From dadf81831c743a458d3b453248d9431f93c0c79e Mon Sep 17 00:00:00 2001 From: alemi Date: Tue, 28 Mar 2023 21:06:28 +0200 Subject: [PATCH] feat: added hooks for connect and socket in so --- Cargo.toml | 1 + src/lib.rs | 34 ++++++++++++++++++++++++++++++++++ 2 files changed, 35 insertions(+) diff --git a/Cargo.toml b/Cargo.toml index 63c1c1d..d977c9d 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -17,6 +17,7 @@ path = "src/needle/main.rs" [dependencies] clap = { version = "4.1.13", features = ["derive"] } ctor = "0.1.26" +retour = "0.1" # plain detour doesn't work on latest nightly? idk elf = "0.7.2" nix = "0.26.2" proc-maps = "0.3.0" diff --git a/src/lib.rs b/src/lib.rs index 2c06f4b..d5180fd 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -1,4 +1,38 @@ +use std::{error::Error, ffi::c_int}; + +use nix::libc::{socklen_t, sockaddr}; +use retour::static_detour; + +static_detour! { + static SOCKET_HOOK : unsafe extern "C" fn(i32, i32, i32) -> i32; + static CONNECT_HOOK : unsafe extern "C" fn(c_int, *const sockaddr, socklen_t) -> c_int; +} + +fn add_hooks() -> Result<(), Box> { + unsafe { + SOCKET_HOOK.initialize(nix::libc::socket, |dom, tp, proto| { + eprintln!("caught socket({}, {}, {}) call", dom, tp, proto); + SOCKET_HOOK.call(dom, tp, proto) + })?; + SOCKET_HOOK.enable()?; + + CONNECT_HOOK.initialize(nix::libc::connect, |fd, info, len| { + eprintln!("caught connect({}, ??, {}) call", fd, len); + CONNECT_HOOK.call(fd, info, len) + })?; + CONNECT_HOOK.enable()?; + } + + Ok(()) +} + + + #[ctor::ctor] fn constructor() { println!("Infected!"); + + if let Err(e) = add_hooks() { + eprintln!("[!] Could not add hooks : {}", e); + } }