Alex Rivera | Logout

Can gdb make a function pointer point to another location?

Asked 2010-07-17T04:42:52.553
26

I'll explain:

Let's say I'm interested in replacing the rand() function used by a certain application.

So I attach gdb to this process and make it load my custom shared library (which has a customized rand() function):

call (int) dlopen("path_to_library/asdf.so")

This would place the customized rand() function inside the process' memory. However, at this point the symbol rand will still point to the default rand() function. Is there a way to make gdb point the symbol to the new rand() function, forcing the process to use my version?

I must say I'm also not allowed to use the LD_PRELOAD (linux) nor DYLD_INSERT_LIBRARIES (mac os x) methods for this, because they allow code injection only in the beginning of the program execution.

The application that I would like to replace rand(), starts several threads and some of them start new processes, and I'm interested in injecting code on one of these new processes. As I mentioned above, GDB is great for this purpose because it allows code injection into a specific process.

Edit
Report

1 Answer

5

I have a new solution, based on the new original constraints. (I am not deleting my first answer, as others may find it useful.)

I have been doing a bunch of research, and I think it would work with a bit more fiddling.

  1. In your .so rename your replacement rand function, e.g my_rand
  2. Compile everything and load up gdb
  3. Use info functions to find the address of rand in the symbol table
  4. Use dlopen then dlsym to load the function into memory and get its address

    call (int) dlopen("my_rand.so", 1) -> -val-

    call (unsigned int) dlsym(-val-, "my_rand") -> my_rand_addr

  5. -the tricky part- Find the hex code of a jumpq 0x*my_rand_addr* instruction
  6. Use set {int}*rand_addr* = *my_rand_addr* to change symbol table instruction
  7. Continue execution: now whenever rand is called, it will jump to my_rand instead

This is a bit complicated, and very round-about, but I'm pretty sure it would work. The only thing I haven't accomplished yet is creating the jumpq instruction code. Everything up until that point works fine.

answered 2010-07-18T03:20:10.893

Your Answer