-
Notifications
You must be signed in to change notification settings - Fork 7
/
Copy pathsasuke_group5.log
executable file
·340 lines (333 loc) · 4.84 KB
/
sasuke_group5.log
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
[Checking the pointers in the system call table...]
read - OK
getdents - OK
getdents64 - OK
recvmsg - OK
open - OK
close - OK
readlink - OK
readlinkat - OK
kill - OK
There are 0 manipulated pointers in the system call table.
[Checking the first bytes of some system calls and other important functions...]
read - B835B848 FFFFA02D E0FFFFFF 61E80824
getdents - OK
getdents64 - OK
recvmsg - C41EB848 FFFFA02D E0FFFFFF FFFFFFEA
open - OK
close - OK
readlink - OK
readlinkat - OK
kill - OK
packet_rcv - OK
packet_rcv_spkt - BD0FB848 FFFFA02D E0FFFFFF 8B4C7D47
tpacket_rcv - BC5CB848 FFFFA02D E0FFFFFF EC8348FB
There are 4 manipulated functions.
[Checking currently running processes...]
[00001] init
[00002] kthreadd
[00003] ksoftirqd/0
[00005] kworker/0:0H
[00006] kworker/u2:0
[00007] rcu_sched
[00008] rcu_bh
[00009] migration/0
[00010] watchdog/0
[00011] khelper
[00012] kdevtmpfs
[00013] netns
[00014] khungtaskd
[00015] writeback
[00016] ksmd
[00017] crypto
[00018] kintegrityd
[00019] bioset
[00020] kblockd
[00022] kswapd0
[00023] fsnotify_mark
[00028] ipv6_addrconf
[00029] deferwq
[00138] ata_sff
[00163] scsi_eh_0
[00164] scsi_tmf_0
[00165] scsi_eh_1
[00166] kworker/u2:2
[00167] scsi_tmf_1
[00168] scsi_eh_2
[00169] scsi_tmf_2
[00178] kworker/0:2
[00182] kworker/0:1H
[00204] jbd2/sda1-8
[00205] ext4-rsv-conver
[00348] udevd
[00504] kpsmoused
[00508] khubd
[01655] rpcbind
[01686] rpc.statd
[01691] rpciod
[01698] nfsiod
[01717] rpc.idmapd
[01747] dhclient
[02030] rsyslogd
[02067] acpid
[02092] atd
[02141] cron
[02410] sshd
[02437] exim4
[02464] login
[02465] getty
[02466] getty
[02467] getty
[02468] getty
[02469] getty
[02470] bash
[02515] bash
[02529] nc
[02648] kworker/0:1
[02670] udevd
[02671] udevd
[03255] insmod
Number of processes: 63 (62 if you account for the 'insmod').
Verify by running the command 'ps ax --no-headers | wc -l'.
[Checking netfilter hooks...]
Number of current netfilter hooks: 0.
[Checking loaded kernel modules in /sys/modules...]
/module/ac
/module/sg
/module/tcp_diag
/module/nfs
/module/hid
/module/vt
/module/8250
/module/acpi
/module/tcp_cubic
/module/snd
/module/ext4
/module/jbd2
/module/loop
/module/i2c_core
/module/nfsd
/module/serio_raw
/module/cpuidle
/module/ipv6
/module/ahci
/module/usb_common
/module/crct10dif_common
/module/e1000
/module/dns_resolver
/module/cdrom
/module/i8042
/module/auth_rpcgss
/module/lockd
/module/evdev
/module/crc16
/module/snd_ac97_codec
/module/i2c_piix4
/module/snd_intel8x0
/module/snd_timer
/module/libahci
/module/mbcache
/module/firmware_class
/module/sysrq
/module/block
/module/rcutree
/module/snd_pcm
/module/spurious
/module/scsi_mod
/module/button
/module/ohci_hcd
/module/ohci_pci
/module/apparmor
/module/fscache
/module/netpoll
/module/nfs_acl
/module/joydev
/module/soundcore
/module/ata_generic
/module/ehci_hcd
/module/mousedev
/module/hid_generic
/module/libata
/module/pcspkr
/module/pciehp
/module/acpiphp
/module/sasuke
/module/pstore
/module/sr_mod
/module/sunrpc
/module/oid_registry
/module/sd_mod
/module/usbhid
/module/usbcore
/module/battery
/module/8250_core
/module/crc_t10dif
/module/processor
/module/printk
/module/parport
/module/ac97_bus
/module/parport_pc
/module/microcode
/module/ata_piix
/module/pcie_aspm
/module/inet_diag
/module/intel_idle
/module/thermal_sys
/module/psmouse
/module/pci_hotplug
/module/keyboard
/module/rcupdate
/module/xz_dec
/module/kernel
/module/workqueue
Number of loaded kernel modules in /sys/modules: 88
[Checking loaded kernel modules in lsmod...]
sasuke
tcp_diag
inet_diag
nfsd
auth_rpcgss
oid_registry
nfs_acl
nfs
lockd
fscache
sunrpc
loop
joydev
hid_generic
usbhid
hid
snd_intel8x0
snd_ac97_codec
snd_pcm
snd_timer
ohci_pci
ohci_hcd
ehci_hcd
usbcore
snd
processor
thermal_sys
psmouse
i2c_piix4
i2c_core
parport_pc
parport
evdev
usb_common
pcspkr
serio_raw
microcode
button
soundcore
ac97_bus
battery
ac
ext4
crc16
jbd2
mbcache
sg
sd_mod
sr_mod
crc_t10dif
crct10dif_common
cdrom
ata_generic
ata_piix
ahci
libahci
e1000
libata
scsi_mod
Number of loaded kernel modules: 59
[Checking loaded kernel modules in kobjects...]
xz_dec
tcp_cubic
kernel
workqueue
printk
spurious
rcupdate
rcutree
pstore
apparmor
block
pcie_aspm
pci_hotplug
pciehp
acpiphp
intel_idle
acpi
sysrq
keyboard
vt
8250_core
8250
firmware_class
i8042
mousedev
cpuidle
netpoll
ipv6
dns_resolver
scsi_mod
libata
e1000
libahci
ahci
ata_piix
ata_generic
cdrom
crct10dif_common
crc_t10dif
sr_mod
sd_mod
sg
mbcache
jbd2
crc16
ext4
ac
battery
ac97_bus
soundcore
button
microcode
serio_raw
pcspkr
usb_common
evdev
parport
parport_pc
i2c_core
i2c_piix4
psmouse
thermal_sys
processor
snd
usbcore
ehci_hcd
ohci_hcd
ohci_pci
snd_timer
snd_pcm
snd_ac97_codec
snd_intel8x0
hid
usbhid
hid_generic
joydev
loop
sunrpc
fscache
lockd
nfs
nfs_acl
oid_registry
auth_rpcgss
nfsd
inet_diag
tcp_diag
Number of loaded kernel modules: 88