inject_linux_amd64.go 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857
  1. package inject
  2. /*
  3. #cgo CFLAGS: -I include
  4. #cgo amd64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_amd64.a
  5. #cgo arm64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_arm64.a
  6. #include "hotpatch.h"
  7. #include <stdlib.h>
  8. */
  9. import "C"
  10. import (
  11. "bufio"
  12. "debug/elf"
  13. "fmt"
  14. "golang.org/x/arch/x86/x86asm"
  15. "log"
  16. "os"
  17. "strings"
  18. "syscall"
  19. "time"
  20. "unsafe"
  21. )
  22. const (
  23. IO_FD_FDID_SYM_OFFSET = 129
  24. NET_SEND_SYM_OFFSET = 518
  25. )
  26. type InstInfo struct {
  27. SymName string
  28. SymSize uint64
  29. SymAddr uint64
  30. PC uint64
  31. Inst x86asm.Inst
  32. OriginInst x86asm.Inst
  33. OriginCode []byte
  34. TargetAddr uint64
  35. OriginTargetAddr uint64
  36. }
  37. type InnerSymbolInfo struct {
  38. IO_fd_fdID InstInfo
  39. NET_Send InstInfo
  40. }
  41. type LibNetInfo struct {
  42. LibName string
  43. LibPath string
  44. FuncSymbol InstInfo
  45. InnerSymbol InnerSymbolInfo
  46. }
  47. type JvmInjector struct {
  48. Pid int
  49. ReleaseLibNetInfo LibNetInfo
  50. DebugLibNetInfo LibNetInfo
  51. // 原方法首个指令不为jmp | ReleaseLibNetInfo 读取无异常
  52. PreCheck struct {
  53. NeedInjectionCheck bool // 原指令校验 true表示可以继续执行注入
  54. LoadingCheck bool // true 表示加载成功
  55. IoFdCheck bool // fd地址校验
  56. NetSendFuncCheck bool // netsend校验
  57. EbpfCanInjection bool
  58. }
  59. AfterCheck struct {
  60. IoFdCheck bool
  61. NetSendFuncCheck bool
  62. }
  63. }
  64. func (j *JvmInjector) findReleaseAddressInfoFromMem() error {
  65. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  66. releaseFuncSym := InnerSymbolInfo{}
  67. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  68. if err != nil {
  69. return err
  70. }
  71. pc := uint64(0)
  72. callCount := 0
  73. preContext := InstInfo{}
  74. for pc < uint64(len(code)) {
  75. inst, err := x86asm.Decode(code[pc:], 64)
  76. if err != nil {
  77. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  78. pc++ // Skip this byte and try to decode again
  79. continue
  80. }
  81. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  82. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  83. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  84. currentData := InstInfo{
  85. PC: pc,
  86. SymAddr: funcAbsAddress + pc,
  87. Inst: inst,
  88. //IntelInst: x86asm.IntelSyntax(inst, 0, nil),
  89. }
  90. if pc == 0 && inst.Op == x86asm.JMP {
  91. // 已经被修改过的首指令
  92. return fmt.Errorf("Inst already modified. <%s>", x86asm.IntelSyntax(inst, 0, nil))
  93. }
  94. if pc == 0 {
  95. j.ReleaseLibNetInfo.FuncSymbol.PC = currentData.PC
  96. j.ReleaseLibNetInfo.FuncSymbol.Inst = currentData.Inst
  97. j.ReleaseLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  98. }
  99. if inst.Op == x86asm.MOV {
  100. if dst, okDst := inst.Args[0].(x86asm.Mem); okDst {
  101. if dst.Base == x86asm.RBP {
  102. if src, okSrc := inst.Args[1].(x86asm.Reg); okSrc {
  103. if src == x86asm.R9L {
  104. j.PreCheck.EbpfCanInjection = true
  105. return fmt.Errorf("MOV from register %v to memory %v\n", src, dst)
  106. }
  107. }
  108. }
  109. }
  110. //src, okSrc := inst.Args[1].(x86asm.Reg)
  111. //fmt.Println(inst.Args)
  112. //fmt.Printf("Instruction: %+v\n", inst)
  113. //
  114. //fmt.Println(okSrc)
  115. //if okDst && okSrc && dst == x86asm.RBP && src == x86asm.R9L {
  116. // fmt.Println("Instruction is 'mov %r9d, %rbp'")
  117. //}
  118. }
  119. if inst.Op == x86asm.CALL {
  120. //fmt.Printf("Pre instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  121. if callCount == 0 {
  122. releaseFuncSym.IO_fd_fdID = preContext
  123. releaseFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Release)"
  124. preInst := preContext.Inst
  125. fmt.Println(preInst.Op)
  126. fmt.Println((preInst.Args))
  127. // 计算目标地址
  128. if preInst.Op == x86asm.MOV &&
  129. len(preInst.Args) == 4 &&
  130. preInst.Args[0] != nil &&
  131. preInst.Args[0] == x86asm.RDX &&
  132. preInst.Args[1] != nil {
  133. if mem, ok := preInst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  134. relOffset := mem.Disp // 直接从Mem结构体中读取偏移
  135. targetAddress := preContext.SymAddr + uint64(preInst.Len) + uint64(relOffset)
  136. fmt.Printf("Target address: 0x%x\n", targetAddress)
  137. releaseFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  138. } else {
  139. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  140. }
  141. } else {
  142. return fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  143. }
  144. //os.Exit(1)
  145. }
  146. callCount++
  147. if callCount == 4 {
  148. releaseFuncSym.NET_Send = currentData
  149. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  150. relOffset, ok := inst.Args[0].(x86asm.Rel)
  151. if !ok {
  152. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  153. }
  154. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  155. releaseFuncSym.NET_Send.TargetAddr = targetAddress
  156. fmt.Println(releaseFuncSym.NET_Send)
  157. releaseFuncSym.NET_Send.SymName = "<NET_Send>(Release)"
  158. fmt.Printf("Target address: 0x%x\n", targetAddress)
  159. }
  160. }
  161. preContext = InstInfo{
  162. PC: pc,
  163. SymAddr: funcAbsAddress + pc,
  164. Inst: inst,
  165. }
  166. pc += uint64(inst.Len)
  167. }
  168. j.ReleaseLibNetInfo.InnerSymbol = releaseFuncSym
  169. j.ReleaseLibNetInfo.FuncSymbol.OriginCode = code[0:5]
  170. return nil
  171. }
  172. func (j *JvmInjector) findDebugAddressInfoFromMem() (uint64, error) {
  173. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  174. debugFuncSym := InnerSymbolInfo{}
  175. //debugFuncSym.FuncSymbol.SymAddr = funcAbsAddress
  176. //offset := sym.Value
  177. size := j.DebugLibNetInfo.FuncSymbol.SymSize
  178. code, err := j.readMemory(funcAbsAddress, size)
  179. //fmt.Println(code, err)
  180. if err != nil {
  181. return 0, err
  182. }
  183. pc := uint64(0)
  184. preContext := InstInfo{}
  185. for pc < uint64(len(code)) {
  186. inst, err := x86asm.Decode(code[pc:], 64)
  187. if err != nil {
  188. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  189. pc++ // Skip this byte and try to decode again
  190. continue
  191. }
  192. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  193. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  194. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  195. currentData := InstInfo{
  196. PC: pc,
  197. SymAddr: funcAbsAddress + pc,
  198. Inst: inst,
  199. }
  200. if pc == 0 {
  201. j.DebugLibNetInfo.FuncSymbol.PC = currentData.PC
  202. j.DebugLibNetInfo.FuncSymbol.Inst = currentData.Inst
  203. j.DebugLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  204. }
  205. if pc == IO_FD_FDID_SYM_OFFSET {
  206. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  207. debugFuncSym.IO_fd_fdID = currentData
  208. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  209. // 计算目标地址
  210. if currentData.Inst.Op == x86asm.MOV &&
  211. len(currentData.Inst.Args) == 4 &&
  212. currentData.Inst.Args[0] != nil &&
  213. currentData.Inst.Args[0] == x86asm.RDX &&
  214. currentData.Inst.Args[1] != nil {
  215. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  216. // 直接从Mem结构体中读取偏移
  217. relOffset := mem.Disp
  218. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  219. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  220. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  221. // 保存原始数据
  222. debugFuncSym.IO_fd_fdID.OriginTargetAddr = targetAddress
  223. debugFuncSym.IO_fd_fdID.OriginInst = currentData.Inst
  224. j.PreCheck.IoFdCheck = true
  225. } else {
  226. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  227. }
  228. } else {
  229. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  230. }
  231. }
  232. if pc == NET_SEND_SYM_OFFSET {
  233. debugFuncSym.NET_Send = currentData
  234. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  235. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  236. if !ok {
  237. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  238. }
  239. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  240. debugFuncSym.NET_Send.TargetAddr = targetAddress
  241. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  242. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  243. // 保存原始数据
  244. debugFuncSym.NET_Send.OriginTargetAddr = targetAddress
  245. debugFuncSym.NET_Send.OriginInst = currentData.Inst
  246. j.PreCheck.NetSendFuncCheck = true
  247. }
  248. preContext = InstInfo{
  249. PC: pc,
  250. SymAddr: funcAbsAddress + pc,
  251. Inst: inst,
  252. }
  253. pc += uint64(inst.Len)
  254. }
  255. j.DebugLibNetInfo.InnerSymbol = debugFuncSym
  256. return 0, nil
  257. }
  258. func (j *JvmInjector) checkDebugFuncSymAfterChange() (uint64, error) {
  259. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  260. debugFuncSym := InnerSymbolInfo{}
  261. code, err := j.readMemory(funcAbsAddress, j.DebugLibNetInfo.FuncSymbol.SymSize)
  262. if err != nil {
  263. return 0, err
  264. }
  265. pc := uint64(0)
  266. preContext := InstInfo{}
  267. for pc < uint64(len(code)) {
  268. inst, err := x86asm.Decode(code[pc:], 64)
  269. if err != nil {
  270. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  271. pc++ // Skip this byte and try to decode again
  272. continue
  273. }
  274. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  275. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  276. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  277. currentData := InstInfo{
  278. PC: pc,
  279. SymAddr: funcAbsAddress + pc,
  280. Inst: inst,
  281. }
  282. if pc == NET_SEND_SYM_OFFSET {
  283. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  284. debugFuncSym.IO_fd_fdID = currentData
  285. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  286. // 计算目标地址
  287. if currentData.Inst.Op == x86asm.MOV &&
  288. len(currentData.Inst.Args) == 4 &&
  289. currentData.Inst.Args[0] != nil &&
  290. currentData.Inst.Args[0] == x86asm.RDX &&
  291. currentData.Inst.Args[1] != nil {
  292. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  293. // 直接从Mem结构体中读取偏移
  294. relOffset := mem.Disp
  295. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  296. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  297. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  298. //j.PreCheck.IoFdCheck = true
  299. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr {
  300. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr = targetAddress
  301. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.Inst = currentData.Inst
  302. j.AfterCheck.IoFdCheck = true
  303. fmt.Println("ok")
  304. }
  305. } else {
  306. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  307. }
  308. } else {
  309. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  310. }
  311. }
  312. if pc == NET_SEND_SYM_OFFSET {
  313. debugFuncSym.NET_Send = currentData
  314. //fmt.Println(currentData.IntelInst)
  315. //fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  316. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  317. if !ok {
  318. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  319. }
  320. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  321. debugFuncSym.NET_Send.TargetAddr = targetAddress
  322. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  323. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  324. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr {
  325. j.DebugLibNetInfo.InnerSymbol.NET_Send.TargetAddr = targetAddress
  326. j.DebugLibNetInfo.InnerSymbol.NET_Send.Inst = currentData.Inst
  327. j.AfterCheck.NetSendFuncCheck = true
  328. }
  329. }
  330. preContext = InstInfo{
  331. PC: pc,
  332. SymAddr: funcAbsAddress + pc,
  333. Inst: inst,
  334. }
  335. pc += uint64(inst.Len)
  336. }
  337. return 0, nil
  338. }
  339. func (j *JvmInjector) checkReleaseFuncSymAfterChange() error {
  340. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  341. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  342. if err != nil {
  343. return fmt.Errorf("readMemory error in checkReleaseFuncSymAfterChange <%v>", err)
  344. }
  345. inst, err := x86asm.Decode(code[0:], 64)
  346. if err != nil {
  347. return fmt.Errorf("Decode error in checkReleaseFuncSymAfterChange <%v>", err)
  348. }
  349. if inst.Op != x86asm.JMP {
  350. return fmt.Errorf("The instruction does not JMP.")
