Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

指定so的syscall的过滤 #66

Open
lixioaolong opened this issue Dec 7, 2024 · 3 comments
Open

指定so的syscall的过滤 #66

lixioaolong opened this issue Dec 7, 2024 · 3 comments

Comments

@lixioaolong
Copy link

默认打印的是整个应用的所有系统调用,太多不便于分析

@SeeFlowerX
Copy link
Owner

没有好的思路

@lixioaolong
Copy link
Author

大大有群嘛,一些简单的问题去群里沟通方便一些

@lixioaolong
Copy link
Author

没有好的思路

我们是否可以在so中先找到svc指令所在的父函数,然后对所有的复函数进行拦截?但是这样会有遗漏,比如会漏掉一些自定义的shellcode执行的系统调用

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants