ¹øÈ£¿Í À̸§ ¸ÅÇÎ
const char *syscall_names[] = {
    "read", "write", "open", "close", "stat", "fstat", "lstat", "poll",
    "lseek", "mmap", "mprotect", "munmap", "brk", "rt_sigaction", "rt_sigprocmask",
    "ioctl", "pread64", "pwrite64", "readv", "writev", "access", "pipe", "select",
    // ÇÊ¿ä½Ã Ãß°¡
};

void print_syscall_name(long syscall_no) {
    if (syscall_no >= 0 && syscall_no < sizeof(syscall_names) / sizeof(syscall_names[0])) {
        printf("½Ã½ºÅÛ ÄÝ: %s (%ld)\n", syscall_names[syscall_no], syscall_no);
    } else {
        printf("¾Ë ¼ö ¾ø´Â ½Ã½ºÅÛ ÄÝ (%ld)\n", syscall_no);
    }
}

int main() {
    pid_t child;
    pid_t pid, ppid, pgid, sid;
    struct user_regs_struct regs;
    int status;

    pid = getpid();
    ppid = getppid();
    pgid = getpgid(0);
    sid = getsid(0);

    printf("ºÎ¸ð ÇÁ·Î¼¼½º Á¤º¸:\n");
    printf("PID: %d\n", pid);
    printf("PPID: %d\n", ppid);
    printf("PGID: %d\n", pgid);
    printf("SID: %d\n", sid);

    child = fork();
    if (child == 0) {
        ptrace(PTRACE_TRACEME, 0, NULL, NULL);
        execl("/bin/ls", "ls", NULL);
    } else {
        wait(&status);
        printf("\n½Ã½ºÅÛ ÄÝ ÃßÀû ½ÃÀÛ:\n");
        while (!WIFEXITED(status)) {
            // ½Ã½ºÅÛ ÄÝ Á÷Àü ÀÎÅͼÁÆ®
            ptrace(PTRACE_SYSCALL, child, NULL, NULL);
            wait(&status);

            if (WIFSTOPPED(status)) {
                // ·¹Áö½ºÅÍ »óÅ Àбâ
                ptrace(PTRACE_GETREGS, child, NULL, ®s);
                print_syscall_name(regs.orig_rax);
            }

            // ½Ã½ºÅÛ ÄÝ Á÷ÈÄ ÀÎÅͼÁÆ®
            ptrace(PTRACE_SYSCALL, child, NULL, NULL);
            wait(&status);
        }
        printf("½Ã½ºÅÛ ÄÝ ÃßÀû Á¾·á.\n");
    }
    return 0;
}

  Hit : 527     Date : 2025/01/19 05:49



    
indra ¸ÚÁø ±ÛÀ̳׿ä.
ptrace()¸¦ Àß ´Ù·ê ¼ö ÀÖ°í ½Ã½ºÅÛ¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ´Ù¸é ¸¹Àº °ÍµéÀ» ÇÒ ¼ö ÀÖ½À´Ï´Ù.
¿ÀÆæ½ÃºêÂÊ¿¡¼­´Â ¿©ÀüÈ÷ Àß »ç¿ëµÇ°í ÀÖÁö¸¸ º¸¾ÈÀ̳ª ¸ð´ÏÅ͸µÃø¸é¿¡¼­´Â ½Ã½ºÅÛ ¾ÈÁ¤¼ºÀ» À§ÇØ ptrace() ¸¦ Á÷Á¢ »ç¿ëÇÏ´Â °Í º¸´Ù eBPF ÂÊ ¿µ¿ªÀ¸·Î °¡ÁöÄ¡±â ÇÑÁö ²Ï µÈ °Í °°³×¿ä.
Àß º¸¾Ò½À´Ï´Ù.
2025/01/31  
ÇØÅ·ÀßÇÏ°í½Í´Ù indra // ¸ÚÁø ±ÛÀ̶ó´Â ĪÂù¿¡ °¨»çÀÇ ¸»¾¸µå¸³´Ï´Ù.
½Ã½ºÅÛ ÇÁ·Î±×·¡¹Ö ÂÊÀº ÇغÃÀÚ Win32 API¶û Posix-C¹Û¿¡ °øºÎÇÑ °Ô ¾ø¾î¼­¿ä.
°´Ã¼ÁöÇâ ¾ð¾îµµ °³³ä¸¸ ¾Ë »Ó, Á¶±Ý ¹Û¿¡ ¸ð¸£°í...
ºÎÁ·ÇÑ Á¡ÀÌ ¸¹Áö¸¸ ±àÁ¤ÀûÀ¸·Î ºÁÁּż­ °¨»çÇÕ´Ï´Ù. ;-)
2025/02/06  
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 19902
1602   ÇØÄ¿½ºÄ𠸸ȭÀÇ ÀÚµ¿À¸·Î ½ºÄµÇÏ´Â ÇÁ·Î±×·¥     ÇØÅ·ÀßÇÏ°í½Í´Ù
02/18 354
  ½Ã½ºÅÛ ÄÝ ÃßÀû È®ÀåÆÇ[2]     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/19 526
1600   °£´ÜÇÑ ½Ã½ºÅÛ ÄÝ ÃßÀû ÇÁ·Î±×·¥ ¸¸µé±â     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/18 506
1599   [overthewire.org] - leviathan1     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 820
1598   [overthewire.org] - leviathan0     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 553
1597   [Write Up] Crypto Cat's CTF 2024 - BabyFlow     ÇØÅ·ÀßÇÏ°í½Í´Ù
12/29 566
1596   [pwnable.kr] bof     ÇØÅ·ÀßÇÏ°í½Í´Ù
12/25 556
1595   [pwnable.kr] Shellshock[1]     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/23 671
1594   ShellshockÀÇ ±âº» ¿ä¾à     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/23 658
1593   [pwnable.kr] fd     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/23 654
1592   VPNÀÌ ¿¬°áµÇ¾ú´Ù°¡ µµÁß¿¡ ²¨µµ À¥ ºê¶ó¿ìÀú»ó¿¡¼­ À¯ÁöµÇ´Â ÀÌÀ¯     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/22 603
1591   ÇØÄ¿µéÀÌ ÇØÅ·½Ã »ç¿ëÇÏ´Â µð·ºÅ丮 °ø°£[1]     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/22 684
1590   Keyboard Hooking -part2 - (Python3 ver)     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/20 634
1589   [Windows API] Keyboard Hooking     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/20 462
1588   [pwnable.kr] cmd1 °ø·«     ÇØÅ·ÀßÇÏ°í½Í´Ù
10/23 635
1587   netdiscover ÆÄÀ̽ãÀ¸·Î ±¸ÇöÇϱ⠠   ÇØÅ·ÀßÇÏ°í½Í´Ù
08/13 846
1586   ÆÄÀ̽ãÀ» ÀÌ¿ëÇÑ ½ÉÇà À¥ Å©·Ñ·¯     ÇØÅ·ÀßÇÏ°í½Í´Ù
08/13 719
1585   ÆÄÀ̽ã random¸ðµâÀ» ÀÌ¿ëÇÑ ¼ýÀÚ¸ÂÃ߱⠰ÔÀÓ ±¸Çö     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/30 1303
1584   ÆÄÀ̽ã äÆà ÇÁ·Î±×·¥ ±¸Çö     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/28 1231
1 [2][3][4][5][6][7][8][9][10]..[81]

Copyright 1999-2025 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org