You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CTF破解求助:如何通过GDB向程序传入PID以获取Shell

Passing a PID to Your Program via GDB's run Command for CTF Shell Access

Hey there! Let's break down how to get that PID passed to your program so you can grab that shell in your CTF challenge. I've got a few practical, easy-to-use methods tailored for GDB (and PEDA, since you're using that) that should work perfectly.

Method 1: Directly Pass the PID as a Command-Line Argument

If your program expects the PID as a command-line parameter, you can pass it right after the run command. Here's how:

  1. First, get the PID you need (if it's the PID of the process you're debugging, use GDB's built-in getpid command):
    (gdb) getpid
    $1 = 12345  # This is your target PID
    
  2. Then pass it directly to run:
    (gdb) run $1
    
    Or if you already know the PID manually, just plug it in:
    (gdb) run 12345
    

Method 2: Pre-Set Arguments with set args

If you want to avoid typing the PID every time you restart the program, use set args to define the parameters first, then run the program:

  1. Grab the PID (again, using getpid if it's the debugged process's PID):
    (gdb) getpid
    $1 = 12345
    
  2. Set the argument:
    (gdb) set args $1
    
  3. Start the program:
    (gdb) run
    
    This will reuse the same PID argument every time you run run until you change it with another set args command.

Method 3: Pass PID via Standard Input (If That's How the Program Reads It)

If your program reads the PID from standard input instead of command-line arguments, you have a couple options:

  • Pass it inline when starting the program:
    (gdb) run <<< $(getpid)
    
  • Manually input it after starting the program:
    (gdb) getpid
    $1 = 12345
    (gdb) run
    # When the program prompts for input, type 12345 and hit enter
    
    With PEDA, you can also use p getpid() to fetch the PID and reference that value later:
    (gdb) p getpid()
    $1 = 12345
    (gdb) run
    # Input $1's value when prompted
    

Quick Note for Edge Cases

If your program expects the PID from an environment variable instead of args/stdin, use GDB's set environment command:

(gdb) getpid
$1 = 12345
(gdb) set environment TARGET_PID=$1
(gdb) run

Just double-check your program's source to confirm how it's expecting the PID (command-line arg, stdin, env var) and pick the method that matches—you'll be in that shell in no time!

内容的提问来源于stack exchange,提问作者mahmoudadel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:59:43