inject_linux_amd64.go 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870
  1. package inject
  2. /*
  3. #cgo CFLAGS: -I include
  4. #cgo amd64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_amd64.a
  5. #cgo arm64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_arm64.a
  6. #include "hotpatch.h"
  7. #include <stdlib.h>
  8. */
  9. import "C"
  10. import (
  11. "bufio"
  12. "debug/elf"
  13. "fmt"
  14. "golang.org/x/arch/x86/x86asm"
  15. "log"
  16. "os"
  17. "strings"
  18. "syscall"
  19. "time"
  20. "unsafe"
  21. )
  22. const (
  23. IO_FD_FDID_SYM_OFFSET = 129
  24. NET_SEND_SYM_OFFSET = 518
  25. )
  26. type InstInfo struct {
  27. SymName string
  28. SymSize uint64
  29. SymAddr uint64
  30. PC uint64
  31. Inst x86asm.Inst
  32. OriginInst x86asm.Inst
  33. OriginCode []byte
  34. TargetAddr uint64
  35. OriginTargetAddr uint64
  36. }
  37. type InnerSymbolInfo struct {
  38. IO_fd_fdID InstInfo
  39. NET_Send InstInfo
  40. }
  41. type LibNetInfo struct {
  42. LibName string
  43. LibPath string
  44. FuncSymbol InstInfo
  45. InnerSymbol InnerSymbolInfo
  46. }
  47. type UprobeData struct {
  48. Offset int
  49. Func string
  50. ELFPath string
  51. }
  52. type JvmInjector struct {
  53. Pid int
  54. ReleaseLibNetInfo LibNetInfo
  55. DebugLibNetInfo LibNetInfo
  56. RecodeInfo LibNetInfo
  57. // 原方法首个指令不为jmp | ReleaseLibNetInfo 读取无异常
  58. PreCheck struct {
  59. NeedInjectionCheck bool // 原指令校验 true表示可以继续执行注入
  60. LoadingCheck bool // true 表示加载成功
  61. IoFdCheck bool // fd地址校验
  62. NetSendFuncCheck bool // netsend校验
  63. EbpfCanInjection bool // 满足则注入ebpf
  64. }
  65. AfterCheck struct {
  66. IoFdCheck bool
  67. NetSendFuncCheck bool
  68. }
  69. Uprobe UprobeData
  70. }
  71. func (j *JvmInjector) findReleaseAddressInfoFromMem() error {
  72. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  73. releaseFuncSym := InnerSymbolInfo{}
  74. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  75. if err != nil {
  76. return err
  77. }
  78. pc := uint64(0)
  79. callCount := 0
  80. preContext := InstInfo{}
  81. for pc < uint64(len(code)) {
  82. inst, err := x86asm.Decode(code[pc:], 64)
  83. if err != nil {
  84. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  85. pc++ // Skip this byte and try to decode again
  86. continue
  87. }
  88. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  89. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  90. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  91. currentData := InstInfo{
  92. PC: pc,
  93. SymAddr: funcAbsAddress + pc,
  94. Inst: inst,
  95. //IntelInst: x86asm.IntelSyntax(inst, 0, nil),
  96. }
  97. if pc == 0 && inst.Op == x86asm.JMP {
  98. // 已经被修改过的首指令
  99. j.PreCheck.EbpfCanInjection = true
  100. fmt.Printf("Inst already modified. <%s>\n", x86asm.IntelSyntax(inst, 0, nil))
  101. return nil
  102. }
  103. if pc == 0 {
  104. j.ReleaseLibNetInfo.FuncSymbol.PC = currentData.PC
  105. j.ReleaseLibNetInfo.FuncSymbol.Inst = currentData.Inst
  106. j.ReleaseLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  107. }
  108. if inst.Op == x86asm.MOV {
  109. if dst, okDst := inst.Args[0].(x86asm.Mem); okDst {
  110. if dst.Base == x86asm.RBP {
  111. if src, okSrc := inst.Args[1].(x86asm.Reg); okSrc {
  112. if src == x86asm.R9L {
  113. // debug so
  114. j.PreCheck.EbpfCanInjection = true
  115. return fmt.Errorf("MOV from register %v to memory %v\n", src, dst)
  116. }
  117. }
  118. }
  119. }
  120. //src, okSrc := inst.Args[1].(x86asm.Reg)
  121. //fmt.Println(inst.Args)
  122. //fmt.Printf("Instruction: %+v\n", inst)
  123. //
