Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 14:32:00 execve("/usr/bin/nc", ["nc", "-t", "-l", "12345"], [/* 29 vars */]) = 0
- 14:32:00 brk(0) = 0x1322000
- 14:32:00 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa177fb4000
- 14:32:00 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
- 14:32:00 open("/etc/ld.so.cache", O_RDONLY) = 3
- 14:32:00 fstat(3, {st_mode=S_IFREG|0644, st_size=64223, ...}) = 0
- 14:32:00 mmap(NULL, 64223, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7fa177fa4000
- 14:32:00 close(3) = 0
- 14:32:00 open("/lib64/libglib-2.0.so.0", O_RDONLY) = 3
- 14:32:00 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0pe\341\3325\0\0\0"..., 832) = 832
- 14:32:00 fstat(3, {st_mode=S_IFREG|0755, st_size=1068832, ...}) = 0
- 14:32:00 mmap(0x35dae00000, 3163832, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x35dae00000
- 14:32:00 mprotect(0x35daf03000, 2097152, PROT_NONE) = 0
- 14:32:00 mmap(0x35db103000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x103000) = 0x35db103000
- 14:32:00 mmap(0x35db104000, 1720, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x35db104000
- 14:32:00 close(3) = 0
- 14:32:00 open("/lib64/libc.so.6", O_RDONLY) = 3
- 14:32:00 read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\356\241\3315\0\0\0"..., 832) = 832
- 14:32:00 fstat(3, {st_mode=S_IFREG|0755, st_size=1926800, ...}) = 0
- 14:32:00 mmap(0x35d9a00000, 3750152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x35d9a00000
- 14:32:00 mprotect(0x35d9b8b000, 2093056, PROT_NONE) = 0
- 14:32:00 mmap(0x35d9d8a000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x18a000) = 0x35d9d8a000
- 14:32:00 mmap(0x35d9d8f000, 18696, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x35d9d8f000
- 14:32:00 close(3) = 0
- 14:32:00 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa177fa3000
- 14:32:00 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa177fa2000
- 14:32:00 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa177fa1000
- 14:32:00 arch_prctl(ARCH_SET_FS, 0x7fa177fa2700) = 0
- 14:32:00 mprotect(0x35d9d8a000, 16384, PROT_READ) = 0
- 14:32:00 mprotect(0x35d941f000, 4096, PROT_READ) = 0
- 14:32:00 munmap(0x7fa177fa4000, 64223) = 0
- 14:32:00 socket(PF_NETLINK, SOCK_RAW, 0) = 3
- 14:32:00 bind(3, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
- 14:32:00 getsockname(3, {sa_family=AF_NETLINK, pid=5885, groups=00000000}, [12]) = 0
- 14:32:00 gettimeofday({1404239520, 407057}, NULL) = 0
- 14:32:00 sendto(3, "\24\0\0\0\26\0\1\3\240\376\262S\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
- 14:32:00 recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"0\0\0\0\24\0\2\0\240\376\262S\375\26\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 108
- 14:32:00 recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\240\376\262S\375\26\0\0\n\200\200\376\1\0\0\0\24\0\1\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
- 14:32:00 recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\240\376\262S\375\26\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
- 14:32:00 close(3) = 0
- 14:32:00 brk(0) = 0x1322000
- 14:32:00 brk(0x1343000) = 0x1343000
- 14:32:00 socket(PF_INET, SOCK_STREAM, IPPROTO_TCP) = 3
- 14:32:00 setsockopt(3, SOL_SOCKET, SO_REUSEADDR, [1], 4) = 0
- 14:32:00 bind(3, {sa_family=AF_INET, sin_port=htons(12345), sin_addr=inet_addr("0.0.0.0")}, 16) = 0
- 14:32:00 listen(3, 1) = 0
- 14:32:00 accept(3, {sa_family=AF_INET, sin_port=htons(59119), sin_addr=inet_addr("127.0.0.1")}, [16]) = 4
- 14:32:26 poll([{fd=4, events=POLLIN}, {fd=0, events=POLLIN}], 2, -1) = 1 ([{fd=0, revents=POLLIN}])
- 14:32:26 read(0, "", 2048) = 0
- 14:32:26 shutdown(4, 1 /* send */) = 0
- 14:32:26 poll([{fd=4, events=POLLIN}, {fd=-1}], 2, -1) = 1 ([{fd=4, revents=POLLIN|POLLHUP}])
- 14:32:26 read(4, "", 2048) = 0
- 14:32:26 shutdown(4, 0 /* receive */) = -1 ENOTCONN (Transport endpoint is not connected)
- 14:32:26 close(4) = 0
- 14:32:26 close(3) = 0
- 14:32:26 close(3) = -1 EBADF (Bad file descriptor)
- 14:32:26 exit_group(0) = ?
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement