[prev in list] [next in list] [prev in thread] [next in thread] 

List:       focus-linux
Subject:    Re: How to make a core dump?
From:       Alexander Morozov <zmoro () mail ! ru>
Date:       2004-09-05 18:19:21
Message-ID: 20040905221921.2d4d8b93.zmoro () mail ! ru
[Download RAW message or body]

Thanks everybody for answering,
so the simliest way found is to use gdb command "gcore".  It dumps
core by copying memory and making all nessesary headers
itself, not relying on kernel ability to dump core.

By the way, the malcious program was injected through a poorly written
php-script and, as i guess from data obtained using gdb memory-dumping
functions, was cracking DES-encrypted passwords, provided by
attacker's server.

With best regards, A. Morozov.




[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic