'''
Created on 2013. 3. 11.
@author: perry912
'''
from ctypes import *
# Let's map the Microsoft types to ctypes for clarity
BYTE = c_ubyte
WORD = c_ushort
DWORD = c_ulong
LPBYTE = POINTER(c_ubyte)
LPTSTR = POINTER(c_char)
HANDLE = c_void_p
PVOID = c_void_p
LPVOID = c_void_p
UINT_PTR = c_ulong
SIZE_T = c_ulong
# Constants
DEBUG_PROCESS = 0x00000001
CREATE_NEW_CONSOLE = 0x00000010
PROCESS_ALL_ACCESS = 0x001F0FFF
INFINITE = 0xFFFFFFFF
DBG_CONTINUE = 0x00010002
# Debug event constants
EXCEPTION_DEBUG_EVENT = 0x1
CREATE_THREAD_DEBUG_EVENT = 0x2
CREATE_PROCESS_DEBUG_EVENT = 0x3
EXIT_THREAD_DEBUG_EVENT = 0x4
EXIT_PROCESS_DEBUG_EVENT = 0x5
LOAD_DLL_DEBUG_EVENT = 0x6
UNLOAD_DLL_DEBUG_EVENT = 0x7
OUTPUT_DEBUG_STRING_EVENT = 0x8
RIP_EVENT = 0x9
# debug exception codes.
EXCEPTION_ACCESS_VIOLATION = 0xC0000005
EXCEPTION_BREAKPOINT = 0x80000003
EXCEPTION_GUARD_PAGE = 0x80000001
EXCEPTION_SINGLE_STEP = 0x80000004
# Thread constants for CreateToolhelp32Snapshot()
TH32CS_SNAPHEAPLIST = 0x00000001
TH32CS_SNAPPROCESS = 0x00000002
TH32CS_SNAPTHREAD = 0x00000004
TH32CS_SNAPMODULE = 0x00000008
TH32CS_INHERIT = 0x80000000
TH32CS_SNAPALL = (TH32CS_SNAPHEAPLIST | TH32CS_SNAPPROCESS | TH32CS_SNAPTHREAD | TH32CS_SNAPMODULE)
THREAD_ALL_ACCESS = 0x001F03FF
# Context flags for GetThreadContext()
CONTEXT_FULL = 0x00010007
CONTEXT_DEBUG_REGISTERS = 0x00010010
# Memory permissions
PAGE_EXECUTE_READWRITE = 0x00000040
# Hardware breakpoint conditions
HW_ACCESS = 0x00000003
HW_EXECUTE = 0x00000000
HW_WRITE = 0x00000001
# Memory page permissions, used by VirtualProtect()
PAGE_NOACCESS = 0x00000001
PAGE_READONLY = 0x00000002
PAGE_READWRITE = 0x00000004
PAGE_WRITECOPY = 0x00000008
PAGE_EXECUTE = 0x00000010
PAGE_EXECUTE_READ = 0x00000020
PAGE_EXECUTE_READWRITE = 0x00000040
PAGE_EXECUTE_WRITECOPY = 0x00000080
PAGE_GUARD = 0x00000100
PAGE_NOCACHE = 0x00000200
PAGE_WRITECOMBINE = 0x00000400
# Structures for CreateProcessA() function
# STARTUPINFO describes how to spawn the process
class STARTUPINFO(Structure):
_fields_ = [
("cb", DWORD),
("lpReserved", LPTSTR),
("lpDesktop", LPTSTR),
("lpTitle", LPTSTR),
("dwX", DWORD),
("dwY", DWORD),
("dwXSize", DWORD),
("dwYSize", DWORD),
("dwXCountChars", DWORD),
("dwYCountChars", DWORD),
("dwFillAttribute",DWORD),
("dwFlags", DWORD),
("wShowWindow", WORD),
("cbReserved2", WORD),
("lpReserved2", LPBYTE),
("hStdInput", HANDLE),
("hStdOutput", HANDLE),
("hStdError", HANDLE),
]
# PROCESS_INFORMATION receives its information
# after the target process has been successfully
# started.
class PROCESS_INFORMATION(Structure):
_fields_ = [
("hProcess", HANDLE),
("hThread", HANDLE),
("dwProcessId", DWORD),
("dwThreadId", DWORD),
]
# When the dwDebugEventCode is evaluated
class EXCEPTION_RECORD(Structure):
pass
EXCEPTION_RECORD._fields_ = [
("ExceptionCode", DWORD),
("ExceptionFlags", DWORD),
("ExceptionRecord", POINTER(EXCEPTION_RECORD)),
("ExceptionAddress", PVOID),
("NumberParameters", DWORD),
("ExceptionInformation", UINT_PTR * 15),
]
class _EXCEPTION_RECORD(Structure):
_fields_ = [
("ExceptionCode", DWORD),
("ExceptionFlags", DWORD),
("ExceptionRecord", POINTER(EXCEPTION_RECORD)),
("ExceptionAddress", PVOID),
("NumberParameters", DWORD),
("ExceptionInformation", UINT_PTR * 15),
]
# Exceptions
class EXCEPTION_DEBUG_INFO(Structure):
_fields_ = [
("ExceptionRecord", EXCEPTION_RECORD),
("dwFirstChance", DWORD),
]
# it populates this union appropriately
class DEBUG_EVENT_UNION(Union):
_fields_ = [
("Exception", EXCEPTION_DEBUG_INFO),
# ("CreateThread", CREATE_THREAD_DEBUG_INFO),
# ("CreateProcessInfo", CREATE_PROCESS_DEBUG_INFO),
# ("ExitThread", EXIT_THREAD_DEBUG_INFO),
# ("ExitProcess", EXIT_PROCESS_DEBUG_INFO),
# ("LoadDll", LOAD_DLL_DEBUG_INFO),
# ("UnloadDll", UNLOAD_DLL_DEBUG_INFO),
# ("DebugString", OUTPUT_DEBUG_STRING_INFO),
# ("RipInfo", RIP_INFO),
]
# DEBUG_EVENT describes a debugging event
# that the debugger has trapped
class DEBUG_EVENT(Structure):
_fields_ = [
("dwDebugEventCode", DWORD),
("dwProcessId", DWORD),
("dwThreadId", DWORD),
("u", DEBUG_EVENT_UNION),
]
# Used by the CONTEXT structure
class FLOATING_SAVE_AREA(Structure):
_fields_ = [
("ControlWord", DWORD),
("StatusWord", DWORD),
("TagWord", DWORD),
("ErrorOffset", DWORD),
("ErrorSelector", DWORD),
("DataOffset", DWORD),
("DataSelector", DWORD),
("RegisterArea", BYTE * 80),
("Cr0NpxState", DWORD),
]
# The CONTEXT structure which holds all of the
# register values after a GetThreadContext() call
class CONTEXT(Structure):
_fields_ = [
("ContextFlags", DWORD),
("Dr0", DWORD),
("Dr1", DWORD),
("Dr2", DWORD),
("Dr3", DWORD),
("Dr6", DWORD),
("Dr7", DWORD),
("FloatSave", FLOATING_SAVE_AREA),
("SegGs", DWORD),
("SegFs", DWORD),
("SegEs", DWORD),
("SegDs", DWORD),
("Edi", DWORD),
("Esi", DWORD),
("Ebx", DWORD),
("Edx", DWORD),
("Ecx", DWORD),
("Eax", DWORD),
("Ebp", DWORD),
("Eip", DWORD),
("SegCs", DWORD),
("EFlags", DWORD),
("Esp", DWORD),
("SegSs", DWORD),
("ExtendedRegisters", BYTE * 512),
]
# THREADENTRY32 contains information about a thread
# we use this for enumerating all of the system threads
class THREADENTRY32(Structure):
_fields_ = [
("dwSize", DWORD),
("cntUsage", DWORD),
("th32ThreadID", DWORD),
("th32OwnerProcessID", DWORD),
("tpBasePri", DWORD),
("tpDeltaPri", DWORD),
("dwFlags", DWORD),
]
# Supporting struct for the SYSTEM_INFO_UNION union
class PROC_STRUCT(Structure):
_fields_ = [
("wProcessorArchitecture", WORD),
("wReserved", WORD),
]
# Supporting union for the SYSTEM_INFO struct
class SYSTEM_INFO_UNION(Union):
_fields_ = [
("dwOemId", DWORD),
("sProcStruc", PROC_STRUCT),
]
# SYSTEM_INFO structure is populated when a call to
# kernel32.GetSystemInfo() is made. We use the dwPageSize
# member for size calculations when setting memory breakpoints
class SYSTEM_INFO(Structure):
_fields_ = [
("uSysInfo", SYSTEM_INFO_UNION),
("dwPageSize", DWORD),
("lpMinimumApplicationAddress", LPVOID),
("lpMaximumApplicationAddress", LPVOID),
("dwActiveProcessorMask", DWORD),
("dwNumberOfProcessors", DWORD),
("dwProcessorType", DWORD),
("dwAllocationGranularity", DWORD),
("wProcessorLevel", WORD),
("wProcessorRevision", WORD),
]
