* Link time manipulation of kernel symbols like read/write
@ 2010-05-07 17:51 Leonidas .
2010-05-09 6:51 ` Leonidas .
0 siblings, 1 reply; 4+ messages in thread
From: Leonidas . @ 2010-05-07 17:51 UTC (permalink / raw)
To: linux-kernel
Hi folks,
Is it possible to wrap module entry points like open/close during the
module compilation?
By wrapping, I mean interposing using linker --wrap option. This is
very much possible in
user space and is commonly used to interpose library functions.
E.g.
void *
__wrap_malloc (int c)
{
printf ("malloc called with %ld\n", c);
return __real_malloc (c);
}
int main()
{
malloc(17);
return 0;
}
Above works expected, can we wrap kmalloc this way?
-Leo.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Link time manipulation of kernel symbols like read/write
2010-05-07 17:51 Link time manipulation of kernel symbols like read/write Leonidas .
@ 2010-05-09 6:51 ` Leonidas .
2010-05-09 14:38 ` Arjan van de Ven
0 siblings, 1 reply; 4+ messages in thread
From: Leonidas . @ 2010-05-09 6:51 UTC (permalink / raw)
To: linux-kernel
Couple more questions:
1. How does the dynamic linking/loading happen in kernel? What is the
equivalent of ld-linux.so in kernel space?
Any pointer will be helpful
-Leo
On Fri, May 7, 2010 at 11:21 PM, Leonidas . <leonidas137@gmail.com> wrote:
> Hi folks,
>
> Is it possible to wrap module entry points like open/close during the
> module compilation?
> By wrapping, I mean interposing using linker --wrap option. This is
> very much possible in
> user space and is commonly used to interpose library functions.
>
> E.g.
>
> void *
> __wrap_malloc (int c)
> {
> printf ("malloc called with %ld\n", c);
> return __real_malloc (c);
> }
>
> int main()
> {
> malloc(17);
> return 0;
> }
>
> Above works expected, can we wrap kmalloc this way?
>
> -Leo.
>
--
-Leo.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Link time manipulation of kernel symbols like read/write
2010-05-09 6:51 ` Leonidas .
@ 2010-05-09 14:38 ` Arjan van de Ven
2010-05-09 15:19 ` Leonidas .
0 siblings, 1 reply; 4+ messages in thread
From: Arjan van de Ven @ 2010-05-09 14:38 UTC (permalink / raw)
To: Leonidas .; +Cc: linux-kernel
On Sun, 9 May 2010 12:21:35 +0530
"Leonidas ." <leonidas137@gmail.com> wrote:
> Couple more questions:
>
> 1. How does the dynamic linking/loading happen in kernel? What is the
> equivalent of ld-linux.so in kernel space?
lkml is not rootkit-help-for-free ;-)
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Link time manipulation of kernel symbols like read/write
2010-05-09 14:38 ` Arjan van de Ven
@ 2010-05-09 15:19 ` Leonidas .
0 siblings, 0 replies; 4+ messages in thread
From: Leonidas . @ 2010-05-09 15:19 UTC (permalink / raw)
To: Arjan van de Ven; +Cc: linux-kernel
>
> lkml is not rootkit-help-for-free ;-)
I promise that I am not going to write a root kit :-). But you gave me
a good start, I will
have to check some of the root kits in order to see how things happen there.
Actually, I want to see similarities between user space way of
linking/loading compared to
kernel space. Have not been able to figure out completely yet at
conceptual level. I have
gone through module.c file and insmod utility.
Any pointers to earlier such attempts would be helpful.
-Leo.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2010-05-09 15:19 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-05-07 17:51 Link time manipulation of kernel symbols like read/write Leonidas .
2010-05-09 6:51 ` Leonidas .
2010-05-09 14:38 ` Arjan van de Ven
2010-05-09 15:19 ` Leonidas .
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®