{"id":54247,"date":"2019-12-21T00:00:00","date_gmt":"2019-12-20T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/v-poiskah-ld_preload"},"modified":"2020-02-18T14:02:14","modified_gmt":"2020-02-18T11:02:14","slug":"v-poiskah-ld_preload","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/v-poiskah-ld_preload","title":{"rendered":"Alla ricerca di LD_PRELOAD","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u042d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u0431\u044b\u043b\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 2014-\u043c \u0433\u043e\u0434\u0443, \u043d\u043e \u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u043f\u0430\u043b \u043f\u043e\u0434 \u0440\u0435\u043f\u0440\u0435\u0441\u0441\u0438\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435 \u0438 \u043e\u043d\u0430 \u043d\u0435 \u0443\u0432\u0438\u0434\u0435\u043b\u0430 \u0441\u0432\u0435\u0442. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430 \u044f \u043f\u0440\u043e \u043d\u0435\u0451 \u0437\u0430\u0431\u044b\u043b, \u0430 \u0441\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0448\u0451\u043b \u0432 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u0430\u0445. \u0414\u0443\u043c\u0430\u043b \u0431\u044b\u043b\u043e \u0443\u0434\u0430\u043b\u0438\u0442\u044c, \u043d\u043e \u0430\u0432\u043e\u0441\u044c \u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u0441\u044f.<\/p>\n<p><img decoding=\"async\" alt=\"\u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 LD_PRELOAD\" src=\"\/wp-content\/uploads\/2019\/12\/a9526ab700e21c7684a4d372f9af02af.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0412 \u043e\u0431\u0449\u0435\u043c, \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043f\u044f\u0442\u043d\u0438\u0447\u043d\u043e\u0435 \u0430\u0434\u043c\u0438\u043d\u0441\u043a\u043e\u0435 \u0447\u0442\u0438\u0432\u043e \u043d\u0430 \u0442\u0435\u043c\u0443 \u043f\u043e\u0438\u0441\u043a\u0430 \u00ab\u0432\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e\u00bb <i>LD_PRELOAD<\/i>.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>1. \u041d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043e\u0442\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u0434\u043b\u044f \u0442\u0435\u0445, \u043a\u0442\u043e \u043d\u0435 \u0437\u043d\u0430\u043a\u043e\u043c \u0441 \u0437\u0430\u043c\u0435\u0449\u0435\u043d\u0438\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0439<\/h2>\n<p>\n\u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u043c \u043c\u043e\u0436\u043d\u043e \u0441\u0440\u0430\u0437\u0443 \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u0442\u044c \u043a <b>\u043f.2<\/b>.<\/p>\n<p>\u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043a\u043b\u0430\u0441\u0441\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u0438\u043c\u0435\u0440\u0430:<\/p>\n<pre><code class=\"cpp\">#include &lt;stdio.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;time.h&gt;\n\nint main()\n{\n  srand (time(NULL));\n  for(int i=0; i&lt;5; i++){\n    printf (\"%dn\", rand()%100);\n  }\n}\n<\/code><\/pre>\n<p>\n\u041a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u0443\u0435\u043c \u0431\u0435\u0437 \u043a\u0430\u043a\u0438\u0445-\u043b\u0438\u0431\u043e \u0444\u043b\u0430\u0433\u043e\u0432:<\/p>\n<pre><code class=\"plaintext\">$ gcc .\/ld_rand.c -o ld_rand\n<\/code><\/pre>\n<p>\n\u0418, \u043e\u0436\u0438\u0434\u0430\u0435\u043c\u043e, \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u043c 5 \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u044b\u0445 \u0447\u0438\u0441\u0435\u043b \u043c\u0435\u043d\u044c\u0448\u0435 100:<\/p>\n<pre><code class=\"plaintext\">$ .\/ld_rand\n53\n93\n48\n57\n20\n<\/code><\/pre>\n<p>\n\u041d\u043e \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u043d\u0435\u0442 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b, \u0430 \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0443\u0436\u043d\u043e.<\/p>\n<p>\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0441\u0432\u043e\u044e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0443 \u0441 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u043c \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u043e\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440:<\/p>\n<pre><code class=\"cpp\">int rand(){\n  return 42;\n}\n<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">$ gcc -shared -fPIC .\/o_rand.c -o ld_rand.so\n<\/code><\/pre>\n<p>\n\u0418 \u0442\u0435\u043f\u0435\u0440\u044c \u043d\u0430\u0448 \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u044b\u0439 \u0432\u044b\u0431\u043e\u0440 \u0432\u043f\u043e\u043b\u043d\u0435 \u043f\u0440\u0435\u0434\u0441\u043a\u0430\u0437\u0443\u0435\u043c:<\/p>\n<pre><code class=\"plaintext\"># LD_PRELOAD=$PWD\/ld_rand.so .\/ld_rand\n42\n42\n42\n42\n42\n<\/code><\/pre>\n<p>\n\u042d\u0442\u043e\u0442 \u0442\u0440\u044e\u043a \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0435\u0449\u0451 \u0431\u043e\u043b\u0435\u0435 \u0432\u043f\u0435\u0447\u0430\u0442\u043b\u044f\u044e\u0449\u0438\u043c, \u0435\u0441\u043b\u0438 \u043c\u044b \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u044d\u043a\u0441\u043f\u043e\u0440\u0442\u0438\u0440\u0443\u0435\u043c \u043d\u0430\u0448\u0443 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0443 \u0447\u0435\u0440\u0435\u0437 <\/p>\n<pre><code class=\"plaintext\">$ export LD_PRELOAD=$PWD\/ld_rand.so\n<\/code><\/pre>\n<p>\n\u0438\u043b\u0438 \u043f\u0440\u0435\u0434\u0432\u0430\u0440\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c<\/p>\n<pre><code class=\"plaintext\"># echo \"$PWD\/ld_rand.so\" &gt; \/etc\/ld.so.preload\n<\/code><\/pre>\n<p>\n\u0430 \u0437\u0430\u0442\u0435\u043c \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043c \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443 \u0432 \u043e\u0431\u044b\u0447\u043d\u043e\u043c \u0440\u0435\u0436\u0438\u043c\u0435. \u041c\u044b \u043d\u0435 \u0438\u0437\u043c\u0435\u043d\u0438\u043b\u0438 \u043d\u0438 \u0441\u0442\u0440\u043e\u0447\u043a\u0438 \u0432 \u043a\u043e\u0434\u0435 \u0441\u0430\u043c\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b, \u043d\u043e \u0435\u0451 \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0442\u0435\u043f\u0435\u0440\u044c \u0437\u0430\u0432\u0438\u0441\u0438\u0442 \u043e\u0442 \u043a\u0440\u043e\u0448\u0435\u0447\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0432 \u043d\u0430\u0448\u0435\u0439 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435. \u0411\u043e\u043b\u0435\u0435 \u0442\u043e\u0433\u043e, \u043d\u0430 \u043c\u043e\u043c\u0435\u043d\u0442 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u0444\u0430\u043b\u044c\u0448\u0438\u0432\u044b\u0439 <i>rand<\/i> \u0434\u0430\u0436\u0435 \u043d\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043e\u0432\u0430\u043b.<\/p>\n<p>\u0427\u0442\u043e \u0436\u0435 \u0437\u0430\u0441\u0442\u0430\u0432\u0438\u043b\u043e \u043d\u0430\u0448\u0443 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u0434\u0434\u0435\u043b\u044c\u043d\u044b\u0439 <i>rand<\/i>? \u0420\u0430\u0437\u0431\u0435\u0440\u0435\u043c \u043f\u043e \u0448\u0430\u0433\u0430\u043c.<br \/>\n\u041a\u043e\u0433\u0434\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f, \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u044e\u0442\u0441\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435. \u041c\u044b \u043c\u043e\u0436\u0435\u043c \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u0438\u0445 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f <i>ldd<\/i>:<\/p>\n<pre><code class=\"plaintext\"># ldd .