p!ranha?
Server IP : 103.169.32.36  /  Your IP : 216.73.217.13
Web Server : Apache
System : Linux web.dpmptsp 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User : apache ( 48)
PHP Version : 5.6.40
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/opt/eset/efs/ewap/eset_wap/

Upload File :
Curr3nt_D!r [ Writeable ] D0cum3nt_r0Ot [ Writeable ]

 
Command :
Current File : /var/opt/eset/efs/ewap/eset_wap/ewap_probes.c
/*
 * eset_wap (ESET Web Access Protection module)
 * Copyright (C) 1992-2023 ESET, spol. s r.o.
 *
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program.  If not, see <https://www.gnu.org/licenses/>.
 *
 * In case of any questions, you can contact us at ESET, spol. s r.o., Einsteinova 24, 851 01 Bratislava, Slovakia.
 */

#include "ewap_probes.h"

#include "ewap_connect_data.h"
#include "ewap_ftrace.h"
#include "ewap_helpers.h"
#include "ewap_tracepoints.h"

#include <asm/current.h>
#include <linux/compiler.h>
#include <linux/cred.h>
#include <net/tcp.h>

static int (*tcp_v4_connect_original)(struct sock *sk, struct sockaddr *uaddr,
                                      int addr_len);

static int tcp_v4_connect_handler(struct sock *sk, struct sockaddr *uaddr,
                                  int addr_len) {
  int original_call_ret;
  int ret;

  ewap_pr_log(EWAP_LOG_HOOKS, "tcp_v4_connect_handler hit from pid: %d",
              current->tgid);

  original_call_ret = tcp_v4_connect_original(sk, uaddr, addr_len);
  if (original_call_ret != 0) {
    ewap_pr_log(EWAP_LOG_HOOKS,
                "not processing unsuccessful original connect (%d)",
                original_call_ret);
    goto end;
  }

  ret = ewap_connect_data_save_connection(sk, current->tgid, current_uid().val);
  if (unlikely(!ret)) {
    ewap_pr_log(EWAP_LOG_HOOKS, "ignoring unknown family %d", sk->sk_family);
  }

end:
  return original_call_ret;
}

static struct ewap_ftrace_hook v4_connect_ftrace_hook = {
    .name = "tcp_v4_connect",
    .original = &tcp_v4_connect_original,
    .handler = &tcp_v4_connect_handler};

static int (*tcp_v6_connect_original)(struct sock *sk, struct sockaddr *uaddr,
                                      int addr_len);

static int tcp_v6_connect_handler(struct sock *sk, struct sockaddr *uaddr,
                                  int addr_len) {
  int original_call_ret;
  int ret;

  ewap_pr_log(EWAP_LOG_HOOKS, "tcp_v6_connect_handler hit from pid: %d",
              current->tgid);

  original_call_ret = tcp_v6_connect_original(sk, uaddr, addr_len);
  if (original_call_ret != 0) {
    ewap_pr_log(EWAP_LOG_HOOKS,
                "not processing unsuccessful original connect (%d)",
                original_call_ret);
    goto end;
  }

  ret = ewap_connect_data_save_connection(sk, current->tgid, current_uid().val);
  if (unlikely(!ret)) {
    ewap_pr_log(EWAP_LOG_HOOKS, "ignoring unknown family %d", sk->sk_family);
  }

end:
  return original_call_ret;
}

static struct ewap_ftrace_hook v6_connect_ftrace_hook = {
    .name = "tcp_v6_connect",
    .original = &tcp_v6_connect_original,
    .handler = &tcp_v6_connect_handler};

static void (*tcp_set_state_original)(struct sock *sk, int state);

static void tcp_set_state_handler(struct sock *sk, int state) {
  int ret;

  ewap_pr_log(EWAP_LOG_HOOKS, "tcp_set_state_handler hit, from pid: %d",
              current->tgid);

  if (state == TCP_CLOSE) {
    ret = ewap_connect_data_erase_connection(sk);
    if (unlikely(!ret)) {
      ewap_pr_log(EWAP_LOG_HOOKS, "ignoring unknown family %d", sk->sk_family);
    }

  } else {
    ewap_pr_log(EWAP_LOG_HOOKS,
                "ignoring processing of non-close tcp_set_state: %d", state);
  }

  tcp_set_state_original(sk, state);
}

static struct ewap_ftrace_hook set_state_ftrace_hook = {
    .name = "tcp_set_state",
    .original = &tcp_set_state_original,
    .handler = &tcp_set_state_handler};

static void probe_sched_process_exit(void *data, struct task_struct *task) {
  ewap_pr_log(EWAP_LOG_HOOKS,
              "sched_process_exit probe called (tgid: %d, pid: %d)", task->tgid,
              task->pid);

  if (task->tgid == task->pid) {
    ewap_connect_data_erase_all_connections(task->tgid);
  }
}

static struct ewap_tracepoint sched_process_exit_hook = {
    .name = "sched_process_exit",
    .handler = &probe_sched_process_exit,
};

int ewap_probes_init(void) {
  int ret = 0;

  if ((ret = ewap_ftrace_register(&v4_connect_ftrace_hook))) {
    ewap_pr_log(EWAP_LOG_ERRORS,
                "v4_connect_ftrace_hook probe register failed: %d", ret);
    goto err_v4_connect_ftrace_hook;
  }

  if ((ret = ewap_ftrace_register(&v6_connect_ftrace_hook))) {
    ewap_pr_log(EWAP_LOG_ERRORS,
                "v6_connect_ftrace_hook probe register failed: %d", ret);
    goto err_v6_connect_ftrace_hook;
  }

  if ((ret = ewap_ftrace_register(&set_state_ftrace_hook))) {
    ewap_pr_log(EWAP_LOG_ERRORS,
                "set_state_ftrace_hook probe register failed: %d", ret);
    goto err_set_state_ftrace_hook;
  }

  if ((ret = ewap_tracepoint_register(&sched_process_exit_hook))) {
    ewap_pr_log(EWAP_LOG_ERRORS,
                "probe_sched_process_exit tracepoint register failed: %d", ret);
    goto err_probe_sched_process_exit;
  }

  ewap_pr_log(EWAP_LOG_HOOKS, "all probes initialized");

  return 0;

err_probe_sched_process_exit:
  ewap_ftrace_unregister(&set_state_ftrace_hook);
err_set_state_ftrace_hook:
  ewap_ftrace_unregister(&v6_connect_ftrace_hook);
err_v6_connect_ftrace_hook:
  ewap_ftrace_unregister(&v4_connect_ftrace_hook);
err_v4_connect_ftrace_hook:
  return ret;
}

void ewap_probes_deinit(void) {
  ewap_ftrace_unregister(&set_state_ftrace_hook);
  ewap_ftrace_unregister(&v6_connect_ftrace_hook);
  ewap_ftrace_unregister(&v4_connect_ftrace_hook);
  ewap_tracepoint_unregister(&sched_process_exit_hook);
  tracepoint_synchronize_unregister();

  ewap_pr_log(EWAP_LOG_HOOKS, "probes deinitialized");
}
N4m3
5!z3
L45t M0d!f!3d
0wn3r / Gr0up
P3Rm!55!0n5
0pt!0n5
..
--
October 29 2025 23:56:25
0 / 0
0775
.eset_wap.ko.cmd
0.245 KB
October 29 2025 23:56:25
0 / 0
0644
.eset_wap.mod.o.cmd
26.813 KB
October 29 2025 23:56:25
0 / 0
0644
.eset_wap.o.cmd
0.588 KB
October 29 2025 23:56:25
0 / 0
0644
.ewap_connect_data.o.cmd
47.326 KB
October 29 2025 23:56:24
0 / 0
0644
.ewap_dev.o.cmd
47.226 KB
October 29 2025 23:56:23
0 / 0
0644
.ewap_ftrace.o.cmd
34.915 KB
October 29 2025 23:56:23
0 / 0
0644
.ewap_mod.o.cmd
49.095 KB
October 29 2025 23:56:22
0 / 0
0644
.ewap_path.o.cmd
34.64 KB
October 29 2025 23:56:25
0 / 0
0644
.ewap_pid_map.o.cmd
25.478 KB
October 29 2025 23:56:24
0 / 0
0644
.ewap_probes.o.cmd
49.259 KB
October 29 2025 23:56:23
0 / 0
0644
.ewap_tcp_map.o.cmd
47.168 KB
October 29 2025 23:56:25
0 / 0
0644
.ewap_tracepoints.o.cmd
17.967 KB
October 29 2025 23:56:23
0 / 0
0644
Makefile
0.996 KB
July 26 2024 11:16:53
0 / 0
0775
eset_wap.h
1.874 KB
July 26 2024 11:16:53
0 / 0
0775
eset_wap.ko
2.13 MB
October 29 2025 23:56:25
0 / 0
0644
eset_wap.mod.c
3.111 KB
October 29 2025 23:56:25
0 / 0
0644
eset_wap.mod.o
60.055 KB
October 29 2025 23:56:25
0 / 0
0644
eset_wap.o
2.08 MB
October 29 2025 23:56:25
0 / 0
0644
ewap_connect_data.c
13.813 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_connect_data.h
1.714 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_connect_data.o
363.984 KB
October 29 2025 23:56:24
0 / 0
0644
ewap_dev.c
5.936 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_dev.h
0.952 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_dev.o
351.031 KB
October 29 2025 23:56:23
0 / 0
0644
ewap_ftrace.c
4.698 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_ftrace.h
1.18 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_ftrace.o
139.648 KB
October 29 2025 23:56:23
0 / 0
0644
ewap_helpers.h
2.34 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_mod.c
2.217 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_mod.o
342.273 KB
October 29 2025 23:56:22
0 / 0
0644
ewap_path.c
3.395 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_path.h
1.246 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_path.o
159.789 KB
October 29 2025 23:56:25
0 / 0
0644
ewap_pid_map.c
4.405 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_pid_map.h
1.697 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_pid_map.o
67.742 KB
October 29 2025 23:56:24
0 / 0
0644
ewap_probes.c
5.887 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_probes.h
0.964 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_probes.o
360 KB
October 29 2025 23:56:23
0 / 0
0644
ewap_tcp_map.c
6.08 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_tcp_map.h
2.088 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_tcp_map.o
352.93 KB
October 29 2025 23:56:25
0 / 0
0644
ewap_tracepoints.c
2.422 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_tracepoints.h
1.24 KB
July 26 2024 11:16:53
0 / 0
0775
ewap_tracepoints.o
26.531 KB
October 29 2025 23:56:23
0 / 0
0644
modules.order
0.05 KB
October 29 2025 23:56:25
0 / 0
0644