Re: How to hack syscall-table, in kernel 2.6+ ?

From: Alan Cox
Date: Tue Aug 14 2012 - 08:35:44 EST


> I have already tried extracting the address of the "sys_call_table"
> from "System.Map"; however, I am still not able to replace the
> function-pointers with mine.

Correct.

> Trying to do gives me page-faults, apparently meaning that the
> syscall-table memory area is read-only.

Correct.

The kernel is specifically designed to stop such uses by rootkits and
trojans and other malware.

If you are trying to patch the system call table you are doing something
wrong. What are you actually trying to achieve ?
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/