\/ld_rand\n        linux-vdso.so.1 (0x00007ffc8b1f3000)\n        libc.so.6 =&gt; \/lib\/x86_64-linux-gnu\/libc.so.6 (0x00007fe3da8af000)\n        \/lib64\/ld-linux-x86-64.so.2 (0x00007fe3daa7e000)\n<\/code><\/pre>\n<p>\n\u042d\u0442\u043e\u0442 \u0441\u043f\u0438\u0441\u043e\u043a \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0440\u0430\u0437\u043b\u0438\u0447\u0435\u043d \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 OS, \u043d\u043e \u0442\u0430\u043c \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u0434\u043e\u043b\u0436\u0435\u043d \u0431\u044b\u0442\u044c \u0444\u0430\u0439\u043b <i>libc.so<\/i>. \u0418\u043c\u0435\u043d\u043d\u043e \u044d\u0442\u0430 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0435 \u0432\u044b\u0437\u043e\u0432\u044b \u0438 \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0442\u0430\u043a\u0438\u0435 \u043a\u0430\u043a <i>open<\/i>, <i>malloc<\/i>, <i>printf<\/i> \u0438 \u0442. \u0434. \u041d\u0430\u0448 <i>rand<\/i> \u0442\u0430\u043a\u0436\u0435 \u0432\u0445\u043e\u0434\u0438\u0442 \u0432 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e. \u0423\u0431\u0435\u0434\u0438\u043c\u0441\u044f \u0432 \u044d\u0442\u043e\u043c:<\/p>\n<pre><code class=\"plaintext\"># nm -D \/lib\/x86_64-linux-gnu\/libc.so.6 | grep \" rand$\"\n000000000003aef0 T rand\n<\/code><\/pre>\n<p>\n\u041f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043d\u0435 \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u0441\u044f \u043b\u0438 \u043d\u0430\u0431\u043e\u0440 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 <i>LD_PRELOAD<\/i><\/p>\n<pre><code class=\"plaintext\"># LD_PRELOAD=$PWD\/ld_rand.so ldd .\/ld_rand\n        linux-vdso.so.1 (0x00007ffea52ae000)\n        \/scripts\/c\/ldpreload\/ld_rand.so (0x00007f690d3f9000)\n        libc.so.6 =&gt; \/lib\/x86_64-linux-gnu\/libc.so.6 (0x00007f690d230000)\n        \/lib64\/ld-linux-x86-64.so.2 (0x00007f690d405000)\n<\/code><\/pre>\n<p>\n\u041e\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u0430\u044f \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u0430\u044f <i>LD_PRELOAD<\/i> \u0437\u0430\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c\u0441\u044f \u043d\u0430\u0448\u0443 <i>ld_rand.so<\/i> \u0434\u0430\u0436\u0435, \u043d\u0435 \u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u0441\u0430\u043c\u0430 \u0435\u0451 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442. \u0418, \u0442\u0430\u043a \u043a\u0430\u043a \u043d\u0430\u0448\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f <i>\u00abrand\u00bb<\/i> \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442\u0441\u044f \u0440\u0430\u043d\u044c\u0448\u0435 \u0447\u0435\u043c <i>rand<\/i> \u043e\u0442 <i>libc.so<\/i>, \u0442\u043e \u043e\u043d\u0430 \u0438 \u043f\u0440\u0430\u0432\u0438\u0442 \u0431\u0430\u043b\u043e\u043c.<\/p>\n<p>Ok, \u0437\u0430\u043c\u0435\u043d\u0438\u0442\u044c \u0440\u043e\u0434\u043d\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u043d\u0430\u043c \u0443\u0434\u0430\u043b\u043e\u0441\u044c, \u043d\u043e \u043a\u0430\u043a \u0431\u044b \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u0438 \u0435\u0451 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u043b\u0441\u044f \u0438 \u043d\u0435\u043a\u0438\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0434\u043e\u0431\u0430\u0432\u0438\u043b\u0438\u0441\u044c. \u041c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u0435\u043c \u043d\u0430\u0448 \u0440\u0430\u043d\u0434\u043e\u043c:<\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n#include &lt;dlfcn.h&gt;\n#include &lt;stdio.h&gt;\n \ntypedef int (*orig_rand_f_type)(void);\n \nint rand()\n{\n  \/* \u0412\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c \u043d\u0435\u043a\u0438\u0439 \u043a\u043e\u0434 *\/\n  printf(\"Evil injected coden\");\n  \n  orig_rand_f_type orig_rand;\n  orig_rand = (orig_rand_f_type)dlsym(RTLD_NEXT,\"rand\");\n  return orig_rand();\n}\n<\/code><\/pre>\n<p>\n\u0417\u0434\u0435\u0441\u044c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043d\u0430\u0448\u0435\u0439 \u00ab\u0434\u043e\u0431\u0430\u0432\u043a\u0438\u00bb \u043c\u044b \u043b\u0438\u0448\u044c \u043f\u0435\u0447\u0430\u0442\u0430\u0435\u043c \u043e\u0434\u043d\u0443 \u0441\u0442\u0440\u043e\u043a\u0443 \u0442\u0435\u043a\u0441\u0442\u0430, \u043f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u0451\u043c \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0438\u0441\u0445\u043e\u0434\u043d\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044f <i>rand<\/i>. \u0414\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u0430 \u044d\u0442\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043d\u0430\u043c \u043f\u043e\u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f <i>dlsym<\/i> \u2014 \u044d\u0442\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 <i>libdl<\/i>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043d\u0430\u0439\u0434\u0435\u0442 \u043d\u0430\u0448 <i>rand<\/i> \u0432 \u0441\u0442\u0435\u043a\u0435 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a. \u041f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u043c\u044b \u0432\u044b\u0437\u043e\u0432\u0435\u043c \u044d\u0442\u0443 \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u0438 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0438\u043c \u0435\u0451 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435. \u0421\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c <i>&#171;-ldl&#187;<\/i> \u043f\u0440\u0438 \u0441\u0431\u043e\u0440\u043a\u0435:<\/p>\n<pre><code class=\"plaintext\">$ gcc -ldl -shared -fPIC .\/o_rand_evil.c -o ld_rand_evil.so\n<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">$ LD_PRELOAD=$PWD\/ld_rand_evil.so .\/ld_rand\nEvil injected code\n66\nEvil injected code\n28\nEvil injected code\n93\nEvil injected code\n93\nEvil injected code\n95\n<\/code><\/pre>\n<p>\n\u0418 \u043d\u0430\u0448\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u00ab\u0440\u043e\u0434\u043d\u043e\u0439\u00bb <i>rand<\/i>, \u043f\u0440\u0435\u0434\u0432\u0430\u0440\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u043d\u0438\u0432 \u043d\u0435\u043a\u0438\u0435 \u043d\u0435\u043f\u043e\u0442\u0440\u0435\u0431\u043d\u044b\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f.<\/p>\n<h2>2. \u041c\u0443\u043a\u0438 \u043f\u043e\u0438\u0441\u043a\u0430<\/h2>\n<p>\n\u0417\u043d\u0430\u044f \u043e \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0443\u0433\u0440\u043e\u0437\u0435, \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0442\u044c, \u0447\u0442\u043e <i>preload<\/i> \u0431\u044b\u043b \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d. \u041f\u043e\u043d\u044f\u0442\u043d\u043e, \u0447\u0442\u043e \u043b\u0443\u0447\u0448\u0438\u0439 \u0441\u043f\u043e\u0441\u043e\u0431 \u0434\u0435\u0442\u0435\u043a\u0442\u0438\u043d\u0433\u0430 \u2014 \u0437\u0430\u043f\u0438\u0445\u043d\u0443\u0442\u044c \u0435\u0433\u043e \u0432 \u044f\u0434\u0440\u043e, \u043d\u043e \u043c\u0435\u043d\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043b\u0438 \u0438\u043c\u0435\u043d\u043d\u043e \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u044b \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u0432 \u044e\u0437\u0435\u0440\u0441\u043f\u044d\u0439\u0441\u0435. <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u043f\u0430\u0440\u0430\u043c\u0438 \u043f\u043e\u0439\u0434\u0443\u0442 \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0438 \u0438\u0445 \u043e\u043f\u0440\u043e\u0432\u0435\u0440\u0436\u0435\u043d\u0438\u0435.<\/p>\n<h2>2.1. \u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043f\u0440\u043e\u0441\u0442\u043e\u0433\u043e<\/h2>\n<p>\n\u041a\u0430\u043a \u0433\u043e\u0432\u043e\u0440\u0438\u043b\u043e\u0441\u044c \u0440\u0430\u043d\u0435\u0435, \u0443\u043a\u0430\u0437\u0430\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u0443\u044e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0443 \u043c\u043e\u0436\u043d\u043e \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u043e\u0439 <i>LD_PRELOAD<\/i> \u0438\u043b\u0438 \u043f\u0440\u043e\u043f\u0438\u0441\u0430\u0432 \u0435\u0451 \u0432 \u0444\u0430\u0439\u043b\u0435 <i>\/etc\/ld.so.preload<\/i>. \u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0434\u0432\u0430 \u043f\u0440\u043e\u0441\u0442\u0435\u0439\u0448\u0438\u0445 \u0434\u0435\u0442\u0435\u043a\u0442\u043e\u0440\u0430. <\/p>\n<p>\u041f\u0435\u0440\u0432\u044b\u0439 \u2014 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u043e\u0439 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f:<\/p>\n<pre><code class=\"cpp\">#include &lt;stdio.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;fcntl.h&gt;\n\nint main()\n{\n  char*  pGetenv = getenv(\"LD_PRELOAD\");\n  pGetenv != NULL ?\n    printf(\"LD_PRELOAD (getenv) [+]n\"):\n    printf(\"LD_PRELOAD (getenv) [-]n\");\n}\n<\/code><\/pre>\n<p>\n\u0412\u0442\u043e\u0440\u043e\u0439 \u2014 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u044f \u0444\u0430\u0439\u043b\u0430:<\/p>\n<pre><code class=\"cpp\">#include &lt;stdio.h&gt;\n#include &lt;fcntl.h&gt;\n\nint main()\n{\n  open(\"\/etc\/ld.so.preload\", O_RDONLY) != -1 ?\n    printf(\"LD_PRELOAD (open) [+]n\"):\n    printf(\"LD_PRELOAD (open) [-]n\");\n}\n<\/code><\/pre>\n<p>\n\u041f\u043e\u0434\u0433\u0440\u0443\u0437\u0438\u043c \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438:<\/p>\n<pre><code class=\"plaintext\">$ export LD_PRELOAD=$PWD\/ld_rand.so\n$ echo \"$PWD\/ld_rand.so\" &gt; \/etc\/ld.so.preload\n\n$ .\/detect_base_getenv\nLD_PRELOAD (getenv) [+]\n$ .\/detect_base_open\nLD_PRELOAD (open) [+]\n<\/code><\/pre>\n<p>\n\u0417\u0434\u0435\u0441\u044c \u0438 \u0434\u0430\u043b\u0435\u0435 [+] \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043d\u0430 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0435 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435. <br \/>\n\u0421\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, [-] \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442 \u043e\u0431\u0445\u043e\u0434 \u0434\u0435\u0442\u0435\u043a\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f.<\/p>\n<p>\u041d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0436\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0435\u043d\u0435\u043d \u0442\u0430\u043a\u043e\u0439 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0442\u0435\u043b\u044c? \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0437\u0430\u0439\u043c\u0451\u043c\u0441\u044f \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u043e\u0439 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f:<\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n#include &lt;stdio.h&gt;\n#include &lt;string.h&gt;\n#include &lt;dlfcn.h&gt;\n\nchar* (*orig_getenv)(const char *) = NULL;\nchar* getenv(const char *name)\n{\n    if(!orig_getenv) orig_getenv = dlsym(RTLD_NEXT, \"getenv\");\n    if(strcmp(name, \"LD_PRELOAD\") == 0) return NULL;\n    return orig_getenv(name);\n}\n<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">$ gcc -shared -fpic -ldl .\/ld_undetect_getenv.c -o .\/ld_undetect_getenv.so\n$ LD_PRELOAD=.\/ld_undetect_getenv.so .\/detect_base_getenv\nLD_PRELOAD (getenv) [-]\n<\/code><\/pre>\n<p>\n\u0410\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u043e \u0438\u0437\u0431\u0430\u0432\u043b\u044f\u0435\u043c\u0441\u044f \u0438 \u043e\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 <i>open<\/i>:<\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n#include &lt;string.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;dlfcn.h&gt;\n#include &lt;errno.h&gt;\n\nint (*orig_open)(const char*, int oflag) = NULL;\n\nint open(const char *path, int oflag, ...)\n{\n    char real_path[256];\n    if(!orig_open) orig_open = dlsym(RTLD_NEXT, \"open\");\n    realpath(path, real_path);\n    if(strcmp(real_path, \"\/etc\/ld.so.preload\") == 0){\n        errno = ENOENT;\n        return -1;\n    }\n    return orig_open(path, oflag);\n}\n<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">$ gcc -shared -fpic -ldl .\/ld_undetect_open.c -o .\/ld_undetect_open.so\n$ LD_PRELOAD=.\/ld_undetect_open.so .\/detect_base_open\nLD_PRELOAD (open) [-]\n<\/code><\/pre>\n<p>\n\u0414\u0430, \u0437\u0434\u0435\u0441\u044c \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u044b \u0434\u0440\u0443\u0433\u0438\u0435 \u0441\u043f\u043e\u0441\u043e\u0431\u044b \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0444\u0430\u0439\u043b\u0443, \u0442\u0430\u043a\u0438\u0435 \u043a\u0430\u043a, <i>open64<\/i>, <i>stat<\/i> \u0438 \u0442.\u0434., \u043d\u043e, \u043f\u043e \u0441\u0443\u0442\u0438, \u0434\u043b\u044f \u0438\u0445 \u043e\u0431\u043c\u0430\u043d\u0430 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b \u0442\u0435 \u0436\u0435 5-10 \u0441\u0442\u0440\u043e\u043a \u043a\u043e\u0434\u0430.<\/p>\n<h2>2.2. \u0414\u0432\u0438\u0433\u0430\u0435\u043c\u0441\u044f \u0434\u0430\u043b\u044c\u0448\u0435<\/h2>\n<p>\n\u0412\u044b\u0448\u0435 \u043c\u044b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b\u0438 <i>getenv()<\/i> \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f <i>LD_PRELOAD<\/i>, \u043d\u043e \u0435\u0441\u0442\u044c \u0436\u0435 \u0438 \u0431\u043e\u043b\u0435\u0435 \u00ab\u043d\u0438\u0437\u043a\u043e\u0443\u0440\u043e\u0432\u043d\u0435\u0432\u044b\u0439\u00bb \u0441\u043f\u043e\u0441\u043e\u0431 \u0434\u043e\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0434\u043e <i>ENV<\/i>-\u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445. \u041d\u0435 \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0440\u043e\u043c\u0435\u0436\u0443\u0442\u043e\u0447\u043d\u044b\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0430 \u043e\u0431\u0440\u0430\u0442\u0438\u043c\u0441\u044f \u043a \u043c\u0430\u0441\u0441\u0438\u0432\u0443 <i>**environ<\/i>, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0445\u0440\u0430\u043d\u0438\u0442\u0441\u044f \u043a\u043e\u043f\u0438\u044f \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f:<\/p>\n<pre><code class=\"cpp\">#include &lt;stdio.h&gt;\n#include &lt;string.h&gt;\n\nextern char **environ;\nint main(int argc, char **argv) {\n  int i;\n  char env[] = \"LD_PRELOAD\";\n  if (environ != NULL)\n    for (i = 0; environ[i] != NULL; i++)\n    {\n      char * pch;\n      pch = strstr(environ[i],env);\n      if(pch != NULL)\n      {\n        printf(\"LD_PRELOAD (**environ) [+]n\");\n        return 0;\n      }\n    }\n  printf(\"LD_PRELOAD (**environ) [-]n\");\n  return 0;\n}\n<\/code><\/pre>\n<p>\n\u0422\u0430\u043a \u043a\u0430\u043a \u0437\u0434\u0435\u0441\u044c \u043c\u044b \u0447\u0438\u0442\u0430\u0435\u043c \u0434\u0430\u043d\u043d\u044b\u0435 \u043d\u0430\u043f\u0440\u044f\u043c\u0443\u044e \u0438\u0437 \u043f\u0430\u043c\u044f\u0442\u0438, \u0442\u043e \u0442\u0430\u043a\u043e\u0439 \u0432\u044b\u0437\u043e\u0432 \u043d\u0435\u043b\u044c\u0437\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u0442\u044c, \u0438 \u043d\u0430\u0448 <i>undetect_getenv<\/i> \u0443\u0436\u0435 \u043d\u0435 \u043c\u0435\u0448\u0430\u0435\u0442 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0432\u0442\u043e\u0440\u0436\u0435\u043d\u0438\u0435.<\/p>\n<pre><code class=\"plaintext\">$ LD_PRELOAD=.\/ld_undetect_getenv.so .\/detect_environ\nLD_PRELOAD (**environ) [+]\n<\/code><\/pre>\n<p>\n\u041a\u0430\u0437\u0430\u043b\u043e\u0441\u044c \u0431\u044b \u043d\u0430 \u044d\u0442\u043e\u043c \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0440\u0435\u0448\u0435\u043d\u0430? \u0412\u0441\u0451 \u0435\u0449\u0451 \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f.