__ __ __ __ _____ _ _ _____ _ _ _ | \/ | \ \ / / | __ \ (_) | | / ____| | | | | | \ / |_ __\ V / | |__) | __ ___ ____ _| |_ ___ | (___ | |__ ___| | | | |\/| | '__|> < | ___/ '__| \ \ / / _` | __/ _ \ \___ \| '_ \ / _ \ | | | | | | |_ / . \ | | | | | |\ V / (_| | || __/ ____) | | | | __/ | | |_| |_|_(_)_/ \_\ |_| |_| |_| \_/ \__,_|\__\___| |_____/|_| |_|\___V 2.1 if you need WebShell for Seo everyday contact me on Telegram Telegram Address : @jackleetFor_More_Tools:
#!/usr/bin/python
#
# strlen_hist_ifunc.py Histogram of system-wide strlen return values.
# This can be used instead of strlen_hist.py if strlen is indirect function.
from __future__ import print_function
from bcc import BPF
from bcc.libbcc import lib, bcc_symbol, bcc_symbol_option
import ctypes as ct
import sys
import time
NAME = 'c'
SYMBOL = 'strlen'
STT_GNU_IFUNC = 1 << 10
HIST_BPF_TEXT = """
#include <uapi/linux/ptrace.h>
BPF_HISTOGRAM(dist);
int count(struct pt_regs *ctx) {
dist.increment(bpf_log2l(PT_REGS_RC(ctx)));
return 0;
}
"""
SUBMIT_FUNC_ADDR_BPF_TEXT = """
#include <uapi/linux/ptrace.h>
BPF_PERF_OUTPUT(impl_func_addr);
void submit_impl_func_addr(struct pt_regs *ctx) {
u64 addr = PT_REGS_RC(ctx);
impl_func_addr.perf_submit(ctx, &addr, sizeof(addr));
}
BPF_PERF_OUTPUT(resolv_func_addr);
int submit_resolv_func_addr(struct pt_regs *ctx) {
u64 rip = PT_REGS_IP(ctx);
resolv_func_addr.perf_submit(ctx, &rip, sizeof(rip));
return 0;
}
"""
def get_indirect_function_sym(module, symname):
sym = bcc_symbol()
sym_op = bcc_symbol_option()
sym_op.use_debug_file = 1
sym_op.check_debug_file_crc = 1
sym_op.lazy_symbolize = 1
sym_op.use_symbol_type = STT_GNU_IFUNC
if lib.bcc_resolve_symname(
module.encode(),
symname.encode(),
0x0,
0,
ct.byref(sym_op),
ct.byref(sym),
) < 0:
return None
else:
return sym
def set_impl_func_addr(cpu, data, size):
addr = ct.cast(data, ct.POINTER(ct.c_uint64)).contents.value
global impl_func_addr
impl_func_addr = addr
def set_resolv_func_addr(cpu, data, size):
addr = ct.cast(data, ct.POINTER(ct.c_uint64)).contents.value
global resolv_func_addr
resolv_func_addr = addr
def find_impl_func_offset(ifunc_symbol):
b = BPF(text=SUBMIT_FUNC_ADDR_BPF_TEXT)
b.attach_uprobe(name=NAME, sym=SYMBOL, fn_name=b'submit_resolv_func_addr')
b['resolv_func_addr'].open_perf_buffer(set_resolv_func_addr)
b.attach_uretprobe(name=NAME, sym=SYMBOL, fn_name=b"submit_impl_func_addr")
b['impl_func_addr'].open_perf_buffer(set_impl_func_addr)
print('wait for the first {} call'.format(SYMBOL))
while True:
try:
if resolv_func_addr and impl_func_addr:
b.detach_uprobe(name=NAME, sym=SYMBOL)
b.detach_uretprobe(name=NAME, sym=SYMBOL)
b.cleanup()
break
b.perf_buffer_poll()
except KeyboardInterrupt:
exit()
print('IFUNC resolution of {} is performed'.format(SYMBOL))
print('resolver function address: {:#x}'.format(resolv_func_addr))
print('resolver function offset: {:#x}'.format(ifunc_symbol.offset))
print('function implementation address: {:#x}'.format(impl_func_addr))
impl_func_offset = impl_func_addr - resolv_func_addr + ifunc_symbol.offset
print('function implementation offset: {:#x}'.format(impl_func_offset))
return impl_func_offset
def main():
ifunc_symbol = get_indirect_function_sym(NAME, SYMBOL)
if not ifunc_symbol:
sys.stderr.write('{} is not an indirect function. abort!\n'.format(SYMBOL))
exit(1)
impl_func_offset = find_impl_func_offset(ifunc_symbol)
b = BPF(text=HIST_BPF_TEXT)
b.attach_uretprobe(name=ct.cast(ifunc_symbol.module, ct.c_char_p).value,
addr=impl_func_offset,
fn_name=b'count')
dist = b['dist']
try:
while True:
time.sleep(1)
print('%-8s\n' % time.strftime('%H:%M:%S'), end='')
dist.print_log2_hist(SYMBOL + ' return:')
dist.clear()
except KeyboardInterrupt:
pass
resolv_func_addr = 0
impl_func_addr = 0
main()
| Name | Type | Size | Permission | Actions |
|---|---|---|---|---|
| CMakeLists.txt | File | 276 B | 0644 |
|
| biolatpcts.py | File | 3.23 KB | 0755 |
|
| biolatpcts_example.txt | File | 650 B | 0644 |
|
| bitehist.py | File | 1.36 KB | 0755 |
|
| bitehist_example.txt | File | 1.18 KB | 0644 |
|
| dddos.py | File | 3.73 KB | 0755 |
|
| dddos_example.txt | File | 2.06 KB | 0644 |
|
| disksnoop.py | File | 1.9 KB | 0755 |
|
| disksnoop_example.txt | File | 1.55 KB | 0644 |
|
| hello_fields.py | File | 679 B | 0755 |
|
| hello_perf_output.py | File | 1.24 KB | 0755 |
|
| hello_perf_output_using_ns.py | File | 1.8 KB | 0755 |
|
| kvm_hypercall.py | File | 1.48 KB | 0755 |
|
| kvm_hypercall.txt | File | 1.74 KB | 0644 |
|
| mallocstacks.py | File | 1.9 KB | 0755 |
|
| mysqld_query.py | File | 1.66 KB | 0755 |
|
| mysqld_query_example.txt | File | 499 B | 0644 |
|
| nflatency.py | File | 6.07 KB | 0755 |
|
| nodejs_http_server.py | File | 1.34 KB | 0755 |
|
| nodejs_http_server_example.txt | File | 276 B | 0644 |
|
| stack_buildid_example.py | File | 3.03 KB | 0755 |
|
| stacksnoop.py | File | 3.18 KB | 0755 |
|
| stacksnoop_example.txt | File | 2.8 KB | 0644 |
|
| strlen_count.py | File | 1.3 KB | 0755 |
|
| strlen_hist.py | File | 1.81 KB | 0755 |
|
| strlen_hist_ifunc.py | File | 3.71 KB | 0755 |
|
| strlen_snoop.py | File | 1.35 KB | 0755 |
|
| sync_timing.py | File | 1.36 KB | 0755 |
|
| task_switch.c | File | 499 B | 0644 |
|
| task_switch.py | File | 486 B | 0755 |
|
| tcpv4connect.py | File | 2.36 KB | 0755 |
|
| tcpv4connect_example.txt | File | 1.04 KB | 0644 |
|
| trace_fields.py | File | 589 B | 0755 |
|
| trace_perf_output.py | File | 1.56 KB | 0755 |
|
| undump.py | File | 3.52 KB | 0755 |
|
| undump_example.txt | File | 886 B | 0644 |
|
| urandomread-explicit.py | File | 1.48 KB | 0755 |
|
| urandomread.py | File | 1.01 KB | 0755 |
|
| urandomread_example.txt | File | 675 B | 0644 |
|
| vfsreadlat.c | File | 896 B | 0644 |
|
| vfsreadlat.py | File | 1.3 KB | 0755 |
|
| vfsreadlat_example.txt | File | 3.53 KB | 0644 |
|