Addition of example plugin for library call detection and counting.#79
Open
joshualant wants to merge 5 commits intobeehive-lab:masterfrom
Open
Addition of example plugin for library call detection and counting.#79joshualant wants to merge 5 commits intobeehive-lab:masterfrom
joshualant wants to merge 5 commits intobeehive-lab:masterfrom
Conversation
…imes they are called with one level of depth in an application.
…ded mambo_calloc function to plugin_support.c which uses simple memset() to initialize mambo_alloc'd memory to zero. Unsure if this is an acceptably performant solution or not...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The pull request is for adding an example plugin, showing how you might begin to create an ltrace type tool using MAMBO. It uses libelf to scan the PLT of the application and adds them to a list, checking the untranslated address against the PLT entry. Instructions are added to increment counters in this list when these addresses are hit pre-basic-block. Also contains a placeholder function for scanning the mapped libraries once main is reached, which could be used in order to parse the PLT of the libraries and show library calls within the libraries themselves.