<\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e \u043a\u0430\u043a \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u0430, \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u043e\u0439 <i>LD_PRELOAD<\/i> \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u0443\u0436\u0435 \u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u0432\u0437\u043b\u043e\u043c\u0449\u0438\u043a\u0430\u043c, \u0442\u043e \u0435\u0441\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u0441\u0447\u0438\u0442\u0430\u0442\u044c \u0435\u0451 \u0438 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0434\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u0430\u043a\u0438\u0445-\u043b\u0438\u0431\u043e \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0439. \u041a\u043e\u043d\u0435\u0447\u043d\u043e, \u043f\u0440\u0430\u0432\u0438\u0442\u044c \u043c\u0430\u0441\u0441\u0438\u0432 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438, \u043a\u0430\u043a \u043c\u0438\u043d\u0438\u043c\u0443\u043c, \u043f\u043b\u043e\u0445\u043e\u0439 \u0441\u0442\u0438\u043b\u044c \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f, \u043d\u043e \u0440\u0430\u0437\u0432\u0435 \u044d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0442\u043e\u0433\u043e, \u043a\u0442\u043e \u0438 \u0442\u0430\u043a \u043d\u0435 \u043e\u0441\u043e\u0431\u043e \u0436\u0435\u043b\u0430\u0435\u0442 \u043d\u0430\u043c \u0434\u043e\u0431\u0440\u0430?<\/p>\n<p>\u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u0441\u0432\u043e\u044e \u0444\u0435\u0439\u043a\u043e\u0432\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e <i>init()<\/i>, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u043c \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0439 <i>LD_PRELOAD<\/i> \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0442\u044c \u0435\u0451 \u043d\u0430\u0448\u0435\u043c\u0443 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0443:<\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n#include &lt;stdio.h&gt;\n#include &lt;string.h&gt;\n#include &lt;unistd.h&gt;\n#include &lt;dlfcn.h&gt;\n#include &lt;stdlib.h&gt;\n\nextern char **environ;\nchar *evil_env;\nint (*orig_execve)(const char *path, char *const argv[], char *const envp[]) = NULL;\n\n\n\/\/ \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0444\u0435\u0439\u043a\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e init\n\/\/ \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u0443\u0434\u0435\u0442 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043f\u0440\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b\n\/\/ \u0434\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u0430\u043a\u0438\u0445-\u043b\u0438\u0431\u043e \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0439\n\nvoid evil_init()\n{\n  \/\/ \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u043c \u0442\u0435\u043a\u0443\u0449\u0435\u0435 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 LD_PRELOAD\n  static const char *ldpreload = \"LD_PRELOAD\";\n  int len = strlen(getenv(ldpreload));\n  evil_env = (char*) malloc(len+1);\n  strcpy(evil_env, getenv(ldpreload));\n\n  int i;\n  char env[] = \"LD_PRELOAD\";\n  if (environ != NULL)\n    for (i = 0; environ[i] != NULL; i++) {\n      char * pch;\n      pch = strstr(environ[i],env);\n      if(pch != NULL) {\n        \/\/ \u0418\u0437\u0431\u0430\u0432\u043b\u044f\u0435\u043c\u0441\u044f \u043e\u0442 \u0442\u0435\u043a\u0443\u0449\u0435\u0433\u043e LD_PRELOAD\n        unsetenv(env);\n        break;\n      }\n    }\n}\n\nint execve(const char *path, char *const argv[], char *const envp[])\n{\n  int i = 0, j = 0, k = -1, ret = 0;\n  char** new_env;\n  if(!orig_execve) orig_execve = dlsym(RTLD_NEXT,\"execve\");\n\n  \/\/ \u041f\u0440\u043e\u0432\u0435\u0440\u044f\u043c \u043d\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442 \u043b\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 LD_PRELOAD\n  for(i = 0; envp[i]; i++){\n    if(strstr(envp[i], \"LD_PRELOAD\")) k = i;\n  }\n  \/\/ \u0415\u0441\u043b\u0438 LD_PRELOAD \u043d\u0435 \u0431\u044b\u043b\u043e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043e \u0434\u043e \u043d\u0430\u0441, \u0442\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0435\u0433\u043e\n  if(k == -1){\n    k = i;\n    i++;\n  }\n  \/\/ \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043d\u043e\u0432\u043e\u0435 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0435\n  new_env = (char**) malloc((i+1)*sizeof(char*));\n\n  \/\/ \u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0441\u0442\u0430\u0440\u043e\u0435 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0435, \u0437\u0430 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435\u043c LD_PRELOAD\n  for(j = 0; j &lt; i; j++) {\n    \/\/ \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u0438\u043b\u0438 \u0441\u043e\u0437\u0434\u0430\u0451\u043c LD_PRELOAD\n    if(j == k) {\n      new_env[j] = (char*) malloc(256);\n      strcpy(new_env[j], \"LD_PRELOAD=\");\n      strcat(new_env[j], evil_env);\n    }\n    else new_env[j] = (char*) envp[j];\n  }\n  new_env[i] = NULL;\n  ret = orig_execve(path, argv, new_env);\n  free(new_env[k]);\n  free(new_env);\n  return ret;\n}\n<\/code><\/pre>\n<p>\n\u0412\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c, \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c:<\/p>\n<pre><code class=\"plaintext\">$ gcc -shared -fpic -ldl -Wl,-init,evil_init  .\/ld_undetect_environ.c -o .\/ld_undetect_environ.so\n$ LD_PRELOAD=.\/ld_undetect_environ.so .\/detect_environ\nLD_PRELOAD (**environ) [-]\n<\/code><\/pre>\n<p><\/p>\n<h2>2.3. \/proc\/self\/<\/h2>\n<p>\n\u041e\u0434\u043d\u0430\u043a\u043e, \u043f\u0430\u043c\u044f\u0442\u044c \u2014 \u044d\u0442\u043e \u043d\u0435 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u043c\u0435\u0441\u0442\u043e, \u0433\u0434\u0435 \u043c\u043e\u0436\u043d\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0442\u044c \u043f\u043e\u0434\u043c\u0435\u043d\u0443 <i>LD_PRELOAD<\/i>, \u0435\u0441\u0442\u044c \u0436\u0435 \u0435\u0449\u0451 \u0438 <i>\/proc\/<\/i>. \u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043e\u0447\u0435\u0432\u0438\u0434\u043d\u043e\u0433\u043e <i>\/proc\/{PID}\/environ<\/i>.<\/p>\n<p>\u041d\u0430 \u0441\u0430\u043c\u043e\u043c \u0434\u0435\u043b\u0435 \u0435\u0441\u0442\u044c \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0430\u043b\u044c\u043d\u043e\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0434\u043b\u044f <i>undetect&#8217;\u0430<\/i> <i>**environ<\/i> \u0438 <i>\/proc\/self\/environ<\/i>. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0432 \u00ab\u043d\u0435\u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e\u043c\u00bb \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0438 <i>unsetenv(env)<\/i>.<\/p>\n<p><b class=\"spoiler_title\">\u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442<\/b><\/p>\n<pre><code class=\"cpp\">void evil_init()\n{\n  \/\/ \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u043c \u0442\u0435\u043a\u0443\u0449\u0435\u0435 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 LD_PRELOAD\n  static const char *ldpreload = \"LD_PRELOAD\";\n  int len = strlen(getenv(ldpreload));\n  evil_env = (char*) malloc(len+1);\n  strcpy(evil_env, getenv(ldpreload));\n \n  int i;\n  char env[] = \"LD_PRELOAD\";\n  if (environ != NULL)\n    for (i = 0; environ[i] != NULL; i++) {\n      char * pch;\n      pch = strstr(environ[i],env);\n      if(pch != NULL) {\n        \/\/ \u0418\u0437\u0431\u0430\u0432\u043b\u044f\u0435\u043c\u0441\u044f \u043e\u0442 \u0442\u0435\u043a\u0443\u0449\u0435\u0433\u043e LD_PRELOAD \n        \/\/unsetenv(env);\n        \/\/ \u0412\u043c\u0435\u0441\u0442\u043e unset \u043f\u0440\u043e\u0441\u0442\u043e \u043e\u0431\u043d\u0443\u043b\u0438\u043c \u043d\u0430\u0448\u0443 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u0443\u044e\n        for(int j = 0; environ[i][j] != ' '; j++) environ[i][j] = ' ';\n        break;\n      }\n    }\n}\n<\/code><\/pre>\n<pre><code class=\"plaintext\">$ gcc -shared -fpic -ldl -Wl,-init,evil_init  .