📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Library Injection.

Topic created on: April 4, 2011 12:45 CDT by wilkux .

Hi
I study computer science. Currently I'm writting my graduate work which I have to do in order to finish my studies. The main part of my work is to inject a library into some running process and create a new thread which will e.g. protect stack. As you can see it is quite interesting, but I have a problem with library injection. I found some awesome article on which I based my work: http://nologin.org/Downloads/Papers/remote-library-injection.pdf . Unfortunately my project doesn't work properly. It crashes in the middle of _dl_open function with the offset 0x163. Could you please have a look on my project: www.purecode.pl/dllInjection.zip and tell me what's wrong with it? Being honest I'm quite stressed because the time is running and I don't really know what's wrong. I work on Arch Linux with ld-2.13.so library.

Thanks in advance,
wilkux

  badfood   April 18, 2011 11:08.07 CDT
I'm new here and I am trying to understand the internals of futo. I see that futo hides itself by deleting the entry from pspcidtable and setting it to null. My question is, how then, does the kernel locate it during scheduling?

Thanks.

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit