-
Notifications
You must be signed in to change notification settings - Fork 7
/
sasuke_group3.log
executable file
·343 lines (336 loc) · 4.89 KB
/
sasuke_group3.log
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
[Checking the pointers in the system call table...]
read - OK
getdents - OK
getdents64 - OK
recvmsg - OK
open - OK
close - OK
readlink - OK
readlinkat - OK
kill - OK
There are 0 manipulated pointers in the system call table.
[Checking the first bytes of some system calls and other important functions...]
read - OK
getdents - OK
getdents64 - OK
recvmsg - OK
open - OK
close - OK
readlink - OK
readlinkat - OK
kill - OK
packet_rcv - 34431A68 2444C7A0 FFFFFF04 EC83C3FF
packet_rcv_spkt - 3443DA68 2444C7A0 FFFFFF04 8B4CC3FF
tpacket_rcv - 34437468 2444C7A0 FFFFFF04 EC83C3FF
There are 3 manipulated functions.
[Checking currently running processes...]
[00001] init
[00002] kthreadd
[00003] ksoftirqd/0
[00005] kworker/0:0H
[00007] rcu_sched
[00008] rcu_bh
[00009] migration/0
[00010] watchdog/0
[00011] khelper
[00012] kdevtmpfs
[00013] netns
[00014] khungtaskd
[00015] writeback
[00016] ksmd
[00017] crypto
[00018] kintegrityd
[00019] bioset
[00020] kblockd
[00022] kswapd0
[00023] fsnotify_mark
[00028] ipv6_addrconf
[00029] deferwq
[00098] ata_sff
[00116] scsi_eh_0
[00117] scsi_tmf_0
[00118] scsi_eh_1
[00119] scsi_tmf_1
[00120] scsi_eh_2
[00121] kworker/u2:2
[00122] scsi_tmf_2
[00124] scsi_eh_3
[00125] scsi_tmf_3
[00134] kworker/0:2
[00142] kworker/0:1H
[00158] jbd2/sda1-8
[00159] ext4-rsv-conver
[00302] udevd
[00433] kpsmoused
[00446] khubd
[01610] rpcbind
[01641] rpc.statd
[01646] rpciod
[01648] nfsiod
[01655] rpc.idmapd
[01990] dhclient
[02011] rsyslogd
[02047] acpid
[02074] atd
[02115] cron
[02130] dbus-daemon
[02427] exim4
[02446] sshd
[02473] getty
[02474] getty
[02475] getty
[02476] getty
[02477] getty
[02774] kworker/u2:0
[03096] kworker/0:1
[03181] kworker/0:0
[03200] login
[03201] zsh
[03222] udevd
[03223] udevd
[03243] insmod
Number of processes: 65 (64 if you account for the 'insmod').
Verify by running the command 'ps ax --no-headers | wc -l'.
[Checking netfilter hooks...]
[(null)] 0xFFFFFFFFA0345060
Number of current netfilter hooks: 1.
[Checking loaded kernel modules in /sys/modules...]
/module/ac
/module/sg
/module/tcp_diag
/module/nfs
/module/hid
/module/vt
/module/8250
/module/acpi
/module/tcp_cubic
/module/snd
/module/ext4
/module/jbd2
/module/loop
/module/i2c_core
/module/nfsd
/module/serio_raw
/module/cpuidle
/module/ipv6
/module/ahci
/module/usb_common
/module/crct10dif_common
/module/nfnetlink
/module/e1000
/module/dns_resolver
/module/cdrom
/module/i8042
/module/auth_rpcgss
/module/lockd
/module/evdev
/module/crc16
/module/block
/module/rcutree
/module/snd_ac97_codec
/module/i2c_piix4
/module/snd_intel8x0
/module/snd_timer
/module/libahci
/module/mbcache
/module/firmware_class
/module/snd_pcm
/module/spurious
/module/scsi_mod
/module/button
/module/nfnetlink_log
/module/ohci_pci
/module/ohci_hcd
/module/apparmor
/module/fscache
/module/netpoll
/module/nfs_acl
/module/joydev
/module/soundcore
/module/ata_generic
/module/ehci_hcd
/module/workqueue
/module/mousedev
/module/hid_generic
/module/libata
/module/pcspkr
/module/pciehp
/module/acpiphp
/module/sasuke
/module/pstore
/module/sr_mod
/module/sunrpc
/module/oid_registry
/module/sd_mod
/module/usbcore
/module/battery
/module/8250_core
/module/crc_t10dif
/module/usbhid
/module/printk
/module/parport
/module/ac97_bus
/module/parport_pc
/module/microcode
/module/ata_piix
/module/pcie_aspm
/module/inet_diag
/module/intel_idle
/module/psmouse
/module/pci_hotplug
/module/keyboard
/module/rcupdate
/module/xz_dec
/module/kernel
/module/sysrq
Number of loaded kernel modules in /sys/modules: 88
[Checking loaded kernel modules in lsmod...]
sasuke
tcp_diag
inet_diag
nfnetlink_log
nfnetlink
nfsd
auth_rpcgss
oid_registry
nfs_acl
nfs
lockd
fscache
sunrpc
loop
joydev
hid_generic
usbhid
hid
snd_intel8x0
snd_ac97_codec
snd_pcm
snd_timer
ohci_pci
ohci_hcd
ehci_hcd
usbcore
snd
parport_pc
parport
usb_common
evdev
microcode
psmouse
serio_raw
pcspkr
i2c_piix4
soundcore
i2c_core
ac97_bus
battery
ac
button
ext4
crc16
jbd2
mbcache
sg
sd_mod
sr_mod
crc_t10dif
cdrom
crct10dif_common
ata_generic
ahci
libahci
ata_piix
libata
scsi_mod
e1000
Number of loaded kernel modules: 59
[Checking loaded kernel modules in kobjects...]
xz_dec
tcp_cubic
kernel
workqueue
printk
spurious
rcupdate
rcutree
pstore
apparmor
block
pcie_aspm
pci_hotplug
pciehp
acpiphp
intel_idle
acpi
sysrq
keyboard
vt
8250_core
8250
firmware_class
i8042
mousedev
cpuidle
netpoll
ipv6
dns_resolver
e1000
scsi_mod
libata
ata_piix
libahci
ahci
ata_generic
crct10dif_common
cdrom
crc_t10dif
sr_mod
sd_mod
sg
mbcache
jbd2
crc16
ext4
button
ac
battery
ac97_bus
i2c_core
soundcore
i2c_piix4
pcspkr
serio_raw
psmouse
microcode
evdev
usb_common
parport
parport_pc
snd
usbcore
ehci_hcd
ohci_hcd
ohci_pci
snd_timer
snd_pcm
snd_ac97_codec
snd_intel8x0
hid
usbhid
hid_generic
joydev
loop
sunrpc
fscache
lockd
nfs
nfs_acl
oid_registry
auth_rpcgss
nfsd
nfnetlink
nfnetlink_log
inet_diag
tcp_diag
Number of loaded kernel modules: 88