\/ld_undetect_environ_2.c -o .\/ld_undetect_environ_2.so\n$ (LD_PRELOAD=.\/ld_undetect_environ_2.so cat \/proc\/self\/environ; echo) | tr \" 00\" \"n\" | grep -F LD_PRELOAD\n$\n<\/code><\/pre>\n<p>\u041d\u043e \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c, \u0447\u0442\u043e \u043c\u044b \u0435\u0433\u043e \u043d\u0435 \u043d\u0430\u0448\u043b\u0438 \u0438 <i>\/proc\/self\/environ<\/i> \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 \u00ab\u043f\u0440\u043e\u0431\u043b\u0435\u043c\u043d\u044b\u0435\u00bb \u0434\u0430\u043d\u043d\u044b\u0435.<\/p>\n<p>\u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u043e\u043f\u0440\u043e\u0431\u0443\u0435\u043c \u0441 \u043d\u0430\u0448\u0435\u0439 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u00ab\u043c\u0430\u0441\u043a\u0438\u0440\u043e\u0432\u043a\u043e\u0439\u00bb:<\/p>\n<pre><code class=\"plaintext\">$ (LD_PRELOAD=.\/ld_undetect_environ.so cat \/proc\/self\/environ; echo) | tr \" 00\" \"n\" | grep -F LD_PRELOAD\nLD_PRELOAD=.\/ld_undetect_environ.so\n<\/code><\/pre>\n<p>\n<i>cat<\/i> \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u0434\u043b\u044f \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u044f \u0444\u0430\u0439\u043b\u0430 \u0432\u0441\u0451 \u0442\u043e\u0442 \u0436\u0435 <i>open()<\/i>, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0441\u0445\u043e\u0434\u043d\u043e \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e \u0443\u0436\u0435 \u0434\u0435\u043b\u0430\u043b\u043e\u0441\u044c \u0432 \u043f.2.1, \u043d\u043e \u0442\u0435\u043f\u0435\u0440\u044c \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b, \u043a\u0443\u0434\u0430 \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f \u0438\u0441\u0442\u0438\u043d\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0431\u0435\u0437 \u0441\u0442\u0440\u043e\u043a \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0438\u0445 <i>LD_PRELOAD<\/i>.<\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n#include &lt;dlfcn.h&gt;\n\n#include &lt;stdlib.h&gt;\n#include &lt;stdio.h&gt;\n#include &lt;string.h&gt;\n#include &lt;fcntl.h&gt;\n#include &lt;sys\/stat.h&gt;\n#include &lt;unistd.h&gt;\n#include &lt;limits.h&gt;\n#include &lt;errno.h&gt;\n\n#define BUFFER_SIZE 256\n\nint (*orig_open)(const char*, int oflag) = NULL;\nchar *soname = \"fakememory_preload.so\";\n\nchar *sstrstr(char *str, const char *sub)\n{\n  int i, found;\n  char *ptr;\n  found = 0;\n  for(ptr = str; *ptr != ' '; ptr++) {\n    found = 1;\n    for(i = 0; found == 1 &amp;&amp; sub[i] != ' '; i++){\n      if(sub[i] != ptr[i]) found = 0;\n    }\n    if(found == 1)\n      break;\n  }\n  if(found == 0)\n    return NULL;\n  return ptr + i;\n}\n\nvoid fakeMaps(char *original_path, char *fake_path, char *pattern)\n{\n  int fd;\n  char buffer[BUFFER_SIZE];\n  int bytes = -1;\n  int wbytes = -1;\n  int k = 0;\n\n  pid_t pid = getpid();\n\n  int fh;\n  if ((fh=orig_open(fake_path,O_CREAT|O_WRONLY))==-1) {\n    printf(\"LD: Cannot open write-file [%s] (%d) (%s)n\", fake_path, errno, strerror(errno));\n    exit (42);\n  }\n  if((fd=orig_open(original_path, O_RDONLY))==-1) {\n    printf(\"LD: Cannot open read-file.n\");\n    exit(42);\n  }\n  do\n  {\n    char t = 0;\n    bytes = read(fd, &amp;t, 1);\n    buffer[k++] = t;\n    \/\/printf(\"%c\", t);\n    if(t == ' ') {\n      \/\/printf(\"n\");\n  \n      if(!sstrstr(buffer, \"LD_PRELOAD\")) {\n        if((wbytes = write(fh,buffer,k))==-1) {\n          \/\/printf(\"write errorn\");\n        }\n        else {\n          \/\/printf(\"writed %dn\", wbytes);\n        }\n      }\n      k = 0;\n    }\n  }\n  while(bytes != 0);\n    \n  close(fd);\n  close(fh);\n}\n\nint open(const char *path, int oflag, ...)\n{\n  char real_path[PATH_MAX], proc_path[PATH_MAX], proc_path_0[PATH_MAX];\n  pid_t pid = getpid();\n  if(!orig_open)\n  orig_open = dlsym(RTLD_NEXT, \"open\");\n  realpath(path, real_path);\n  snprintf(proc_path, PATH_MAX, \"\/proc\/%d\/environ\", pid);\n  \n  if(strcmp(real_path, proc_path) == 0) {\n    snprintf(proc_path, PATH_MAX, \"\/tmp\/%d.fakemaps\", pid);\n    realpath(proc_path_0, proc_path);\n    \n    fakeMaps(real_path, proc_path, soname);\n    return orig_open(proc_path, oflag);\n  }\n  return orig_open(path, oflag);\n}\n<\/code><\/pre>\n<p>\n\u0418 \u044d\u0442\u043e\u0442 \u044d\u0442\u0430\u043f \u043f\u0440\u043e\u0439\u0434\u0435\u043d:<\/p>\n<pre><code class=\"plaintext\">$ (LD_PRELOAD=.\/ld_undetect_proc_environ.so cat \/proc\/self\/environ; echo) | tr \" 00\" \"n\" | grep -F LD_PRELOAD\n$\n<\/code><\/pre>\n<p>\n\u0421\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435 \u043e\u0447\u0435\u0432\u0438\u0434\u043d\u043e\u0435 \u043c\u0435\u0441\u0442\u043e \u2014 <i>\/proc\/self\/maps<\/i>. \u0417\u0430\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u043d\u0430 \u043d\u0435\u043c \u043d\u0435\u0442 \u0441\u043c\u044b\u0441\u043b\u0430. \u0420\u0435\u0448\u0435\u043d\u0438\u0435 \u0430\u0431\u0441\u043e\u043b\u044e\u0442\u043d\u043e \u0438\u0434\u0435\u043d\u0442\u0438\u0447\u043d\u043e\u0435 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u043c\u0443: \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0434\u0430\u043d\u043d\u044b\u0435 \u0438\u0437 \u0444\u0430\u0439\u043b\u0430 \u0437\u0430 \u0432\u044b\u0447\u0435\u0442\u043e\u043c \u0441\u0442\u0440\u043e\u043a \u043c\u0435\u0436\u0434\u0443 <i>libc.so<\/i> \u0438 <i>ld.so<\/i>.<\/p>\n<h2>2.4. \u0412\u0430\u0440\u0438\u0430\u043d\u0442 \u043e\u0442 Chokepoint<\/h2>\n<p>\n\u042d\u0442\u043e \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u043c\u043d\u0435 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e \u043f\u043e\u043d\u0440\u0430\u0432\u0438\u043b\u043e\u0441\u044c \u0441\u0432\u043e\u0435\u0439 \u043f\u0440\u043e\u0441\u0442\u043e\u0442\u043e\u0439. \u0421\u0440\u0430\u0432\u043d\u0438\u0432\u0430\u0435\u043c \u0430\u0434\u0440\u0435\u0441\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0445 \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0438\u0437 <i>libc<\/i>, \u0438 \u00abNEXT\u00bb-\u0430\u0434\u0440\u0435\u0441\u0430. <\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n\n#include &lt;stdio.h&gt;\n#include &lt;dlfcn.h&gt;\n\n#define LIBC \"\/lib\/x86_64-linux-gnu\/libc.so.6\"\n\nint main(int argc, char *argv[]) {\n  void *libc = dlopen(LIBC, RTLD_LAZY); \/\/ Open up libc directly\n  char *syscall_open = \"open\";\n  int i;\n  void *(*libc_func)();\n  void *(*next_func)();\n  \n  libc_func = dlsym(libc, syscall_open);\n  next_func = dlsym(RTLD_NEXT, syscall_open);\n  if (libc_func != next_func) {\n    printf(\"LD_PRELOAD (syscall - %s) [+]n\", syscall_open);\n    printf(\"Libc address: %pn\", libc_func);\n    printf(\"Next address: %pn\", next_func);\n  }\n  else {\n    printf(\"LD_PRELOAD (syscall - %s) [-]n\", syscall_open);\n  }\n  return 0;\n}\n<\/code><\/pre>\n<p>\n\u0417\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0443 \u0441 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u043e\u043c <i>\u00abopen()\u00bb<\/i> \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c:<\/p>\n<pre><code class=\"plaintext\">$ export LD_PRELOAD=$PWD\/ld_undetect_open.so\n$ .\/detect_chokepoint\nLD_PRELOAD (syscall - open) [+]\nLibc address: 0x7fa86893b160\nNext address: 0x7fa868a26135\n<\/code><\/pre>\n<p>\n\u041e\u043f\u0440\u043e\u0432\u0435\u0440\u0436\u0435\u043d\u0438\u0435 \u043e\u043a\u0430\u0437\u0430\u043b\u043e\u0441\u044c \u0435\u0449\u0451 \u043f\u0440\u043e\u0449\u0435:<\/p>\n<pre><code class=\"plaintext\">#define _GNU_SOURCE\n#include &lt;stdio.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;string.h&gt;\n#include &lt;dlfcn.h&gt;\n\nextern void * _dl_sym (void *, const char *, void *);\nvoid * dlsym (void * handle, const char * symbol)\n{\n  return _dl_sym (handle, symbol, dlsym);\n}\n<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\"># LD_PRELOAD=.\/ld_undetect_chokepoint.so .\/detect_chokepoint\nLD_PRELOAD (syscall - open) [-]\n<\/code><\/pre>\n<p><\/p>\n<h2>2.5. Syscalls<\/h2>\n<p>\n\u041a\u0430\u0437\u0430\u043b\u043e\u0441\u044c \u0431\u044b \u043d\u0430 \u044d\u0442\u043e\u043c \u0432\u0441\u0451, \u043d\u043e \u0435\u0449\u0451 \u043f\u043e\u0431\u0430\u0440\u0430\u0445\u0442\u0430\u0435\u043c\u0441\u044f. \u0415\u0441\u043b\u0438 \u043c\u044b \u043d\u0430\u043f\u0440\u0430\u0432\u0438\u043c \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u0432\u044b\u0437\u043e\u0432 \u043d\u0430\u043f\u0440\u044f\u043c\u0443\u044e \u043a \u044f\u0434\u0440\u0443, \u0442\u043e \u044d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043e\u0431\u043e\u0439\u0442\u0438 \u0432\u0435\u0441\u044c \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430. \u0420\u0435\u0448\u0435\u043d\u0438\u0435 \u043d\u0438\u0436\u0435, \u0440\u0430\u0437\u0443\u043c\u0435\u0435\u0442\u0441\u044f, \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u043e\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0435 (<i>x86_64<\/i>). \u041f\u043e\u043f\u0440\u043e\u0431\u0443\u0435\u043c \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u044f <i>ld.so.preload<\/i>.<\/p>\n<pre><code class=\"cpp\">#include &lt;stdio.h&gt;\n#include &lt;sys\/stat.h&gt;\n#include &lt;fcntl.h&gt;\n\n#define BUFFER_SIZE 256\n\nint syscall_open(char *path, long oflag)\n{\n    int fd = -1;\n    __asm__ (\n             \"mov $2, %%rax;\" \/\/ Open syscall number\n             \"mov %1, %%rdi;\" \/\/ Address of our string\n             \"mov %2, %%rsi;\" \/\/ Open mode\n             \"mov $0, %%rdx;\" \/\/ No create mode\n             \"syscall;\"       \/\/ Straight to ring0\n             \"mov %%eax, %0;\" \/\/ Returned file descriptor\n             :\"=r\" (fd)\n             :\"m\" (path), \"m\" (oflag)\n             :\"rax\", \"rdi\", \"rsi\", \"rdx\"\n             );\n    return fd;\n }\nint main()\n{\n    syscall_open(\"\/etc\/ld.so.preload\", O_RDONLY) &gt; 0 ?\n      printf(\"LD_PRELOAD (open syscall) [+]n\"):\n      printf(\"LD_PRELOAD (open syscall) [-]n\");\n        \n}\n<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">$ .\/detect_syscall\nLD_PRELOAD (open syscall) [+]\n<\/code><\/pre>\n<p>\n\u0418 \u0434\u0430\u043d\u043d\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u043a\u0430 \u0438\u043c\u0435\u0435\u0442 \u0440\u0435\u0448\u0435\u043d\u0438\u0435. \u0412\u044b\u0434\u0435\u0440\u0436\u043a\u0430 \u0438\u0437 <i>man<\/i>&#8216;\u0430:<\/p>\n<blockquote><p>ptrace \u2014 \u044d\u0442\u043e \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u043e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0435 \u0440\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u043c\u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0443 \u043d\u0430\u0431\u043b\u044e\u0434\u0430\u0442\u044c \u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u0440\u043e\u0442\u0435\u043a\u0430\u043d\u0438\u0435 \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430, \u043f\u0440\u043e\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0442\u044c \u0438 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u0435\u0433\u043e \u0434\u0430\u043d\u043d\u044b\u0435 \u0438 \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u044b. \u041e\u0431\u044b\u0447\u043d\u043e \u044d\u0442\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0442\u043e\u0447\u0435\u043a \u043f\u0440\u0435\u0440\u044b\u0432\u0430\u043d\u0438\u044f \u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435 \u043e\u0442\u043b\u0430\u0434\u043a\u0438 \u0438 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0432\u044b\u0437\u043e\u0432\u043e\u0432.<\/p>\n<p>\u0420\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043c\u043e\u0436\u0435\u0442 \u043d\u0430\u0447\u0430\u0442\u044c \u0442\u0440\u0430\u0441\u0441\u0438\u0440\u043e\u0432\u043a\u0443, \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u0432\u044b\u0437\u0432\u0430\u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u044e fork(2), \u0430 \u0437\u0430\u0442\u0435\u043c \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0439\u0441\u044f \u0434\u043e\u0447\u0435\u0440\u043d\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043c\u043e\u0436\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c PTRACE_TRACEME, \u0437\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u043c (\u043e\u0431\u044b\u0447\u043d\u043e) \u0441\u043b\u0435\u0434\u0443\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 exec(3). \u0421 \u0434\u0440\u0443\u0433\u043e\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b, \u0440\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043c\u043e\u0436\u0435\u0442 \u043d\u0430\u0447\u0430\u0442\u044c \u043e\u0442\u043b\u0430\u0434\u043a\u0443 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 PTRACE_ATTACH.<\/p>\n<p>\u041f\u0440\u0438 \u0442\u0440\u0430\u0441\u0441\u0438\u0440\u043e\u0432\u043a\u0435 \u0434\u043e\u0447\u0435\u0440\u043d\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043e\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043a\u0430\u0436\u0434\u044b\u0439 \u0440\u0430\u0437 \u043f\u0440\u0438 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u0438 \u0441\u0438\u0433\u043d\u0430\u043b\u0430, \u0434\u0430\u0436\u0435 \u0435\u0441\u043b\u0438 \u044d\u0442\u043e\u0442 \u0441\u0438\u0433\u043d\u0430\u043b \u0438\u0433\u043d\u043e\u0440\u0438\u0440\u0443\u0435\u0442\u0441\u044f. (\u0418\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435\u043c \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f SIGKILL, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0439 \u043e\u0431\u044b\u0447\u043d\u044b\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c.) \u0420\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0431\u0443\u0434\u0435\u0442 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d \u043e\u0431 \u044d\u0442\u043e\u043c \u043f\u0440\u0438 \u0432\u044b\u0437\u043e\u0432\u0435 wait(2), \u043f\u043e\u0441\u043b\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043e\u043d \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u043e\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0442\u044c \u0438 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0434\u043e \u0435\u0433\u043e \u0437\u0430\u043f\u0443\u0441\u043a\u0430. \u041f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u0440\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u0435\u0442 \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u043c\u0443 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u0443, \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u043b\u0443\u0447\u0430\u044f\u0445 \u0438\u0433\u043d\u043e\u0440\u0438\u0440\u0443\u044f \u043f\u043e\u0441\u044b\u043b\u0430\u0435\u043c\u044b\u0439 \u0435\u043c\u0443 \u0441\u0438\u0433\u043d\u0430\u043b \u0438\u043b\u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u044f \u0432\u043c\u0435\u0441\u0442\u043e \u044d\u0442\u043e\u0433\u043e \u0434\u0440\u0443\u0433\u043e\u0439 \u0441\u0438\u0433\u043d\u0430\u043b).\n<\/p><\/blockquote>\n<p>\n\u0422\u0435\u043c \u0441\u0430\u043c\u044b\u043c, \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0442\u044c \u043f\u0440\u043e\u0446\u0435\u0441\u0441, \u043e\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044f \u0435\u0433\u043e \u043f\u0435\u0440\u0435\u0434 \u043a\u0430\u0436\u0434\u044b\u043c \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u043c \u0432\u044b\u0437\u043e\u0432\u043e\u043c \u0438, \u043f\u0440\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u043f\u043e\u0442\u043e\u043a \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u043b\u043e\u0432\u0443\u0448\u043a\u0438.<\/p>\n<pre><code class=\"cpp\">#define _GNU_SOURCE\n#include &lt;fcntl.h&gt;\n#include &lt;stdlib.h&gt;\n#include &lt;stdio.h&gt;\n#include &lt;string.h&gt;\n#include &lt;unistd.h&gt;\n#include &lt;errno.h&gt;\n#include &lt;limits.h&gt;\n#include &lt;sys\/ptrace.h&gt;\n#include &lt;sys\/wait.h&gt;\n#include &lt;sys\/reg.h&gt;\n#include &lt;sys\/user.h&gt;\n#include &lt;asm\/unistd.h&gt;\n\n\n#if defined(__x86_64__)\n#define REG_SYSCALL ORIG_RAX\n#define REG_SP rsp\n#define REG_IP rip \n#endif\n\nlong NOHOOK = 0;\n\nlong evil_open(const char *path, long oflag, long cflag) \n{\n    char real_path[PATH_MAX], maps_path[PATH_MAX];\n    long ret;\n    pid_t pid;\n    pid = getpid();\n    realpath(path, real_path);\n    if(strcmp(real_path, \"\/etc\/ld.so.preload\") == 0)\n    {\n        errno = ENOENT;\n        ret = -1;\n    }\n    else\n    {\n        NOHOOK = 1; \/\/ Entering NOHOOK section\n        ret = open(path, oflag, cflag);\n    }\n    \/\/ Exiting NOHOOK section\n    NOHOOK = 0;\n    return ret;\n}\n\nvoid init()\n{\n    pid_t program;\n    \/\/ \u0424\u043e\u0440\u043a\u0430\u0435\u043c \u0434\u043e\u0447\u0435\u0440\u043d\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\n    program = fork();\n    if(program != 0) {\n        int status;\n        long syscall_nr;\n        struct user_regs_struct regs;\n        \/\/ \u041f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u0441\u044f \u043a \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u043c\u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0443\n        if(ptrace(PTRACE_ATTACH, program) != 0) {\n            printf(\"Failed to attach to the program.n\");\n            exit(1);\n        }\n        waitpid(program, &amp;status, 0);\n        \/\/ \u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u043c \u0442\u043e\u043b\u044c\u043a\u043e SYSCALLs\n        ptrace(PTRACE_SETOPTIONS, program, 0, PTRACE_O_TRACESYSGOOD);\n        while(1) {\n            ptrace(PTRACE_SYSCALL, program, 0, 0);\n            waitpid(program, &amp;status, 0);\n            if(WIFEXITED(status) || WIFSIGNALED(status)) break;\n            else if(WIFSTOPPED(status) &amp;&amp; WSTOPSIG(status) == SIGTRAP|0x80) {\n                \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u043d\u043e\u043c\u0435\u0440 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430\n                syscall_nr = ptrace(PTRACE_PEEKUSER, program, sizeof(long)*REG_SYSCALL);\n                if(syscall_nr == __NR_open) {\n                    \/\/ \u0427\u0438\u0442\u0430\u0435\u043c \u0441\u043b\u043e\u0432\u043e \u0438\u0437 \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\n                    NOHOOK = ptrace(PTRACE_PEEKDATA, program, (void*)&amp;NOHOOK);\n                    \/\/ \u041f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u044b\u0437\u043e\u0432\n                    if(!NOHOOK) {\n                        \n                        \/\/ \u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u044b \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\n                        \/\/ \u0432 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u0443\u044e regs \u0440\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u0433\u043e\n                        ptrace(PTRACE_GETREGS, program, 0, &amp;regs);\n                        \/\/ Push return address on the stack\n                        regs.REG_SP -= sizeof(long);\n                        \/\/ \u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0441\u043b\u043e\u0432\u043e \u0432 \u043f\u0430\u043c\u044f\u0442\u044c \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\n                        ptrace(PTRACE_POKEDATA, program, (void*)regs.REG_SP, regs.REG_IP);\n                        \/\/ \u0423\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c RIP \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443 evil_open\n                        regs.REG_IP = (unsigned long) evil_open;\n                        \/\/ \u0417\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u043e\u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\n                        ptrace(PTRACE_SETREGS, program, 0, &amp;regs);\n                    }\n                }\n                ptrace(PTRACE_SYSCALL, program, 0, 0);\n                waitpid(program, &amp;status, 0);\n            }\n        }\n        exit(0);\n    }\n    else {\n        sleep(0);\n    }\n}\n<\/code><\/pre>\n<p>\n\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c:<\/p>\n<pre><code class=\"plaintext\">$ .\/detect_syscall\nLD_PRELOAD (open syscall) [+]\n$ LD_PRELOAD=.\/ld_undetect_syscall.so .\/detect_syscall\nLD_PRELOAD (open syscall) [-]\n<\/code><\/pre>\n<p>\n<b>+0-0=5<\/b><\/p>\n<p>\u041e\u0433\u0440\u043e\u043c\u043d\u043e\u0435 \u0441\u043f\u0430\u0441\u0438\u0431\u043e <\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/haxelion\" rel=\"nofollow\">Charles Hubain<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/chokepoint\" rel=\"nofollow\">Chokepoint<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/users\/valdikss\/\">ValdikSS<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/doegox\" rel=\"nofollow\">Philippe Teuwen<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/stackoverflow.com\/users\/2327517\/derhass\" rel=\"nofollow\"> derhass<\/a><\/noindex><\/p>\n<p>, \u0447\u044c\u0438 \u0441\u0442\u0430\u0442\u044c\u0438, \u0438\u0441\u0445\u043e\u0434\u043d\u0438\u043a\u0438 \u0438 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u0441\u0434\u0435\u043b\u0430\u043b\u0438 \u043d\u0430\u043c\u043d\u043e\u0433\u043e \u0431\u043e\u043b\u044c\u0448\u0435, \u0447\u0435\u043c \u044f, \u0434\u043b\u044f \u0442\u043e\u0433\u043e \u0447\u0442\u043e\u0431\u044b \u044d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c \u0437\u0434\u0435\u0441\u044c.<br \/>\n<br \/>\u0418\u0441\u0442\u043e\u0447\u043d\u0438\u043a: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/479858\/\">habr.com<\/a><\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u042d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u0431\u044b\u043b\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 2014-\u043c \u0433\u043e\u0434\u0443, \u043d\u043e \u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u043f\u0430\u043b \u043f\u043e\u0434 \u0440\u0435\u043f\u0440\u0435\u0441\u0441\u0438\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435 \u0438 \u043e\u043d\u0430 \u043d\u0435 \u0443\u0432\u0438\u0434\u0435\u043b\u0430 \u0441\u0432\u0435\u0442. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430 \u044f \u043f\u0440\u043e \u043d\u0435\u0451 \u0437\u0430\u0431\u044b\u043b, \u0430 \u0441\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0448\u0451\u043b \u0432 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u0430\u0445. \u0414\u0443\u043c\u0430\u043b \u0431\u044b\u043b\u043e \u0443\u0434\u0430\u043b\u0438\u0442\u044c, \u043d\u043e \u0430\u0432\u043e\u0441\u044c \u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u0441\u044f. \u0412 \u043e\u0431\u0449\u0435\u043c, \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043f\u044f\u0442\u043d\u0438\u0447\u043d\u043e\u0435 \u0430\u0434\u043c\u0438\u043d\u0441\u043a\u043e\u0435 \u0447\u0442\u0438\u0432\u043e \u043d\u0430 \u0442\u0435\u043c\u0443 \u043f\u043e\u0438\u0441\u043a\u0430 \u00ab\u0432\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e\u00bb LD_PRELOAD. 