Ejemplo n.º 1
0
    def __init__(self, ctx):
        fe.log('in memdump constructor')
        fe.set_name('memdump')

        fe.log('getting memsize')
        self.memsize = fe.get_memsize()
        fe.log(f'memsize: {self.memsize}')

        self.offset = 0
        self.ttl = 100
        #self.bound = fe.MAX_FIELD_SIZE - 1024
        #self.bound = 8096
        self.bound = 2**22
        self.did = -1

        fe.event_register({'event_type': fe.BE, 'callback': self.be_callback})
        fe.event_register({
            'event_type': fe.TIMER,
            'time_value': 2.0,
            'callback': self.timer_callback
        })

        self.ticks = 0
        self.one_way = False
        self.two_way = False

        self.zco = zlib.compressobj()

        fe.log('leaving memdump constructor')
Ejemplo n.º 2
0
    def __init__(self, ctx):
        fe.log("in pslist constructor")
        fe.set_name("pslist")

        self.lookups = {
            "name_offset": fe.lookup_structure("task_struct", "comm"),
            "pid_offset": fe.lookup_structure("task_struct", "pid"),
            "tasks_offset": fe.lookup_structure("task_struct", "tasks"),
            "init_task": fe.lookup_symbol("init_task"),
        }

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)

        e = {
            "event_type": fe.TIMER,
            "time_value": 0.1,  # seconds
            "callback": self.timer_callback,
        }
        fe.event_register(e)

        self.pslist = {}
        self.log = []
        self.calls = []
        self.msgs = []
        self.procs = []

        fe.log("leaving pslist constructor")
Ejemplo n.º 3
0
    def __init__(self, ctx):
        fe.log("in Example constructor")
        fe.set_name("example")
        self.cr3_ctr = 0
        self.cr3_event = None
        self.pslist = {}

        self.lookups = {
            "name_offset": fe.lookup_structure("task_struct", "comm"),
            "pid_offset": fe.lookup_structure("task_struct", "pid"),
            "tasks_offset": fe.lookup_structure("task_struct", "tasks"),
            "init_task": fe.lookup_symbol("init_task"),
        }

        fe.events_start()
        e = {
            "event_type": fe.REG,
            "reg_type": fe.CR3,
            "sync": fe.ASYNC,
            "callback": self.cr3_callback,
        }
        self.cr3_event = fe.event_register(e)
        fe.log("registered CR3 event: {eid}".format(eid=self.cr3_event))

        e = {
            "event_type": fe.TIMER,
            "time_value": 10.0,  # seconds
            "callback": self.timer_callback,
        }
        fe.event_register(e)

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)

        fe.log("leaving Example constructor")
Ejemplo n.º 4
0
    def __init__(self, ctx):
        fe.log("in memdump constructor")
        fe.set_name("memdump")

        fe.log("getting memsize")
        self.memsize = fe.get_memsize()
        fe.log(f"memsize: {self.memsize}")

        self.offset = 0
        self.ttl = 100
        # self.bound = fe.MAX_FIELD_SIZE - 1024
        # self.bound = 8096
        self.bound = 2 ** 22
        self.did = -1

        fe.event_register({"event_type": fe.BE, "callback": self.be_callback})
        fe.event_register(
            {"event_type": fe.TIMER, "time_value": 2.0, "callback": self.timer_callback}
        )

        self.ticks = 0
        self.one_way = False
        self.two_way = False

        self.zco = zlib.compressobj()

        fe.log("leaving memdump constructor")
    def __init__(self, ctx):
        fe.log("in vmi_runtime_testing constructor")
        fe.event_register(
            {"event_type": fe.TIMER, "time_value": 1.0, "callback": self.timer_callback}
        )

        self.lookups = {
            "name_offset": fe.get_offset("linux_name"),
            "pid_offset": fe.get_offset("linux_pid"),
            "tasks_offset": fe.get_offset("linux_tasks"),
            "init_task": fe.translate_ksym2v("init_task"),
        }

        self.pslist = {}
Ejemplo n.º 6
0
    def __init__(self, ctx):
        fe.log("in arav constructor")
        fe.set_name("arav")

        self.l = {
            "name_offset": fe.lookup_structure("task_struct", "comm"),
            "pid_offset": fe.lookup_structure("task_struct", "pid"),
            "tasks_offset": fe.lookup_structure("task_struct", "tasks"),
            "mm_offset": fe.lookup_structure("task_struct", "mm"),
            "pgd_offset": fe.lookup_structure("mm_struct", "pgd"),
            "vm_file_offset": fe.lookup_structure("vm_area_struct", "vm_file"),
            "vm_file_path_offset": fe.lookup_structure("file", "f_path"),
            "path_dentry_offset": fe.lookup_structure("path", "dentry"),
            "dentry_d_name_offset": fe.lookup_structure("dentry", "d_name"),
            "dentry_d_parent_offset":
            fe.lookup_structure("dentry", "d_parent"),
            "d_name_str_offset": fe.lookup_structure("qstr", "name"),
            "commit_creds": fe.lookup_symbol("commit_creds"),
        }

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)

        e = {
            "event_type": fe.TIMER,
            "time_value": 2.0,
            "callback": self.timer_callback
        }
        fe.event_register(e)

        self.state = INIT
        self.pslist = {}
        self.events = {}
        self.target_proc = {}
        self.last = 0.0
        self.tick = 0
        self.symbol_string = ""
        self.symbols = {}
        self.fmts = []
        self.users = []

        self.load_symbols()
        self.parse_symbols()
        fe.events_start()

        fe.log("leaving arav constructor")
Ejemplo n.º 7
0
    def __init__(self, ctx):
        fe.log("in syscalls constructor")
        fe.set_name("syscalls")

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)

        e = {
            "event_type": fe.TIMER,
            "time_value": 2.0,  # seconds
            "callback": self.timer_callback,
        }
        fe.event_register(e)
        self.ticks = 0
        self.calls = 0

        fe.log("leaving syscalls constructor")
Ejemplo n.º 8
0
    def __init__(self, ctx):
        fe.set_name("modlist")
        self.pslist = {}

        self.lookups = {
            "name_offset": fe.lookup_structure("task_struct", "comm"),
            "pid_offset": fe.lookup_structure("task_struct", "pid"),
            "tasks_offset": fe.lookup_structure("task_struct", "tasks"),
            "modules": fe.lookup_symbol("modules"),
        }

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)

        self.do_modlist()

        fe.exit()
Ejemplo n.º 9
0
    def __init__(self, ctx):
        fe.log("in pslist_dk constructor")
        fe.set_name("pslist_dk")

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)
        self.pslist = {}
        self.log = []
        self.calls = []
        self.msgs = []
        self.procs = []

        timeit_on = False
        cprof = False

        if cprof:
            self.do_dk_pslist(pause=True)  # zmq warmup
            cProfile.runctx(
                "self.do_dk_pslist()",
                globals(),
                locals(),
                filename="/home/micah/femain.dk.profile",
            )

        if timeit_on:
            self.do_dk_pslist(pause=True)  # zmq warmup
            fe.pause_vm()
            t = timeit.Timer(lambda: self.do_dk_pslist()).timeit(number=100)
            t = t / 100.0
            fe.resume_vm()
            fe.log("timeit pslist in {sec:.6f} seconds".format(sec=t))
        else:
            self.pslist = {}
            gc.disable()
            self.do_dk_pslist(pause=True)
            gc.enable()
            fe.log(self.pslist)

        for l in self.log:
            fe.log(l)
        fe.log("calls: %s" % self.calls)
        fe.log("procs: %s" % self.procs)
        fe.log("msgs: %s" % self.msgs)
        fe.log("leaving pslist_dk constructor")
        fe.exit()
Ejemplo n.º 10
0
    def __init__(self, ctx):
        fe.log("in rekall constructor")
        fe.set_name("rekall")

        e = {"event_type": fe.BE, "callback": self.be_callback}
        fe.event_register(e)

        e = {
            "event_type": fe.TIMER,
            "time_value": 2.0,  # seconds
            "callback": self.timer_callback,
        }
        fe.event_register(e)
        self.ticks = 0
        self.one_way = False
        self.two_way = False

        fe.log("leaving rekall constructor")
Ejemplo n.º 11
0
    def be_callback(self, ctx):
        fe.log(f'BE CALLBACK: {ctx}')
        self.two_way = True

        # msg format: {'cmd': 'foo', 'data': 'bar', 'ix': dump_order, 'hash': hash}
        # ALL ASYNC
        # FE: hi, waiting, memdump_running, memdump_done, error
        # BE: memdump_cmd: go, stop
        msg = json.loads(ctx.message)
        fe.log(f'JSON message: {msg}')

        if msg['cmd'] == 'memdump_cmd' and msg['data'] == 'go':
            if self.did >= 0:
                fe.log(f'error, dump already in procress (eid={self.did})')
                fe.notify(
                    json.dumps({
                        'cmd': 'error',
                        'data': 'memdump already running'
                    }))
            else:
                fe.log(f'running memdump')
                fe.notify(
                    json.dumps({
                        'cmd': 'memdump_running',
                        'data': time.time()
                    }))
                self.did = fe.event_register({
                    'event_type': fe.TIMER,
                    'time_value': 0.0,
                    'callback': self.memdump_callback
                })
                fe.log(f'registered new event {self.did}')

        elif msg['cmd'] == 'memdump_cmd' and msg['data'] == 'stop':
            if self.did >= 0:
                fe.event_clear(self.did)
                self.did = -1
                fe.log(f'canceled dump')
            else:
                fe.log(f'error, no dump in procress (eid={self.did})')

        elif msg['cmd'] == 'memdump_cmd' and msg['data'] == 'exit':
            fe.log('was commanded to exit...')
            fe.exit()

        fe.log('BE CALLBACK done')
Ejemplo n.º 12
0
    def be_callback(self, ctx):
        fe.log(f"BE CALLBACK: {ctx}")
        self.two_way = True

        # msg format: {'cmd': 'foo', 'data': 'bar', 'ix': dump_order, 'hash': hash}
        # ALL ASYNC
        # FE: hi, waiting, memdump_running, memdump_done, error
        # BE: memdump_cmd: go, stop
        msg = json.loads(ctx.message)
        fe.log(f"JSON message: {msg}")

        if msg["cmd"] == "memdump_cmd" and msg["data"] == "go":
            if self.did >= 0:
                fe.log(f"error, dump already in procress (eid={self.did})")
                fe.notify(
                    json.dumps({"cmd": "error", "data": "memdump already running"})
                )
            else:
                fe.log(f"running memdump")
                fe.notify(json.dumps({"cmd": "memdump_running", "data": time.time()}))
                self.did = fe.event_register(
                    {
                        "event_type": fe.TIMER,
                        "time_value": 0.0,
                        "callback": self.memdump_callback,
                    }
                )
                fe.log(f"registered new event {self.did}")

        elif msg["cmd"] == "memdump_cmd" and msg["data"] == "stop":
            if self.did >= 0:
                fe.event_clear(self.did)
                self.did = -1
                fe.log(f"canceled dump")
            else:
                fe.log(f"error, no dump in procress (eid={self.did})")

        elif msg["cmd"] == "memdump_cmd" and msg["data"] == "exit":
            fe.log("was commanded to exit...")
            fe.exit()

        fe.log("BE CALLBACK done")
Ejemplo n.º 13
0
    def timer_callback(self, ctx):

        now = time.time()
        if self.last + 10 < now:
            fe.log("refreshing pslist")
            # pslist[proc.pid] = {'name': proc.name, 'process_block_ptr': proc.process_block_ptr}
            self.pslist = fe.process_list()
            # fe.log(f'#procs: {len(self.pslist)}')

            for pid, proc in self.pslist.items():
                if proc["name"] == "sshd":
                    fe.log(f"found sshd: {pid} {proc}")
                    if not self.target_proc:
                        self.target_proc["pid"] = pid
                        for k, v in proc.items():
                            self.target_proc[k] = v
                        for k, v in self.enumerate_proc(
                                proc["process_block_ptr"]).items():
                            self.target_proc[k] = v
                        fe.log(f"loading target_proc {self.target_proc}")

        if self.state == INIT:
            fe.log(f"installing breakpoint on commit_creds")
            address = self.l["commit_creds"]
            e = {
                "event_type": fe.INT,
                "sync": fe.SYNC,
                "bp_pid": fe.KERNEL,
                "bp_addr": address,
                "callback": self.commit_creds_callback,
            }
            try:
                eid = fe.event_register(e)
            except Exception:
                fe.log(f"could not inject at commit_creds")
                errors.append("commit_creds")
            else:
                self.events[eid] = address
                fe.log(f"event is {eid}")
                self.symbols[address] = {
                    "address": address,
                    "t": "T",
                    "func_name": "commit_creds",
                }
            self.state = INJECTED

        if False and self.state == INIT:
            fe.log(f"injecting against {self.target_proc}")
            self.state = INJECTED
            errors = []
            for address, info in self.symbols.items():
                if "do_log" != info["func_name"]:
                    fe.log(f"skipping {info['func_name']}")
                    continue
                bp_addr = self.target_proc["text_start"] + address
                pid = self.target_proc["pid"]
                fe.log(f"installing bp at {bp_addr:x} for {address}:{info}")
                e = {
                    "event_type": fe.INT,
                    "sync": fe.SYNC,
                    "bp_pid": pid,
                    "bp_addr": bp_addr,
                    "callback": self.int_callback,
                }
                try:
                    eid = fe.event_register(e)
                except Exception:
                    fe.log(f"could not inject at {info['func_name']}")
                    errors.append(info["func_name"])
                else:
                    self.events[eid] = address
                    fe.log(f"event is {eid}")
            fe.log(f"done, errors: {errors}")

        if self.tick == 15:
            fe.log("shutting down")
            fe.events_stop()
            for eid, address in self.events.items():
                fe.log(f"clearing {eid}: {self.symbols[address]['func_name']}")
                fe.event_clear(eid)
            self.events = {}
            print(f"formats: {self.fmts}")
            print(f"users: {self.users}")

            fe.exit()

        fe.log(f"tick {self.tick}")
        self.tick += 1
        self.last = now