# MEMORY_BASIC_INFORMATION contains information about a
# particular region of memory. A call to kernel32.VirtualQuery()
# populates this structure.
class MEMORY_BASIC_INFORMATION(Structure):
_fields_ = [
("BaseAddress", PVOID),
("AllocationBase", PVOID),
("AllocationProtect", DWORD),
("RegionSize", SIZE_T),
("State", DWORD),
("Protect", DWORD),
("Type", DWORD),
]
2013년 3월 11일 월요일
2012년 3월 21일 수요일
2012년 3월 18일 일요일
커널 컴파일 후 에도 grub 메뉴에 추가 되지 않았을 때
커널 컴파일 후 에도 grub 목록에 추가 되지 않았을 때..
혹은 커널 컴파일 후 initrd 이미지가 생성되지 않았을때 해결방법
initrd 이미지가 생성이 되지 않으면
update-grub 혹은 update-grub2를 실행해도
/boot/grub/grub.cfg에 추가 되지 않는다.
이것 때문에.. 5일 정도 삽질함.. ㅡㅡ;; 검색해도 계속 딴 말만 나오고..
됐고!!
이렇게 해서 해결했다. 물론 환경에 따라 달라질 수 도 있습니다~
관련 스크립트 수동 복사
$sudo cp /usr/share/kernel-package/examples/etc/kernel/postinst.d/initramfs /etc/kernel/postinst.d/
$sudo cp /usr/share/kernel-package/examples/etc/kernel/postrm.d/initramfs /etc/kernel/postrm.d
$sudo update-initramfs -c -k 2.6.32.58
: 2.6.32.58은 /lib/modules/ 에 있는 폴더명 대로 해주거나 위 명령어 오류시 해당 위치에 모듈이 없다고 메시지가 나오니 참조하면 된다.
/boot/grub/grub.cfg 에서 컴파일된 버전이 menuentry에 추가 되어 있는지 확인한다.
아래 링크 참조
http://ubuntu.or.kr/viewtopic.php?p=52374
2012년 3월 4일 일요일
ext2 파일 시스템 만들고 마운트[펌글]
http://www.joinc.co.kr/modules/moniwiki/wiki.php/ext2
아래링크에서 dd 명령어로 덤프 이미지 만들때 크기를 50k로 해서 생성한다.
그렇지 않으면 fat파일시스템으로 만들때 오류!
http://www.troot.co.kr/tc/2067
리눅스 파일 시스템
http://www.ibm.com/developerworks/kr/library/l-linux-filesystem/
파일 시스템 분석
http://secuworld.blogspot.com/2009/05/unix-%EB%AA%85%EB%A0%B9%EC%96%B4%EB%A1%9C-%ED%95%98%EB%93%9C-%EC%9D%B4%EB%AF%B8%EC%A7%80-%EC%88%98%EB%8F%99%EC%9C%BC%EB%A1%9C-%EC%83%9D%EC%84%B1%ED%95%98%EA%B8%B0.html
아래는 위 링크 복사한 자료입니다.
아래링크에서 dd 명령어로 덤프 이미지 만들때 크기를 50k로 해서 생성한다.
그렇지 않으면 fat파일시스템으로 만들때 오류!
http://www.troot.co.kr/tc/2067
리눅스 파일 시스템
http://www.ibm.com/developerworks/kr/library/l-linux-filesystem/
파일 시스템 분석
http://secuworld.blogspot.com/2009/05/unix-%EB%AA%85%EB%A0%B9%EC%96%B4%EB%A1%9C-%ED%95%98%EB%93%9C-%EC%9D%B4%EB%AF%B8%EC%A7%80-%EC%88%98%EB%8F%99%EC%9C%BC%EB%A1%9C-%EC%83%9D%EC%84%B1%ED%95%98%EA%B8%B0.html
아래는 위 링크 복사한 자료입니다.
Unix 명령어로 하드 이미지 수동으로 생성하기.
파일 시스템(FAT, NTFS, EXT, etc,.) 공부 할 때 실제로 하드디스크를 물리적으로 PC 에 연결하여 일일이 포멧(Format) 하고 덤프뜬 이미지를 사용한다면 여간 번거러운 일이 안일것이다.