  351. }
  352. relOffset, ok := inst.Args[0].(x86asm.Rel)
  353. if !ok {
  354. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  355. }
  356. // 验证target与Debug入口是否一致
  357. targetAddress := funcAbsAddress + uint64(inst.Len) + uint64(relOffset)
  358. if targetAddress != j.DebugLibNetInfo.FuncSymbol.SymAddr {
  359. return fmt.Errorf("Function entry jmp address does not match expectations.")
  360. }
  361. return nil
  362. }
  363. // readMemory 用于读取指定地址的内存数据
  364. func (j *JvmInjector) readMemory(address uint64, size uint64) ([]byte, error) {
  365. memFile := fmt.Sprintf("/proc/%d/mem", j.Pid)
  366. file, err := os.Open(memFile)
  367. if err != nil {
  368. return nil, err
  369. }
  370. defer file.Close()
  371. data := make([]byte, size)
  372. _, err = file.ReadAt(data, int64(address))
  373. if err != nil {
  374. return nil, err
  375. }
  376. return data, nil
  377. }
  378. // findLibraryBases 用于在 /proc/[pid]/maps 文件中查找库的所有基地址
  379. func findLibraryBasesList(pid int, libraryName string, libPath string) ([]uint64, error) {
  380. mapsFile := fmt.Sprintf("/proc/%d/maps", pid)
  381. file, err := os.Open(mapsFile)
  382. if err != nil {
  383. return nil, err
  384. }
  385. defer file.Close()
  386. var bases []uint64
  387. scanner := bufio.NewScanner(file)
  388. for scanner.Scan() {
  389. line := scanner.Text()
  390. if strings.Contains(line, libraryName) && strings.Contains(line, libPath) {
  391. var start, end uint64
  392. fmt.Sscanf(line, "%x-%x", &start, &end)
  393. bases = append(bases, start)
  394. }
  395. }
  396. if len(bases) == 0 {
  397. return nil, fmt.Errorf("library %s not found", libraryName)
  398. }
  399. return bases, nil
  400. }
  401. func (j *JvmInjector) findLibBaseFromProcMaps(libName string) (uint64, string, error) {
  402. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  403. file, err := os.Open(mapsFile)
  404. if err != nil {
  405. return 0, "", err
  406. }
  407. defer file.Close()
  408. var start, end uint64
  409. scanner := bufio.NewScanner(file)
  410. for scanner.Scan() {
  411. line := scanner.Text()
  412. if strings.Contains(line, "/"+libName) {
  413. fmt.Sscanf(line, "%x-%x", &start, &end)
  414. fields := strings.Fields(line)
  415. if len(fields) > 5 {
  416. path := fields[5]
  417. if strings.HasSuffix(path, ".so") {
  418. fmt.Printf("Found library %s\n", path)
  419. return start, path, nil
  420. }
  421. }
  422. }
  423. }
  424. return 1, "", fmt.Errorf("library %s not found", libName)
  425. }
  426. func (j *JvmInjector) getFunctionOffset(libPath, functionName string) (elf.Symbol, error) {
  427. elfFile, err := elf.Open(libPath)
  428. if err != nil {
  429. return elf.Symbol{}, fmt.Errorf("failed to open ELF file: %v", err)
  430. }
  431. defer elfFile.Close()
  432. symbols, err := elfFile.DynamicSymbols()
  433. if err != nil {
  434. return elf.Symbol{}, fmt.Errorf("failed to read dynamic symbols: %v", err)
  435. }
  436. for _, sym := range symbols {
  437. if sym.Name == functionName {
  438. fmt.Println("size:", sym.Size)
  439. return sym, nil
  440. }
  441. }
  442. //textSection := elfFile.Section(".text")
  443. //if textSection == nil {
  444. // fmt.Println("textSection is null")
  445. // //return nil
  446. //}
  447. //textSectionData, err := textSection.Data()
  448. //if err != nil {
  449. // fmt.Println("textSectionData error is", err)
  450. // //return nil
  451. //}
  452. //textSectionLen := uint64(len(textSectionData) - 1)
  453. return elf.Symbol{}, fmt.Errorf("function %s not found", functionName)
  454. }
  455. //var PID string
  456. func (j *JvmInjector) findReleaseFuncContextFromLibPath() error {
  457. // 获取release库的基地址
  458. baseAddress, libPath, err := j.findLibBaseFromProcMaps(j.ReleaseLibNetInfo.LibName)
  459. functionName := j.ReleaseLibNetInfo.FuncSymbol.SymName
  460. j.ReleaseLibNetInfo.LibPath = libPath
  461. libName := j.ReleaseLibNetInfo.LibName
  462. if err != nil {
  463. log.Fatalf("Error finding base addresses: %v", err)
  464. return err
  465. }
  466. fmt.Printf("Base address of (%s)%s: %x\n", "", libName, baseAddress)
  467. // 获取函数的偏移量
  468. functionSym, err := j.getFunctionOffset(libPath, functionName)
  469. // 计算函数的实际内存地址
  470. j.ReleaseLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  471. j.ReleaseLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  472. if err != nil {
  473. log.Fatalf("Error getting function offset: %v", err)
  474. return err
  475. }
  476. fmt.Printf("Actual memory address of %s at base 0x%x: 0x%x\n", functionName, baseAddress, j.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  477. err = j.findReleaseAddressInfoFromMem()
  478. if err != nil {
  479. return err
  480. } else {
  481. j.PreCheck.NeedInjectionCheck = true
  482. }
  483. return nil
  484. }
  485. func (j *JvmInjector) findDebugFuncContextFromLibPath() error {
  486. libName := j.DebugLibNetInfo.LibName
  487. // 获取release库的基地址
  488. baseAddress, libPath, err := j.findLibBaseFromProcMaps(libName)
  489. fmt.Println(libPath)
  490. functionName := j.DebugLibNetInfo.FuncSymbol.SymName
  491. j.DebugLibNetInfo.LibPath = libPath
  492. if err != nil {
  493. log.Fatalf("Error finding base addresses: %v", err)
  494. return err
  495. }
  496. // 获取函数的偏移量
  497. functionSym, err := j.getFunctionOffset(libPath, functionName)
  498. // 计算函数的实际内存地址
  499. j.DebugLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  500. j.DebugLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  501. if err != nil {
  502. log.Fatalf("Error getting function offset: %v", err)
  503. return err
  504. }
  505. fmt.Printf("Actual memory address of %s at base 0x%x: 0x%x\n", functionName, baseAddress, j.DebugLibNetInfo.FuncSymbol.SymAddr)
  506. callAddress, err := j.findDebugAddressInfoFromMem()
  507. if err != nil || callAddress == 0 {
  508. log.Printf("Error finding first CALL instuction: %v", err)
  509. return err
  510. }
  511. fmt.Printf("First CALL instuction o1f %s at base 0x%x: 0x%x\n", functionName, baseAddress, callAddress)
  512. return nil
  513. }
  514. func printCodeData(data LibNetInfo) {
  515. fmt.Printf("========FuncEnter <0x%x> \n", data.FuncSymbol.SymAddr)
  516. fmt.Printf("Name %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x> \nOrigin-Inst:<%s> | Inst:<%s> \n",
  517. data.InnerSymbol.IO_fd_fdID.SymName,
  518. data.InnerSymbol.IO_fd_fdID.SymAddr,
  519. data.InnerSymbol.IO_fd_fdID.OriginTargetAddr,
  520. data.InnerSymbol.IO_fd_fdID.TargetAddr,
  521. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.OriginInst, 0, nil),
  522. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.Inst, 0, nil))
  523. fmt.Printf("\nName %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x>\nOrigin-Inst:<%s> | Inst:<%s> \n",
  524. data.InnerSymbol.NET_Send.SymName,
  525. data.InnerSymbol.NET_Send.SymAddr,
  526. data.InnerSymbol.NET_Send.OriginTargetAddr,
  527. data.InnerSymbol.NET_Send.TargetAddr,
  528. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.OriginInst, 0, nil),
  529. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.Inst, 0, nil))
  530. fmt.Println("========")
  531. }
  532. func (j *JvmInjector) jvmInjectLib() int {
  533. dll := C.CString(j.DebugLibNetInfo.LibPath) // 替换为实际的DLL路径
  534. defer C.free(unsafe.Pointer(dll)) // 确保在使用完字符串后释放内存
  535. result := C.cw_inject_library(C.int(j.Pid), C.int(1), dll)
  536. fmt.Printf("Result: %d\n", result)
  537. return int(result)
  538. }
  539. func (j *JvmInjector) validateAllPreCheck() bool {
  540. return j.PreCheck.NeedInjectionCheck && j.PreCheck.LoadingCheck && j.PreCheck.IoFdCheck && j.PreCheck.NetSendFuncCheck
  541. }
  542. func (j *JvmInjector) validateAllModifyCheck() bool {
  543. return j.AfterCheck.IoFdCheck && j.AfterCheck.NetSendFuncCheck
  544. }
  545. /*修改部分*/
  546. func readData(pid int, addr uintptr) (uint64, error) {
  547. var data uint64
  548. if _, err := syscall.PtracePeekData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  549. return 0, fmt.Errorf("ptrace PEEKDATA: %v", err)
  550. }
  551. return data, nil
  552. }
  553. func writeData(pid int, addr uintptr, data uint64) error {
  554. if _, err := syscall.PtracePokeData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  555. return fmt.Errorf("ptrace POKEDATA: %v", err)
  556. }
  557. return nil
  558. }
  559. func modifyIoFdTargetAddr(pid int, insertAddr, distAddr uintptr) error {
  560. newOffset := distAddr - (insertAddr + 7)
  561. targetAddr := insertAddr + 3
  562. // 获取目标地址处的数据
  563. originalData, err := readData(pid, targetAddr)
  564. if err != nil {
  565. return err
  566. }
  567. // 更新数据中的目标偏移
  568. updatedData := (originalData & 0xFFFFFFFF00000000) | uint64(newOffset&0xFFFFFFFF)
  569. err = writeData(pid, targetAddr, updatedData)
  570. if err != nil {
  571. return err
  572. }
  573. return nil
  574. }
  575. func modifyNetSetTargetAddr(pid int, sendDebugAddr, sendReleaseAddr uintptr) error {
  576. sendOffset := sendReleaseAddr - sendDebugAddr - 5
  577. // 读取原始数据
  578. alignedAddr := sendDebugAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  579. originalData, err := readData(pid, alignedAddr)
  580. if err != nil {
  581. return err
  582. }
  583. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  584. offsetLocation := (sendDebugAddr % uintptr(unsafe.Sizeof(uintptr(0)))) + 1
  585. *(*uint32)(unsafe.Pointer(&bytes[offsetLocation])) = uint32(sendOffset)
  586. err = writeData(pid, alignedAddr, originalData)
  587. if err != nil {
  588. return err
  589. }
