4 ms·
And for earlier kernel versions, there is an STAP patch: 1) On the host, save the following in a file with the ".stp" extension: probe kernel.function("me
by aexaey 10y ago
And for earlier kernel versions, there is an STAP patch:
1) On the host, save the following in a file with the ".stp" extension:
probe kernel.function("mem_write").call ? {
$count = 0
}
probe syscall.ptrace { // includes compat ptrace as well
$request = 0xfff
}
2) Install the "systemtap" package and any required dependencies. Refer
to the "2. Using SystemTap" chapter in the Red Hat Enterprise Linux
"SystemTap Beginners Guide" document, available from docs.redhat.com,
for information on installing the required -debuginfo packages.
3) Run the "stap -g [filename-from-step-1].stp" command as root.
From https://bugzilla.redhat.com/show_bug.cgi?id=1384344#c13 https://bugzilla.redhat.com/show_bug.cgi?id=1384344#c13
- geofft 10y agoDoesn't this break Upstart (which uses ptrace for service activation), meaning you really don't want to use it on RHEL 6 or Ubuntu 14.04?
- h1d 10y agoAbove link says, it would not work on rhel 5 and 6. Doesn't mention about 7 though.
- lima 10y agoNope, this only helps against one particular exploit which happens to use ptrace and /proc/self/mem.