  124. //fmt.Println(okSrc)
  125. //if okDst && okSrc && dst == x86asm.RBP && src == x86asm.R9L {
  126. // fmt.Println("Instruction is 'mov %r9d, %rbp'")
  127. //}
  128. }
  129. if inst.Op == x86asm.CALL {
  130. //fmt.Printf("Pre instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  131. if callCount == 0 {
  132. releaseFuncSym.IO_fd_fdID = preContext
  133. releaseFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Release)"
  134. preInst := preContext.Inst
  135. fmt.Println(preInst.Op)
  136. fmt.Println((preInst.Args))
  137. // 计算目标地址
  138. if preInst.Op == x86asm.MOV &&
  139. len(preInst.Args) == 4 &&
  140. preInst.Args[0] != nil &&
  141. preInst.Args[0] == x86asm.RDX &&
  142. preInst.Args[1] != nil {
  143. if mem, ok := preInst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  144. relOffset := mem.Disp // 直接从Mem结构体中读取偏移
  145. targetAddress := preContext.SymAddr + uint64(preInst.Len) + uint64(relOffset)
  146. fmt.Printf("Target address: 0x%x\n", targetAddress)
  147. releaseFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  148. } else {
  149. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  150. }
  151. } else {
  152. return fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  153. }
  154. //os.Exit(1)
  155. }
  156. callCount++
  157. if callCount == 4 {
  158. releaseFuncSym.NET_Send = currentData
  159. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  160. relOffset, ok := inst.Args[0].(x86asm.Rel)
  161. if !ok {
  162. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  163. }
  164. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  165. releaseFuncSym.NET_Send.TargetAddr = targetAddress
  166. fmt.Println(releaseFuncSym.NET_Send)
  167. releaseFuncSym.NET_Send.SymName = "<NET_Send>(Release)"
  168. fmt.Printf("Target address: 0x%x\n", targetAddress)
  169. }
  170. }
  171. preContext = InstInfo{
  172. PC: pc,
  173. SymAddr: funcAbsAddress + pc,
  174. Inst: inst,
  175. }
  176. pc += uint64(inst.Len)
  177. }
  178. j.ReleaseLibNetInfo.InnerSymbol = releaseFuncSym
  179. j.ReleaseLibNetInfo.FuncSymbol.OriginCode = code[0:5]
  180. return nil
  181. }
  182. func (j *JvmInjector) findDebugAddressInfoFromMem() (uint64, error) {
  183. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  184. debugFuncSym := InnerSymbolInfo{}
  185. //debugFuncSym.FuncSymbol.SymAddr = funcAbsAddress
  186. //offset := sym.Value
  187. size := j.DebugLibNetInfo.FuncSymbol.SymSize
  188. code, err := j.readMemory(funcAbsAddress, size)
  189. //fmt.Println(code, err)
  190. if err != nil {
  191. return 0, err
  192. }
  193. pc := uint64(0)
  194. preContext := InstInfo{}
  195. for pc < uint64(len(code)) {
  196. inst, err := x86asm.Decode(code[pc:], 64)
  197. if err != nil {
  198. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  199. pc++ // Skip this byte and try to decode again
  200. continue
  201. }
  202. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  203. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  204. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  205. currentData := InstInfo{
  206. PC: pc,
  207. SymAddr: funcAbsAddress + pc,
  208. Inst: inst,
  209. }
  210. if pc == 0 {
  211. j.DebugLibNetInfo.FuncSymbol.PC = currentData.PC
  212. j.DebugLibNetInfo.FuncSymbol.Inst = currentData.Inst
  213. j.DebugLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  214. }
  215. if pc == IO_FD_FDID_SYM_OFFSET {
  216. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  217. debugFuncSym.IO_fd_fdID = currentData
  218. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  219. // 计算目标地址
  220. if currentData.Inst.Op == x86asm.MOV &&
  221. len(currentData.Inst.Args) == 4 &&
  222. currentData.Inst.Args[0] != nil &&
  223. currentData.Inst.Args[0] == x86asm.RDX &&
  224. currentData.Inst.Args[1] != nil {
  225. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  226. // 直接从Mem结构体中读取偏移
  227. relOffset := mem.Disp
  228. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  229. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  230. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  231. // 保存原始数据
  232. debugFuncSym.IO_fd_fdID.OriginTargetAddr = targetAddress
  233. debugFuncSym.IO_fd_fdID.OriginInst = currentData.Inst
  234. j.PreCheck.IoFdCheck = true
  235. } else {
  236. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  237. }
  238. } else {
  239. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  240. }
  241. }
  242. if pc == NET_SEND_SYM_OFFSET {
  243. debugFuncSym.NET_Send = currentData
  244. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  245. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  246. if !ok {
  247. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  248. }
  249. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  250. debugFuncSym.NET_Send.TargetAddr = targetAddress
  251. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  252. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  253. // 保存原始数据
  254. debugFuncSym.NET_Send.OriginTargetAddr = targetAddress
  255. debugFuncSym.NET_Send.OriginInst = currentData.Inst
  256. j.PreCheck.NetSendFuncCheck = true
  257. }
  258. preContext = InstInfo{
  259. PC: pc,
  260. SymAddr: funcAbsAddress + pc,
  261. Inst: inst,
  262. }
  263. pc += uint64(inst.Len)
  264. }
  265. j.DebugLibNetInfo.InnerSymbol = debugFuncSym
  266. return 0, nil
  267. }
  268. func (j *JvmInjector) checkDebugFuncSymAfterChange() (uint64, error) {
  269. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  270. debugFuncSym := InnerSymbolInfo{}
  271. code, err := j.readMemory(funcAbsAddress, j.DebugLibNetInfo.FuncSymbol.SymSize)
  272. if err != nil {
  273. return 0, err
  274. }
  275. pc := uint64(0)
  276. preContext := InstInfo{}
  277. for pc < uint64(len(code)) {
  278. inst, err := x86asm.Decode(code[pc:], 64)
  279. if err != nil {
  280. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  281. pc++ // Skip this byte and try to decode again
  282. continue
  283. }
  284. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  285. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  286. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  287. currentData := InstInfo{
  288. PC: pc,
  289. SymAddr: funcAbsAddress + pc,
  290. Inst: inst,
  291. }
  292. if pc == NET_SEND_SYM_OFFSET {
  293. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  294. debugFuncSym.IO_fd_fdID = currentData
  295. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  296. // 计算目标地址
  297. if currentData.Inst.Op == x86asm.MOV &&
  298. len(currentData.Inst.Args) == 4 &&
  299. currentData.Inst.Args[0] != nil &&
  300. currentData.Inst.Args[0] == x86asm.RDX &&
  301. currentData.Inst.Args[1] != nil {
  302. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  303. // 直接从Mem结构体中读取偏移
  304. relOffset := mem.Disp
  305. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  306. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  307. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  308. //j.PreCheck.IoFdCheck = true
  309. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr {
  310. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr = targetAddress
  311. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.Inst = currentData.Inst
  312. j.AfterCheck.IoFdCheck = true
  313. fmt.Println("ok")
  314. }
  315. } else {
  316. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  317. }
  318. } else {
  319. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  320. }
  321. }
  322. if pc == NET_SEND_SYM_OFFSET {
  323. debugFuncSym.NET_Send = currentData
  324. //fmt.Println(currentData.IntelInst)
  325. //fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  326. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  327. if !ok {
  328. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  329. }
  330. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  331. debugFuncSym.NET_Send.TargetAddr = targetAddress
  332. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  333. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  334. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr {
  335. j.DebugLibNetInfo.InnerSymbol.NET_Send.TargetAddr = targetAddress
  336. j.DebugLibNetInfo.InnerSymbol.NET_Send.Inst = currentData.Inst
  337. j.AfterCheck.NetSendFuncCheck = true
  338. }
  339. }
  340. preContext = InstInfo{
  341. PC: pc,
  342. SymAddr: funcAbsAddress + pc,
  343. Inst: inst,
  344. }
  345. pc += uint64(inst.Len)
  346. }
  347. return 0, nil
  348. }
  349. func (j *JvmInjector) checkReleaseFuncSymAfterChange() error {
  350. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  351. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  352. if err != nil {
  353. return fmt.Errorf("readMemory error in checkReleaseFuncSymAfterChange <%v>", err)
  354. }
  355. inst, err := x86asm.Decode(code[0:], 64)
  356. if err != nil {
  357. return fmt.Errorf("Decode error in checkReleaseFuncSymAfterChange <%v>", err)
  358. }
  359. if inst.Op != x86asm.JMP {
  360. return fmt.Errorf("The instruction does not JMP.")
  361. }
  362. relOffset, ok := inst.Args[0].(x86asm.Rel)
  363. if !ok {
  364. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  365. }
  366. // 验证target与Debug入口是否一致
  367. targetAddress := funcAbsAddress + uint64(inst.Len) + uint64(relOffset)
  368. if targetAddress != j.DebugLibNetInfo.FuncSymbol.SymAddr {
  369. return fmt.Errorf("Function entry jmp address does not match expectations.")
  370. }
  371. return nil
  372. }
  373. // readMemory 用于读取指定地址的内存数据
  374. func (j *JvmInjector) readMemory(address uint64, size uint64) ([]byte, error) {
  375. memFile := fmt.Sprintf("/proc/%d/mem", j.Pid)
  376. file, err := os.Open(memFile)
  377. if err != nil {
  378. return nil, err
  379. }
  380. defer file.Close()
  381. data := make([]byte, size)
  382. _, err = file.ReadAt(data, int64(address))
  383. if err != nil {
  384. return nil, err
  385. }
  386. return data, nil
  387. }
  388. // findLibraryBases 用于在 /proc/[pid]/maps 文件中查找库的所有基地址
  389. func findLibraryBasesList(pid int, libraryName string, libPath string) ([]uint64, error) {
  390. mapsFile := fmt.Sprintf("/proc/%d/maps", pid)
  391. file, err := os.Open(mapsFile)
  392. if err != nil {
  393. return nil, err
  394. }
  395. defer file.Close()
  396. var bases []uint64
  397. scanner := bufio.NewScanner(file)
  398. for scanner.Scan() {
  399. line := scanner.Text()
  400. if strings.Contains(line, libraryName) && strings.Contains(line, libPath) {
  401. var start, end uint64
  402. fmt.Sscanf(line, "%x-%x", &start, &end)
  403. bases = append(bases, start)
  404. }
  405. }
  406. if len(bases) == 0 {
  407. return nil, fmt.Errorf("library %s not found", libraryName)
  408. }
  409. return bases, nil
  410. }
  411. func (j *JvmInjector) findLibBaseFromProcMaps(libName string) (uint64, string, error) {
  412. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  413. file, err := os.Open(mapsFile)
  414. if err != nil {
  415. return 0, "", err
  416. }
  417. defer file.Close()
  418. var start, end uint64
  419. scanner := bufio.NewScanner(file)
  420. for scanner.Scan() {
  421. line := scanner.Text()
  422. if strings.Contains(line, "/"+libName) {
  423. fmt.Sscanf(line, "%x-%x", &start, &end)
  424. fields := strings.Fields(line)
  425. if len(fields) > 5 {
  426. path := fields[5]
  427. if strings.HasSuffix(path, ".so") {
  428. fmt.Printf("Found library %s\n", path)
  429. return start, path, nil
  430. }
  431. }
  432. }
  433. }
  434. return 1, "", fmt.Errorf("library %s not found", libName)
  435. }
  436. func (j *JvmInjector) getFunctionOffset(libPath, functionName string) (elf.Symbol, error) {
  437. elfFile, err := elf.Open(libPath)
  438. if err != nil {
  439. return elf.Symbol{}, fmt.Errorf("failed to open ELF file: %v", err)
  440. }
  441. defer elfFile.Close()
  442. symbols, err := elfFile.DynamicSymbols()
  443. if err != nil {
  444. return elf.Symbol{}, fmt.Errorf("failed to read dynamic symbols: %v", err)
  445. }
  446. for _, sym := range symbols {
  447. if sym.Name == functionName {
  448. fmt.Println("size:", sym.Size)
  449. return sym, nil
  450. }
  451. }
  452. //textSection := elfFile.Section(".text")
  453. //if textSection == nil {
  454. // fmt.Println("textSection is null")
  455. // //return nil
  456. //}
  457. //textSectionData, err := textSection.Data()
  458. //if err != nil {
  459. // fmt.Println("textSectionData error is", err)
  460. // //return nil
  461. //}
  462. //textSectionLen := uint64(len(textSectionData) - 1)
  463. return elf.Symbol{}, fmt.Errorf("function %s not found", functionName)
  464. }
  465. //var PID string
  466. func (j *JvmInjector) findReleaseFuncContextFromLibPath() error {
  467. // 获取release库的基地址
  468. baseAddress, libPath, err := j.findLibBaseFromProcMaps(j.ReleaseLibNetInfo.LibName)
  469. functionName := j.ReleaseLibNetInfo.FuncSymbol.SymName
  470. j.ReleaseLibNetInfo.LibPath = libPath
  471. libName := j.ReleaseLibNetInfo.LibName
  472. if err != nil {
  473. log.Fatalf("Error finding base addresses: %v", err)
  474. return err
  475. }
  476. fmt.Printf("Base address of (%s)%s: %x\n", "", libName, baseAddress)
  477. // 获取函数的偏移量
  478. functionSym, err := j.getFunctionOffset(libPath, functionName)
  479. // 计算函数的实际内存地址
  480. j.ReleaseLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  481. j.ReleaseLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  482. if err != nil {
  483. log.Fatalf("Error getting function offset: %v", err)
  484. return err
  485. }
  486. fmt.Printf("Actual memory address of %s at base 0x%x: 0x%x\n", functionName, baseAddress, j.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  487. err = j.findReleaseAddressInfoFromMem()
  488. if err != nil {
  489. return err
  490. } else {
  491. j.PreCheck.NeedInjectionCheck = true
  492. }
  493. return nil
  494. }
  495. func (j *JvmInjector) findDebugFuncContextFromLibPath() error {
  496. libName := j.DebugLibNetInfo.LibName
  497. // 获取release库的基地址
  498. baseAddress, libPath, err := j.findLibBaseFromProcMaps(libName)
  499. fmt.Println(libPath)
  500. functionName := j.DebugLibNetInfo.FuncSymbol.SymName
  501. j.DebugLibNetInfo.LibPath = libPath
  502. if err != nil {
  503. log.Fatalf("Error finding base addresses: %v", err)
  504. return err
  505. }
  506. // 获取函数的偏移量
  507. functionSym, err := j.getFunctionOffset(libPath, functionName)
  508. // 计算函数的实际内存地址
  509. j.DebugLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  510. j.DebugLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  511. if err != nil {
  512. log.Fatalf("Error getting function offset: %v", err)
  513. return err
  514. }
  515. fmt.Printf("Actual memory address of %s at base 0x%x: 0x%x\n", functionName, baseAddress, j.DebugLibNetInfo.FuncSymbol.SymAddr)
  516. _, err = j.findDebugAddressInfoFromMem()
  517. if err != nil {
  518. log.Printf("Error finding first CALL instuction: %v", err)
  519. return err
  520. }
  521. fmt.Printf("First CALL instuction o1f %s at base 0x%x\n", functionName, baseAddress)
  522. return nil
  523. }
  524. func printCodeData(data LibNetInfo) {
  525. fmt.Printf("========FuncEnter <0x%x> \n", data.FuncSymbol.SymAddr)
  526. fmt.Printf("Name %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x> \nOrigin-Inst:<%s> | Inst:<%s> \n",
  527. data.InnerSymbol.IO_fd_fdID.SymName,
  528. data.InnerSymbol.IO_fd_fdID.SymAddr,
  529. data.InnerSymbol.IO_fd_fdID.OriginTargetAddr,
  530. data.InnerSymbol.IO_fd_fdID.TargetAddr,
  531. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.OriginInst, 0, nil),
  532. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.Inst, 0, nil))
  533. fmt.Printf("\nName %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x>\nOrigin-Inst:<%s> | Inst:<%s> \n",
  534. data.InnerSymbol.NET_Send.SymName,
  535. data.InnerSymbol.NET_Send.SymAddr,
  536. data.InnerSymbol.NET_Send.OriginTargetAddr,
  537. data.InnerSymbol.NET_Send.TargetAddr,
  538. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.OriginInst, 0, nil),
  539. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.Inst, 0, nil))
  540. fmt.Println("========")
  541. }
  542. func (j *JvmInjector) jvmInjectLib() int {
  543. dll := C.CString(j.DebugLibNetInfo.LibPath) // 替换为实际的DLL路径
  544. defer C.free(unsafe.Pointer(dll)) // 确保在使用完字符串后释放内存
  545. result := C.cw_inject_library(C.int(j.Pid), C.int(1), dll)
  546. fmt.Printf("Result: %d\n", result)
  547. return int(result)
  548. }
  549. func (j *JvmInjector) validateAllPreCheck() bool {
  550. return j.PreCheck.NeedInjectionCheck && j.PreCheck.LoadingCheck && j.PreCheck.IoFdCheck && j.PreCheck.NetSendFuncCheck
  551. }
  552. func (j *JvmInjector) validateAllModifyCheck() bool {
  553. return j.AfterCheck.IoFdCheck && j.AfterCheck.NetSendFuncCheck
  554. }
  555. /*修改部分*/
  556. func readData(pid int, addr uintptr) (uint64, error) {
  557. var data uint64
  558. if _, err := syscall.PtracePeekData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  559. return 0, fmt.Errorf("ptrace PEEKDATA: %v", err)
  560. }
  561. return data, nil
  562. }
  563. func writeData(pid int, addr uintptr, data uint64) error {
  564. if _, err := syscall.PtracePokeData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  565. return fmt.Errorf("ptrace POKEDATA: %v", err)
  566. }
  567. return nil
  568. }
  569. func modifyIoFdTargetAddr(pid int, insertAddr, distAddr uintptr) error {
  570. newOffset := distAddr - (insertAddr + 7)
  571. targetAddr := insertAddr + 3
  572. // 获取目标地址处的数据
  573. originalData, err := readData(pid, targetAddr)
  574. if err != nil {
  575. return err
  576. }
  577. // 更新数据中的目标偏移
  578. updatedData := (originalData & 0xFFFFFFFF00000000) | uint64(newOffset&0xFFFFFFFF)
  579. err = writeData(pid, targetAddr, updatedData)
  580. if err != nil {
  581. return err
  582. }
  583. return nil
  584. }
  585. func modifyNetSetTargetAddr(pid int, sendDebugAddr, sendReleaseAddr uintptr) error {
  586. sendOffset := sendReleaseAddr - sendDebugAddr - 5
  587. // 读取原始数据
  588. alignedAddr := sendDebugAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  589. originalData, err := readData(pid, alignedAddr)
  590. if err != nil {
  591. return err
  592. }
  593. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  594. offsetLocation := (sendDebugAddr % uintptr(unsafe.Sizeof(uintptr(0)))) + 1
  595. *(*uint32)(unsafe.Pointer(&bytes[offsetLocation])) = uint32(sendOffset)
  596. err = writeData(pid, alignedAddr, originalData)
  597. if err != nil {
  598. return err
  599. }
  600. return nil
  601. }
  602. func modifyReleaseFuncEnter(pid int, originEnterAddr, debugEnterAddr uintptr) error {
  603. offset := debugEnterAddr - (originEnterAddr + 5)
  604. // 读取原始数据
  605. alignedAddr := originEnterAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  606. originalData, err := readData(pid, alignedAddr)
  607. if err != nil {
  608. return err
  609. }
  610. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  611. bytes[originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0)))] = 0xe9
  612. *(*uint32)(unsafe.Pointer(&bytes[(originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0))))+1])) = uint32(offset)
  613. err = writeData(pid, alignedAddr, originalData)
  614. if err != nil {
  615. return err
  616. }
  617. return nil
  618. }
  619. func restoreOriginalInstructions(pid int, addr uintptr, instructions []byte) error {
  620. alignedAddr := addr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  621. originalData, err := readData(pid, alignedAddr)
  622. if err != nil {
  623. return err
  624. }
  625. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  626. for i := 0; i < len(instructions); i++ {
  627. bytes[addr%uintptr(unsafe.Sizeof(uintptr(0)))+uintptr(i)] = instructions[i]
  628. }
  629. err = writeData(pid, alignedAddr, originalData)
  630. if err != nil {
  631. return err
  632. }
  633. return nil
  634. }
  635. //func main() {
  636. // flag.StringVar(&PID, "p", "", "PID")
  637. // flag.Parse()
  638. // pidStr := PID // 替换为目标进程的 PID
  639. // pid, err := strconv.Atoi(pidStr)
  640. // if err != nil {
  641. // log.Fatalf("Invalid PID: %v", err)
  642. // }
  643. // functionName := "Java_java_net_SocketOutputStream_socketWrite0"
  644. // libraryName := "libnet.so"
  645. //
  646. // cwLibraryName := "cwlibnet.so"
  647. // cwLibraryPath := "/root/cwlibnet.so"
  648. //
  649. // jvmInjector := &JvmInjector{
  650. // pid: pid,
  651. // ReleaseLibNetInfo: LibNetInfo{
  652. // libName: libraryName,
  653. // FuncSymbol: instInfo{
  654. // SymName: functionName,
  655. // },
  656. // },
  657. // DebugLibNetInfo: LibNetInfo{
  658. // // TODO 根据版本设置
  659. // libName: cwLibraryName,
  660. // // TODO 根据版本设置
  661. // libPath: cwLibraryPath,
  662. // FuncSymbol: instInfo{
  663. // SymName: functionName,
  664. // },
  665. // },
  666. // }
  667. //
  668. // err = jvmInject(jvmInjector)
  669. // fmt.Println(err)
  670. //}
  671. func JvmInject(jvmInjector *JvmInjector) error {
  672. pid := jvmInjector.Pid
  673. var err error
  674. err = jvmInjector.findReleaseFuncContextFromLibPath()
  675. // Debug版本无需修改寄存器
  676. // 已经加载so并指令修改正确的
  677. if jvmInjector.PreCheck.EbpfCanInjection {
  678. fmt.Println("eBPF can injection.")
  679. return nil
  680. }
  681. if err != nil {
  682. log.Fatalf("Error message during release phase: %v", err)
  683. return err
  684. }
  685. // 原指令校验通过
  686. if !jvmInjector.PreCheck.NeedInjectionCheck {
  687. return err
  688. }
  689. printCodeData(jvmInjector.ReleaseLibNetInfo)
  690. _type, _, err := jvmInjector.findLibBaseFromProcMaps(jvmInjector.DebugLibNetInfo.LibName)
  691. if err != nil {
  692. // load so
  693. if _type == 1 {
  694. fmt.Println(err, "Load it.")
  695. if jvmInjector.jvmInjectLib() == 0 {
  696. jvmInjector.PreCheck.LoadingCheck = true
  697. } else {
  698. return err
  699. }
  700. }
  701. } else {
  702. jvmInjector.PreCheck.LoadingCheck = true
  703. }
  704. if !jvmInjector.PreCheck.LoadingCheck {
  705. fmt.Println("Failed load so")
  706. return err
  707. }
  708. err = jvmInjector.findDebugFuncContextFromLibPath()
  709. if err != nil {
  710. log.Fatalf("Failed to find debug Context: %v", err)
  711. }
  712. if !jvmInjector.validateAllPreCheck() {
  713. fmt.Println("failed validateAllPreCheck ")
  714. return err
  715. }
  716. // 修改
  717. debugFuncEnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncSymbol.SymAddr)
  718. debugIoFdAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.SymAddr)
  719. debugNetSendAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.NET_Send.SymAddr)
  720. originFuncEnterAddr := uintptr(jvmInjector.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  721. ioFdReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr)
  722. netSendReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr)
  723. fmt.Printf("<0x%x> -> <0x%x>\n", originFuncEnterAddr, debugFuncEnterAddr)
  724. fmt.Printf("<0x%x> -> <0x%x>\n", debugIoFdAddr, ioFdReleaseTargetAddr)
  725. fmt.Printf("<0x%x> -> <0x%x>\n", debugNetSendAddr, netSendReleaseTargetAddr)
  726. // 附加到目标进程
  727. err = syscall.PtraceAttach(pid)
  728. if err != nil {
  729. fmt.Printf("ptrace ATTACH: %v", err)
  730. }
  731. // 等待目标进程停止
  732. if _, err := syscall.Wait4(pid, nil, 0, nil); err != nil {
  733. fmt.Printf("wait4: %v", err)
  734. return err
  735. }
  736. time.Now().UnixNano()
  737. // 修改目标的内存
  738. err = modifyIoFdTargetAddr(pid, debugIoFdAddr, ioFdReleaseTargetAddr)
  739. if err != nil {
  740. fmt.Println(err)
  741. return err
  742. }
  743. err = modifyNetSetTargetAddr(pid, debugNetSendAddr, netSendReleaseTargetAddr)
  744. fmt.Println(err)
  745. if err != nil {
  746. fmt.Println(err)
  747. return err
  748. }
  749. // 二次效验 读取并验证地址
  750. _, err = jvmInjector.checkDebugFuncSymAfterChange()
  751. printCodeData(jvmInjector.ReleaseLibNetInfo)
  752. printCodeData(jvmInjector.DebugLibNetInfo)
  753. // 效验目标函数内地址是否与预期一致
  754. if !jvmInjector.validateAllModifyCheck() && err == nil {
  755. return err
  756. }
  757. // 更新函数入口
  758. err = modifyReleaseFuncEnter(pid, originFuncEnterAddr, debugFuncEnterAddr)
  759. if err != nil {
  760. fmt.Println(err)
  761. return err
  762. }
  763. // 校验jmp地址修改正确
  764. err = jvmInjector.checkReleaseFuncSymAfterChange()
  765. if err != nil {
  766. fmt.Println(err)
  767. if len(jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode) == 5 {
  768. err = restoreOriginalInstructions(pid, originFuncEnterAddr, jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode)
  769. if err != nil {
  770. fmt.Println(err)
  771. return err
  772. }
  773. }
  774. }
  775. // 恢复执行
  776. if err = syscall.PtraceDetach(pid); err != nil {
  777. fmt.Printf("ptrace DETACH: %v", err)
  778. return err
  779. }
  780. return nil
  781. }