  590. return nil
  591. }
  592. func modifyReleaseFuncEnter(pid int, originEnterAddr, debugEnterAddr uintptr) error {
  593. offset := debugEnterAddr - (originEnterAddr + 5)
  594. // 读取原始数据
  595. alignedAddr := originEnterAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  596. originalData, err := readData(pid, alignedAddr)
  597. if err != nil {
  598. return err
  599. }
  600. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  601. bytes[originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0)))] = 0xe9
  602. *(*uint32)(unsafe.Pointer(&bytes[(originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0))))+1])) = uint32(offset)
  603. err = writeData(pid, alignedAddr, originalData)
  604. if err != nil {
  605. return err
  606. }
  607. return nil
  608. }
  609. func restoreOriginalInstructions(pid int, addr uintptr, instructions []byte) error {
  610. alignedAddr := addr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  611. originalData, err := readData(pid, alignedAddr)
  612. if err != nil {
  613. return err
  614. }
  615. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  616. for i := 0; i < len(instructions); i++ {
  617. bytes[addr%uintptr(unsafe.Sizeof(uintptr(0)))+uintptr(i)] = instructions[i]
  618. }
  619. err = writeData(pid, alignedAddr, originalData)
  620. if err != nil {
  621. return err
  622. }
  623. return nil
  624. }
  625. //func main() {
  626. // flag.StringVar(&PID, "p", "", "PID")
  627. // flag.Parse()
  628. // pidStr := PID // 替换为目标进程的 PID
  629. // pid, err := strconv.Atoi(pidStr)
  630. // if err != nil {
  631. // log.Fatalf("Invalid PID: %v", err)
  632. // }
  633. // functionName := "Java_java_net_SocketOutputStream_socketWrite0"
  634. // libraryName := "libnet.so"
  635. //
  636. // cwLibraryName := "cwlibnet.so"
  637. // cwLibraryPath := "/root/cwlibnet.so"
  638. //
  639. // jvmInjector := &JvmInjector{
  640. // pid: pid,
  641. // ReleaseLibNetInfo: LibNetInfo{
  642. // libName: libraryName,
  643. // FuncSymbol: instInfo{
  644. // SymName: functionName,
  645. // },
  646. // },
  647. // DebugLibNetInfo: LibNetInfo{
  648. // // TODO 根据版本设置
  649. // libName: cwLibraryName,
  650. // // TODO 根据版本设置
  651. // libPath: cwLibraryPath,
  652. // FuncSymbol: instInfo{
  653. // SymName: functionName,
  654. // },
  655. // },
  656. // }
  657. //
  658. // err = jvmInject(jvmInjector)
  659. // fmt.Println(err)
  660. //}
  661. func JvmInject(jvmInjector *JvmInjector) error {
  662. pid := jvmInjector.Pid
  663. var err error
  664. err = jvmInjector.findReleaseFuncContextFromLibPath()
  665. // Debug版本无需修改寄存器
  666. if jvmInjector.PreCheck.EbpfCanInjection {
  667. fmt.Println("Debug version loaded.")
  668. return nil
  669. }
  670. if err != nil {
  671. log.Fatalf("Error message during release phase: %v", err)
  672. }
  673. // 原指令校验通过
  674. if !jvmInjector.PreCheck.NeedInjectionCheck {
  675. return err
  676. }
  677. printCodeData(jvmInjector.ReleaseLibNetInfo)
  678. _type, _, err := jvmInjector.findLibBaseFromProcMaps(jvmInjector.DebugLibNetInfo.LibName)
  679. if err != nil {
  680. // load so
  681. if _type == 1 {
  682. fmt.Println(err, "Load it.")
  683. if jvmInjector.jvmInjectLib() == 0 {
  684. jvmInjector.PreCheck.LoadingCheck = true
  685. } else {
  686. return err
  687. }
  688. }
  689. } else {
  690. jvmInjector.PreCheck.LoadingCheck = true
  691. }
  692. if !jvmInjector.PreCheck.LoadingCheck {
  693. fmt.Println("Failed load so")
  694. return err
  695. }
  696. err = jvmInjector.findDebugFuncContextFromLibPath()
  697. if err != nil {
  698. log.Fatalf("Failed to find debug Context: %v", err)
  699. }
  700. if !jvmInjector.validateAllPreCheck() {
  701. fmt.Println("failed validateAllPreCheck ")
  702. return err
  703. }
  704. // 修改
  705. debugFuncEnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncSymbol.SymAddr)
  706. debugIoFdAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.SymAddr)
  707. debugNetSendAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.NET_Send.SymAddr)
  708. originFuncEnterAddr := uintptr(jvmInjector.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  709. ioFdReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr)
  710. netSendReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr)
  711. fmt.Printf("<0x%x> -> <0x%x>\n", originFuncEnterAddr, debugFuncEnterAddr)
  712. fmt.Printf("<0x%x> -> <0x%x>\n", debugIoFdAddr, ioFdReleaseTargetAddr)
  713. fmt.Printf("<0x%x> -> <0x%x>\n", debugNetSendAddr, netSendReleaseTargetAddr)
  714. // 附加到目标进程
  715. err = syscall.PtraceAttach(pid)
  716. if err != nil {
  717. fmt.Printf("ptrace ATTACH: %v", err)
  718. }
  719. // 等待目标进程停止
  720. if _, err := syscall.Wait4(pid, nil, 0, nil); err != nil {
  721. fmt.Printf("wait4: %v", err)
  722. return err
  723. }
  724. time.Now().UnixNano()
  725. // 修改目标的内存
  726. err = modifyIoFdTargetAddr(pid, debugIoFdAddr, ioFdReleaseTargetAddr)
  727. if err != nil {
  728. fmt.Println(err)
  729. return err
  730. }
  731. err = modifyNetSetTargetAddr(pid, debugNetSendAddr, netSendReleaseTargetAddr)
  732. fmt.Println(err)
  733. if err != nil {
  734. fmt.Println(err)
  735. return err
  736. }
  737. // 二次效验 读取并验证地址
  738. _, err = jvmInjector.checkDebugFuncSymAfterChange()
  739. printCodeData(jvmInjector.ReleaseLibNetInfo)
  740. printCodeData(jvmInjector.DebugLibNetInfo)
  741. // 效验目标函数内地址是否与预期一致
  742. if !jvmInjector.validateAllModifyCheck() && err == nil {
  743. return err
  744. }
  745. // 更新函数入口
  746. err = modifyReleaseFuncEnter(pid, originFuncEnterAddr, debugFuncEnterAddr)
  747. if err != nil {
  748. fmt.Println(err)
  749. return err
  750. }
  751. // 校验jmp地址修改正确
  752. err = jvmInjector.checkReleaseFuncSymAfterChange()
  753. if err != nil {
  754. fmt.Println(err)
  755. if len(jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode) == 5 {
  756. err = restoreOriginalInstructions(pid, originFuncEnterAddr, jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode)
  757. if err != nil {
  758. fmt.Println(err)
  759. return err
  760. }
  761. }
  762. }
  763. // 恢复执行
  764. if err = syscall.PtraceDetach(pid); err != nil {
  765. fmt.Printf("ptrace DETACH: %v", err)
  766. return err
  767. }
  768. return nil
  769. }