Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ======================================
- hook execve called
- executing prog:
- ffffff8002400c40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- ffffff8002400c50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- executing /app0/eboot_dec.bin
- argc 1
- ffffff8046e00000 2f 61 70 70 30 2f 65 62 6f 6f 74 5f 64 65 63 2e |/app0/eboot_dec.|
- ffffff8046e00010 62 69 6e 00 00 00 00 00 00 00 00 00 00 00 00 00 |bin.............|
- ffffff8046e00020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- td[38] = fffffe0029b2da00:
- fffffe0029b2da58 07 00 00 00 00 00 00 38 00 00 00 00 00 1c 00 40 |.......8.......@|
- fffffe0029b2da68 00 ff 00 00 00 00 00 80 00 00 00 00 00 00 00 00 |................|
- fffffe0029b2da78 00 00 00 00 00 00 00 00 00 00 00 80 00 40 00 40 |.............@.@|
- fffffe0029b2da88 00 00 00 00 00 00 00 80 00 00 00 00 00 00 00 08 |................|
- fffffe0029b2da98 00 40 ff ff 00 00 00 f0 00 00 00 00 00 00 00 00 |.@..............|
- fffffe0029b2daa8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029b2dab8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029b2dac8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029b2dad8 00 00 00 00 00 00 00 00 |................|
- has hito payload? 0
- header 9010102464c457f
- eboot.bin redirecting to our test_elf_imgact
- section
- { type: 1 offset: 4000 vaddr: 400000 memsz: 91ac58 filesz: 91ac58 prot: 5 }
- [INFO] first map len: 91c000
- [INFO] got to a map_insert
- { off: 4000 start: 400000 end: d1c000 prot: 5}
- section
- { type: 1 offset: 920000 vaddr: d1c000 memsz: 10726c filesz: 7a490 prot: 3 }
- [INFO] first map len: 78000
- [INFO] got to a map_insert
- { off: 920000 start: d1c000 end: d94000 prot: 3}
- [INFO] mapping anonymous page copy_len: 2490 madrr: d94000 maplen: 90000
- [INFO] got to a map_insert
- { off: 0 start: d94000 end: e24000 prot: 7}
- [INFO] mapped
- [INFO] vm_imgact_map_page fffffe0064f79880
- fffffe004f570000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe004f570010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- [INFO] off = 998000 - 998000
- [INFO] copyout 0 d94000 2490
- [INFO] copyout
- [INFO] vm_imgact_unmap_page
- [INFO] protecting page
- [INFO] protecting page done
- test returned: 0(0)
- imgp->entry_addr: 82e393d58
- imgp->base: 82e393d58
- imgp->100: 800000000000ff00
- imgp->108: 0
- imgp->110: 0
- imgp->118: 4000400080000000
- imgp->120: 8000000000000000
- imgp->128: 800000000000000
- imgp->130: f0000000ffff4000
- imgp->138: 0
- imgp->140: 0
- imgp->148: 0
- imgp->150: 0
- imgp->158: 0
- imgp->160: 0
- imgp->168: 0
- imgp->170: 0
- imgp->178: 0
- imgp->180: d1c000
- imgp->188: 40
- imgp->190: 7
- imgp->198: 131b50
- imgp->1a0: cb0
- imgp->1a8: 7
- imgp->1b0: 99a4a0
- imgp->1b8: 132800
- imgp->1c0: 8
- imgp->1c8: accca0
- imgp->1d0: 6c
- imgp->1d8: fffffe003b2c5fe0
- imgp->1e0: ffffff8046e00000
- imgp->1e8: 0
- imgp->1f0: a24000
- imgp->1f8: 186b100000001
- imgp->200: 0
- imgp->208: fe10
- imgp->210: 186b00000000c
- imgp->218: 0
- imgp->220: 0
- imgp->228: 186af0000000c
- imgp->230: 0
- imgp->238: 0
- imgp->PT_SCE_DYNLIBDATA_segment_index: 7
- imgp->LOOS_DYNLIB_SEGMENT: 99a4a0
- imgp->PT_SCE_DYNLIBDATA: 132800
- imgp->1c8: accca0
- proc 1: fffffe003a842400
- dinamic?: d1c000
- 0000000000d1c000 40 00 00 00 00 00 00 00 4f 52 42 49 01 00 00 00 |@.......ORBI....|
- 0000000000d1c010 81 00 70 01 00 00 00 00 00 00 00 00 00 00 00 00 |..p.............|
- fffffe003af17000 48 31 ed 48 83 ec 18 48 c7 c0 57 02 00 00 0f 05 |H1.H...H..W.....|
- fffffe003af17010 72 1f 48 c7 c0 57 02 00 00 49 89 fc 48 89 e6 48 |r.H..W...I..H..H|
- fffffe003af17020 89 e2 48 83 c2 08 e8 dd 0a 00 00 5e 4c 89 e7 ff |..H........^L...|
- fffffe003af17030 e0 0f 0b 90 90 90 90 90 30 c0 48 83 7f 10 00 74 |........0.H....t|
- fffffe003af17040 0a 83 bf 18 01 00 00 ff 0f 95 c0 0f b6 c0 c3 66 |...............f|
- fffffe003af17050 0f 1f 84 00 00 00 00 00 55 48 89 e5 53 50 48 89 |........UH..SPH.|
- fffffe003af17060 fb f6 05 54 |...T............|
- self_imgact_img[0xf0]
- fffffe0029a860f0 07 00 00 00 00 00 00 38 00 00 00 00 00 00 00 20 |.......8....... |
- fffffe0029a86100 00 ff 00 00 00 00 00 80 00 00 00 00 00 00 00 00 |................|
- fffffe0029a86110 00 00 00 00 00 00 00 00 00 00 00 80 00 40 00 40 |.............@.@|
- fffffe0029a86120 00 00 00 00 00 00 00 80 00 00 00 00 00 00 00 08 |................|
- fffffe0029a86130 00 40 ff ff 00 00 00 f0 00 00 00 00 00 00 00 00 |.@..............|
- fffffe0029a86140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029a86150 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029a86160 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029a86170 00 00 00 00 00 00 00 00 |................|
- setting regs for /app0/eboot_dec.bin rip(should be libkernel->start): 82e393d58
- kernel entry
- ffffff8002400c40 48 31 ed 48 83 ec 18 48 c7 c0 57 02 00 00 0f 05 |H1.H...H..W.....|
- ffffff8002400c50 72 1f 48 c7 c0 57 02 00 00 49 89 fc 48 89 e6 48 |r.H..W...I..H..H|
- stack_base 7efccadc8:
- found? 0
- Loading custom module
- after NDINIT v2
- namei returned: 0
- exec_check_permissions: 0, opened: 1
- exec_map_first_page: 0 fffffe004f988000
- binvp->v_object: fffffe003b2c5980
- after vm_object_reference
- fffffe004f988000 7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 |.ELF............|
- fffffe004f988010 03 00 3e 00 01 00 00 00 e0 14 00 00 00 00 00 00 |..>.............|
- fffffe004f988020 40 00 00 00 00 00 00 00 a8 8c 00 00 00 00 00 00 |@...............|
- fffffe004f988030 00 00 00 00 40 00 38 00 08 00 40 00 10 00 0f 00 |....@.8...@.....|
- fffffe004f988040 06 00 00 00 05 00 00 00 40 00 00 00 00 00 00 00 |........@.......|
- fffffe004f988050 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 |@.......@.......|
- fffffe004f988060 c0 01 00 00 00 00 00 00 c0 01 00 00 00 00 00 00 |................|
- fffffe004f988070 08 00 00 00 00 00 00 00 03 00 00 00 04 00 00 00 |................|
- fffffe004f988080 00 02 00 00 00 00 00 00 00 02 00 00 00 00 00 00 |................|
- fffffe004f988090 00 02 00 00 00 00 00 00 1c 00 00 00 00 00 00 00 |................|
- fffffe004f9880a0 1c 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 |................|
- fffffe004f9880b0 01 00 00 00 05 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe004f9880c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe004f9880d0 78 77 00 00 00 00 00 00 78 77 00 00 00 00 00 00 |xw......xw......|
- fffffe004f9880e0 00 00 20 00 00 00 00 00 01 00 00 00 06 00 00 00 |.. .............|
- fffffe004f9880f0 f0 7e 00 00 00 00 00 00 f0 7e 20 00 00 00 00 00 |.~.......~ .....|
- Elf64_Ehdr {
- unsigned char e_ident[EI_NIDENT]; /* File identification. */
- Elf64_Half e_type = 3; /* File type. */
- Elf64_Half e_machine = 62; /* Machine architecture. */
- Elf64_Word e_version = 1; /* ELF format version. */
- Elf64_Addr e_entry = 14e0; /* Entry point. */
- Elf64_Off e_phoff = 40; /* Program header file offset. */
- Elf64_Off e_shoff; /* Section header file offset. */
- Elf64_Word e_flags; /* Architecture-specific flags. */
- Elf64_Half e_ehsize; /* Size of ELF header in bytes. */
- Elf64_Half e_phentsize; /* Size of program header entry. */
- Elf64_Half e_phnum; /* Number of program header entries. */
- Elf64_Half e_shentsize; /* Size of section header entry. */
- Elf64_Half e_shnum; /* Number of section header entries. */
- Elf64_Half e_shstrndx = f; /* Section name strings section. */
- }
- fffffe004f988040 06 00 00 00 05 00 00 00 40 00 00 00 00 00 00 00 |........@.......|
- fffffe004f988050 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 |@.......@.......|
- fffffe004f988060 c0 01 00 00 00 00 00 00 c0 01 00 00 00 00 00 00 |................|
- fffffe004f988070 08 00 00 00 00 00 00 00 03 00 00 00 04 00 00 00 |................|
- section
- { type: 6 offset: 40 vaddr: 40 memsz: 1c0 filesz: 1c0 prot: 5 }
- section
- { type: 3 offset: 200 vaddr: 200 memsz: 1c filesz: 1c prot: 1 }
- section
- { type: 1 offset: 0 vaddr: 0 memsz: 7778 filesz: 7778 prot: 5 }
- rebasing to 2009e8000
- [INFO] first map len: 8000
- [INFO] got to a map_insert
- { off: 0 start: 2009e8000 end: 2009f0000 prot: 5}
- section
- { type: 1 offset: 7ef0 vaddr: 200befef0 memsz: c058 filesz: 110 prot: 3 }
- [INFO] first map len: 4000
- [INFO] got to a map_insert
- { off: 4000 start: 200bec000 end: 200bf0000 prot: 3}
- [INFO] mapping anonymous page copy_len: 0 madrr: 200bf0000 maplen: c000
- [INFO] got to a map_insert
- { off: 0 start: 200bf0000 end: 200bfc000 prot: 7}
- [INFO] mapped
- [INFO] protecting page
- [INFO] protecting page done
- section
- { type: 2 offset: 7ef0 vaddr: 200befef0 memsz: 110 filesz: 110 prot: 3 }
- section
- { type: 1685382480 offset: 7398 vaddr: 2009ef398 memsz: 9c filesz: 9c prot: 1 }
- section
- { type: 1685382481 offset: 0 vaddr: 2009e8000 memsz: 0 filesz: 0 prot: 7 }
- section
- { type: 1685382482 offset: 7ef0 vaddr: 200befef0 memsz: 110 filesz: 110 prot: 1 }
- fffffe0029868400 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868410 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868420 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868430 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868440 1b 00 00 00 01 00 00 00 02 00 00 00 00 00 00 00 |................|
- fffffe0029868450 00 02 00 00 00 00 00 00 00 02 00 00 00 00 00 00 |................|
- fffffe0029868460 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868470 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868480 23 00 00 00 05 00 00 00 02 00 00 00 00 00 00 00 |#...............|
- fffffe0029868490 20 02 00 00 00 00 00 00 20 02 00 00 00 00 00 00 | ....... .......|
- fffffe00298684a0 10 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 |................|
- fffffe00298684b0 08 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 |................|
- fffffe00298684c0 29 00 00 00 0b 00 00 00 02 00 00 00 00 00 00 00 |)...............|
- fffffe00298684d0 30 02 00 00 00 00 00 00 30 02 00 00 00 00 00 00 |0.......0.......|
- fffffe00298684e0 18 00 00 00 00 00 00 00 04 00 00 00 01 00 00 00 |................|
- fffffe00298684f0 08 00 00 00 00 00 00 00 18 00 00 00 00 00 00 00 |................|
- fffffe0029868500 31 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 |1...............|
- fffffe0029868510 48 02 00 00 00 00 00 00 48 02 00 00 00 00 00 00 |H.......H.......|
- fffffe0029868520 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868530 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868540 39 00 00 00 04 00 00 00 02 00 00 00 00 00 00 00 |9...............|
- fffffe0029868550 50 02 00 00 00 00 00 00 50 02 00 00 00 00 00 00 |P.......P.......|
- fffffe0029868560 90 12 00 00 00 00 00 00 03 00 00 00 00 00 00 00 |................|
- fffffe0029868570 08 00 00 00 00 00 00 00 18 00 00 00 00 00 00 00 |................|
- fffffe0029868580 43 00 00 00 01 00 00 00 06 00 00 00 00 00 00 00 |C...............|
- fffffe0029868590 e0 14 00 00 00 00 00 00 e0 14 00 00 00 00 00 00 |................|
- fffffe00298685a0 61 1b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |a...............|
- fffffe00298685b0 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe00298685c0 49 00 00 00 01 00 00 00 02 00 00 00 00 00 00 00 |I...............|
- fffffe00298685d0 50 30 00 00 00 00 00 00 50 30 00 00 00 00 00 00 |P0......P0......|
- fffffe00298685e0 47 43 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |GC..............|
- fffffe00298685f0 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868600 51 00 00 00 01 00 00 00 02 00 00 00 00 00 00 00 |Q...............|
- fffffe0029868610 98 73 00 00 00 00 00 00 98 73 00 00 00 00 00 00 |.s.......s......|
- fffffe0029868620 9c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868630 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868640 5f 00 00 00 01 00 00 00 02 00 00 00 00 00 00 00 |_...............|
- fffffe0029868650 38 74 00 00 00 00 00 00 38 74 00 00 00 00 00 00 |8t......8t......|
- fffffe0029868660 40 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |@...............|
- fffffe0029868670 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868680 69 00 00 00 06 00 00 00 03 00 00 00 00 00 00 00 |i...............|
- fffffe0029868690 f0 7e 20 00 00 00 00 00 f0 7e 00 00 00 00 00 00 |.~ ......~......|
- fffffe00298686a0 10 01 00 00 00 00 00 00 04 00 00 00 00 00 00 00 |................|
- fffffe00298686b0 08 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 |................|
- fffffe00298686c0 72 00 00 00 08 00 00 00 03 00 00 00 00 00 00 00 |r...............|
- fffffe00298686d0 00 80 20 00 00 00 00 00 00 80 00 00 00 00 00 00 |.. .............|
- fffffe00298686e0 48 bf 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |H...............|
- fffffe00298686f0 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868700 77 00 00 00 01 00 00 00 30 00 00 00 00 00 00 00 |w.......0.......|
- fffffe0029868710 00 00 00 00 00 00 00 00 00 80 00 00 00 00 00 00 |................|
- fffffe0029868720 2d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |-...............|
- fffffe0029868730 01 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 |................|
- fffffe0029868740 01 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868750 00 00 00 00 00 00 00 00 30 80 00 00 00 00 00 00 |........0.......|
- fffffe0029868760 b0 07 00 00 00 00 00 00 0e 00 00 00 25 00 00 00 |............%...|
- fffffe0029868770 08 00 00 00 00 00 00 00 18 00 00 00 00 00 00 00 |................|
- fffffe0029868780 09 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe0029868790 00 00 00 00 00 00 00 00 e0 87 00 00 00 00 00 00 |................|
- fffffe00298687a0 48 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |H...............|
- fffffe00298687b0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe00298687c0 11 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe00298687d0 00 00 00 00 00 00 00 00 28 8c 00 00 00 00 00 00 |........(.......|
- fffffe00298687e0 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- fffffe00298687f0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
- reading string section 8c28 80
- ffffff800210c000 00 2e 73 79 6d 74 61 62 00 2e 73 74 72 74 61 62 |..symtab..strtab|
- ffffff800210c010 00 2e 73 68 73 74 72 74 61 62 00 2e 69 6e 74 65 |..shstrtab..inte|
- ffffff800210c020 72 70 00 2e 68 61 73 68 00 2e 64 79 6e 73 79 6d |rp..hash..dynsym|
- ffffff800210c030 00 2e 64 79 6e 73 74 72 00 2e 72 65 6c 61 2e 64 |..dynstr..rela.d|
- ffffff800210c040 79 6e 00 2e 74 65 78 74 00 2e 72 6f 64 61 74 61 |yn..text..rodata|
- ffffff800210c050 00 2e 65 68 5f 66 72 61 6d 65 5f 68 64 72 00 2e |..eh_frame_hdr..|
- ffffff800210c060 65 68 5f 66 72 61 6d 65 00 2e 64 79 6e 61 6d 69 |eh_frame..dynami|
- ffffff800210c070 63 00 2e 62 73 73 00 2e 63 6f 6d 6d 65 6e 74 00 |c..bss..comment.|
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement