3 ms·
But that would only be possible from the same process space, right? So only applicable for plugins etc.? What I'd like to see is hotpatching the function for a
by csl 11y ago
But that would only be possible from the same process space, right? So only applicable for plugins etc.?
What I'd like to see is hotpatching the function for another process, but I guess that's very hard to do with ASLR. Probably doable with some tricks, though.
Edit: Come to think of it, gdb is able to attach to a running process w/o debug symbols and find function addresses. So in other words, I just need to dig into and grok the gdb source.
- chatmasta 11y agoIf you are able to recompile the program, you can disable ASLR. For example on iOS it just requires a change to the MACH-O header of the binary. [0] But I doubt you could disable ASLR of a running process, for somewhat obvious reasons... [0] https://github.com/peterfillmore/removePIE https://github.com/peterfillmore/removePIE
- dreamlayers 11y agoYou can similarly disable ASLR via the header in Windows, though there are ways to override that. ASLR shouldn't be a big problem though. Only the base address of code in each file (executable or library) is changed, and you can easily find it. Functions within one file are not shuffled around. ASLR only exists to stop you from hard-coding function addresses, to make exploits harder.
- dreamlayers 11y agoThe program being modified doesn't need some feature for loading your code as a plugin. You can instead use https://en.wikipedia.org/wiki/DLL_injection https://en.wikipedia.org/wiki/DLL_injection