1. \u041d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043e\u0442\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u0434\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":54248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-54247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u042d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u0431\u044b\u043b\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 2014-\u043c \u0433\u043e\u0434\u0443, \u043d\u043e \u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u043f\u0430\u043b \u043f\u043e\u0434 \u0440\u0435\u043f\u0440\u0435\u0441\u0441\u0438\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435 \u0438 \u043e\u043d\u0430 \u043d\u0435 \u0443\u0432\u0438\u0434\u0435\u043b\u0430 \u0441\u0432\u0435\u0442. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430 \u044f \u043f\u0440\u043e \u043d\u0435\u0451 \u0437\u0430\u0431\u044b\u043b, \u0430 \u0441\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0448\u0451\u043b \u0432 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u0430\u0445. \u0414\u0443\u043c\u0430\u043b \u0431\u044b\u043b\u043e \u0443\u0434\u0430\u043b\u0438\u0442\u044c, \u043d\u043e \u0430\u0432\u043e\u0441\u044c \u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u0441\u044f. \u0412 \u043e\u0431\u0449\u0435\u043c, \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043f\u044f\u0442\u043d\u0438\u0447\u043d\u043e\u0435 \u0430\u0434\u043c\u0438\u043d\u0441\u043a\u043e\u0435 \u0447\u0442\u0438\u0432\u043e \u043d\u0430 \u0442\u0435\u043c\u0443 \u043f\u043e\u0438\u0441\u043a\u0430 \u00ab\u0432\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e\u00bb LD_PRELOAD. 1. \u041d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043e\u0442\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u0434\u043b\u044f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/v-poiskah-ld_preload\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 LD_PRELOAD | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u042d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u0431\u044b\u043b\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 2014-\u043c \u0433\u043e\u0434\u0443, \u043d\u043e \u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u043f\u0430\u043b \u043f\u043e\u0434 \u0440\u0435\u043f\u0440\u0435\u0441\u0441\u0438\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435 \u0438 \u043e\u043d\u0430 \u043d\u0435 \u0443\u0432\u0438\u0434\u0435\u043b\u0430 \u0441\u0432\u0435\u0442. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430 \u044f \u043f\u0440\u043e \u043d\u0435\u0451 \u0437\u0430\u0431\u044b\u043b, \u0430 \u0441\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0448\u0451\u043b \u0432 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u0430\u0445. \u0414\u0443\u043c\u0430\u043b \u0431\u044b\u043b\u043e \u0443\u0434\u0430\u043b\u0438\u0442\u044c, \u043d\u043e \u0430\u0432\u043e\u0441\u044c \u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u0441\u044f. \u0412 \u043e\u0431\u0449\u0435\u043c, \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043f\u044f\u0442\u043d\u0438\u0447\u043d\u043e\u0435 \u0430\u0434\u043c\u0438\u043d\u0441\u043a\u043e\u0435 \u0447\u0442\u0438\u0432\u043e \u043d\u0430 \u0442\u0435\u043c\u0443 \u043f\u043e\u0438\u0441\u043a\u0430 \u00ab\u0432\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e\u00bb LD_PRELOAD. 1. \u041d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043e\u0442\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u0434\u043b\u044f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/v-poiskah-ld_preload\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-20T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:02:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 LD_PRELOAD | ProHoster","description":"\u042d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u0431\u044b\u043b\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 2014-\u043c \u0433\u043e\u0434\u0443, \u043d\u043e \u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u043f\u0430\u043b \u043f\u043e\u0434 \u0440\u0435\u043f\u0440\u0435\u0441\u0441\u0438\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435 \u0438 \u043e\u043d\u0430 \u043d\u0435 \u0443\u0432\u0438\u0434\u0435\u043b\u0430 \u0441\u0432\u0435\u0442. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430 \u044f \u043f\u0440\u043e \u043d\u0435\u0451 \u0437\u0430\u0431\u044b\u043b, \u0430 \u0441\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0448\u0451\u043b \u0432 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u0430\u0445. \u0414\u0443\u043c\u0430\u043b \u0431\u044b\u043b\u043e \u0443\u0434\u0430\u043b\u0438\u0442\u044c, \u043d\u043e \u0430\u0432\u043e\u0441\u044c \u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u0441\u044f. \u0412 \u043e\u0431\u0449\u0435\u043c, \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043f\u044f\u0442\u043d\u0438\u0447\u043d\u043e\u0435 \u0430\u0434\u043c\u0438\u043d\u0441\u043a\u043e\u0435 \u0447\u0442\u0438\u0432\u043e \u043d\u0430 \u0442\u0435\u043c\u0443 \u043f\u043e\u0438\u0441\u043a\u0430 \u00ab\u0432\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e\u00bb LD_PRELOAD. 1. \u041d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043e\u0442\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u0434\u043b\u044f","canonical_url":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/v-poiskah-ld_preload","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 LD_PRELOAD | ProHoster","og:description":"\u042d\u0442\u0430 \u0437\u0430\u043c\u0435\u0442\u043a\u0430 \u0431\u044b\u043b\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 2014-\u043c \u0433\u043e\u0434\u0443, \u043d\u043e \u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u043f\u0430\u043b \u043f\u043e\u0434 \u0440\u0435\u043f\u0440\u0435\u0441\u0441\u0438\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435 \u0438 \u043e\u043d\u0430 \u043d\u0435 \u0443\u0432\u0438\u0434\u0435\u043b\u0430 \u0441\u0432\u0435\u0442. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430 \u044f \u043f\u0440\u043e \u043d\u0435\u0451 \u0437\u0430\u0431\u044b\u043b, \u0430 \u0441\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0448\u0451\u043b \u0432 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u0430\u0445. \u0414\u0443\u043c\u0430\u043b \u0431\u044b\u043b\u043e \u0443\u0434\u0430\u043b\u0438\u0442\u044c, \u043d\u043e \u0430\u0432\u043e\u0441\u044c \u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u0441\u044f. \u0412 \u043e\u0431\u0449\u0435\u043c, \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043f\u044f\u0442\u043d\u0438\u0447\u043d\u043e\u0435 \u0430\u0434\u043c\u0438\u043d\u0441\u043a\u043e\u0435 \u0447\u0442\u0438\u0432\u043e \u043d\u0430 \u0442\u0435\u043c\u0443 \u043f\u043e\u0438\u0441\u043a\u0430 \u00ab\u0432\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e\u00bb LD_PRELOAD. 1. \u041d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043e\u0442\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u0434\u043b\u044f","og:url":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/v-poiskah-ld_preload","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-20T21:00:00+00:00","article:modified_time":"2020-02-18T11:02:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"54247","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 10:37:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:09:24","updated":"2026-01-24 10:37:23"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/54247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=54247"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/54247\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/54248"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=54247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=54247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=54247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}