Unix 계열의 OS 에서는 쉽게 장치 이미지를 생성하여 마운트(Mount) 시킬 수 있다. 이번 글에서는 이러한 이미지를 만드는데 필요한 일련의 명령어를 통해 얻을 수 있다.
그리고 아래에서 사용되는 fsstat, istat 등의 프로그램을 얻기 위해서는 sleutkit 을 설치하여야 하는데, http://www.sleuthkit.org/ 여기에 Unix 용과 Windows 설치 파일이 존제하며 Unix 용으로 mac os x 에서 컴파일이 잘 된다.
// 우선 dd 를 이용하여 만들고 싶은 크기만큼의 Null 파일을 생성한다.
Unix 계열의 OS 에서는 쉽게 장치 이미지를 생성하여 마운트(Mount) 시킬 수 있다. 이번 글에서는 이러한 이미지를 만드는데 필요한 일련의 명령어를 통해 얻을 수 있다.
그리고 아래에서 사용되는 fsstat, istat 등의 프로그램을 얻기 위해서는 sleutkit 을 설치하여야 하는데, http://www.sleuthkit.org/ 여기에 Unix 용과 Windows 설치 파일이 존제하며 Unix 용으로 mac os x 에서 컴파일이 잘 된다.
// 우선 dd 를 이용하여 만들고 싶은 크기만큼의 Null 파일을 생성한다.
// 이렇게 생성된 파일은 단지 Null 로만 채워진 파일이다.
$> dd if=/dev/zero of=hard.dd bs=1024 count=20000
$> dd if=/dev/zero of=hard.dd bs=1024 count=20000
// 따라서 이런 파일을 장치로 인식시켜야 하는데,
// 먼저 현재 시스템이 사용중인 장치이름을 아래의 명령어로 확인한다.
$> losetup -a
// 내가 사용할 장치 즉, 비어있는 장치이름을 아래 명령어로도 얻을 수 있다.
$> losetup -f
// 이렇게 장치명이 결정되었으면
// 먼저 현재 시스템이 사용중인 장치이름을 아래의 명령어로 확인한다.
$> losetup -a
// 내가 사용할 장치 즉, 비어있는 장치이름을 아래 명령어로도 얻을 수 있다.
$> losetup -f
// 이렇게 장치명이 결정되었으면
// 현재 Null 파일인 파일을 디바이스로 인식시키기 위한 포멧으로 변경한다.
$> losetup /dev/loop5 hard.dd
// 그리고 여기서는 ext2 형식으로 파일 시스템을 포멧(format) 한다.
$> losetup /dev/loop5 hard.dd
// 그리고 여기서는 ext2 형식으로 파일 시스템을 포멧(format) 한다.
// 다른 파일시스템을 원할 경우 지원하는 다른 형식의 파일시스템으로 포멧 하면된다.
$> mkfs.ext2 /dev/loop5
// 임의의 폴더를 생성하고
$> mkdir hard
// 이미지 파일을 임의의 폴더에 마운트(mount) 한다.
$> mount -o loop hard.dd ./hard
// 이렇게 준비가 모두 끝났다면, 하드 디스크의 정보를 출력하여 확인한다.
$> fsstat /dev/loop5
// 이제부터는 해당 파일 시스템을 분석하면 된다.
$> mkfs.ext2 /dev/loop5
// 임의의 폴더를 생성하고
$> mkdir hard
// 이미지 파일을 임의의 폴더에 마운트(mount) 한다.
$> mount -o loop hard.dd ./hard
// 이렇게 준비가 모두 끝났다면, 하드 디스크의 정보를 출력하여 확인한다.
$> fsstat /dev/loop5
// 이제부터는 해당 파일 시스템을 분석하면 된다.
// 위에서 포멧한 ext2 파일 시스템의 Root Directory Node 정보를 아래와 같은 명령어를 사용하여 출력할 수 있다.
$> istat hard.dd 2
$> istat hard.dd 2
2012년 2월 18일 토요일
Go Lang 설치
Go를 설치하기 위한 다른 프로그램 설치는 아래 링크에서..
http://code.google.com/p/golang-korea/wiki/GoInstall
Go를 다운 받은 후 인스톨 및 리눅스 환경설정은 아래 링크에서..
http://ggogun.tistory.com/category/Programming
http://code.google.com/p/golang-korea/wiki/GoInstall
Go를 다운 받은 후 인스톨 및 리눅스 환경설정은 아래 링크에서..
http://ggogun.tistory.com/category/Programming
피드 구독하기:
글 (Atom)