1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
|
/* ptrace.c - Wrappers for the ptrace system call.
Copyright (C) 2017 Jakob Kreuze, All Rights Reserved.
This file is part of Hypodermic.
Hypodermic is free software: you can redistribute it and/or modify it
under the terms of the GNU General Public License as published by the
Free Software Foundation, either version 3 of the License, or (at
your option) any later version.
Hypodermic is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
General Public License for more details.
You should have received a copy of the GNU General Public License
along with Hypodermic. If not, see <http://www.gnu.org/licenses/>. */
#include <sys/ptrace.h>
#include <sys/types.h>
#include <sys/user.h>
#include <sys/utsname.h>
#include <sys/wait.h>
#include <stddef.h>
#include <string.h>
#include <unistd.h>
static void run_target(const char *path) {
if (ptrace(PTRACE_TRACEME, 0, NULL, NULL) < 0) {
return;
}
execl(path, path, 0);
}
int new_proc(const char *path) {
int wait_stat;
pid_t pid;
if (path == NULL) {
return -1;
}
pid = fork();
if (pid == 0) {
run_target(path);
} else if (pid > 0) {
wait(&wait_stat);
} else {
return -1;
}
return pid;
}
int attach(int pid) {
if ((ptrace(PTRACE_ATTACH, pid, NULL, NULL)) < 0) {
return -1;
}
waitpid(pid, NULL, WUNTRACED);
return 0;
}
int detach(int pid) {
return ptrace(PTRACE_DETACH, pid, NULL, NULL) < 0;
}
int cont(int pid) {
int s;
if ((ptrace(PTRACE_CONT, pid, NULL, NULL)) < 0) {
return -1;
}
while (!WIFSTOPPED(s)) {
waitpid(pid, &s, WNOHANG);
}
return 0;
}
/* TODO: As of now, Hypodermis is strongly tied to the Intel x86
family of processors. This should really be expanded. */
int is_amd64(void) {
struct utsname ub;
uname(&ub);
return !strcmp(ub.machine, "x86_64");
}
#ifdef __x86_64__
unsigned long long getreg(int pid, int idx) {
struct user_regs_struct regs;
ptrace(PTRACE_GETREGS, pid, NULL, ®s);
return ((unsigned long long *) ®s)[idx];
}
#else
unsigned long getreg(int pid, int idx) {
struct user_regs_struct regs;
ptrace(PTRACE_GETREGS, pid, NULL, ®s);
return ((unsigned long *) ®s)[idx];
}
#endif
|