f0rb1dd3n / Reptile

LKM Linux rootkit
2.53k stars 571 forks source link

Failed to insmod #91

Open iusearch opened 4 years ago

iusearch commented 4 years ago

Output from strace:

execve("./reptile", ["./reptile"], 0x7fff63796390 /* 22 vars */) = 0
brk(NULL)                               = 0x1abb000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f88e1bdf000
access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=23179, ...}) = 0
mmap(NULL, 23179, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f88e1bd9000
close(3)                                = 0
open("/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`&\2\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=2156240, ...}) = 0
mmap(NULL, 3985920, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f88e15f1000
mprotect(0x7f88e17b4000, 2097152, PROT_NONE) = 0
mmap(0x7f88e19b4000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1c3000) = 0x7f88e19b4000
mmap(0x7f88e19ba000, 16896, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f88e19ba000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f88e1bd8000
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f88e1bd6000
arch_prctl(ARCH_SET_FS, 0x7f88e1bd6740) = 0
mprotect(0x7f88e19b4000, 16384, PROT_READ) = 0
mprotect(0x600000, 4096, PROT_READ)     = 0
mprotect(0x7f88e1be0000, 4096, PROT_READ) = 0
munmap(0x7f88e1bd9000, 23179)           = 0
mmap(NULL, 1826816, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f88e1a18000
init_module(0x7f88e1a18010, 1823624, "") = -1 EINVAL (Invalid argument)
munmap(0x7f88e1a18000, 1826816)         = 0
exit_group(-1)                          = ?
+++ exited with 255 +++

uname -a: Linux xxx 4.19.91-19.1.al7.x86_64 #1 SMP Tue May 26 19:19:43 CST 2020 x86_64 x86_64 x86_64 GNU/Linux