Skip to content

Instantly share code, notes, and snippets.

/-

Created November 15, 2017 01:14
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save anonymous/76067d0e7a72571ad155aec6a9d2029a to your computer and use it in GitHub Desktop.
Save anonymous/76067d0e7a72571ad155aec6a9d2029a to your computer and use it in GitHub Desktop.
execve("/usr/bin/gufw", ["gufw"], [/* 50 vars */]) = 0
brk(NULL) = 0x55a25864b000
access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f641d787000
access("/etc/ld.so.preload", R_OK) = 0
open("/etc/ld.so.preload", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=0, ...}) = 0
close(3) = 0
open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=145175, ...}) = 0
mmap(NULL, 145175, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f641d763000
close(3) = 0
access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
open("/lib/x86_64-linux-gnu/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\t\2\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1868984, ...}) = 0
mmap(NULL, 3971488, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f641d19a000
mprotect(0x7f641d35a000, 2097152, PROT_NONE) = 0
mmap(0x7f641d55a000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1c0000) = 0x7f641d55a000
mmap(0x7f641d560000, 14752, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f641d560000
close(3) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f641d762000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f641d761000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f641d760000
arch_prctl(ARCH_SET_FS, 0x7f641d761700) = 0
mprotect(0x7f641d55a000, 16384, PROT_READ) = 0
mprotect(0x55a2584d7000, 8192, PROT_READ) = 0
mprotect(0x7f641d789000, 4096, PROT_READ) = 0
munmap(0x7f641d763000, 145175) = 0
getuid() = 1000
getgid() = 1000
getpid() = 6357
rt_sigaction(SIGCHLD, {0x55a2582cb540, ~[RTMIN RT_1], SA_RESTORER, 0x7f641d1cf4b0}, NULL, 8) = 0
geteuid() = 1000
brk(NULL) = 0x55a25864b000
brk(0x55a25866c000) = 0x55a25866c000
getppid() = 6354
stat("/home/prs-player", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
stat(".", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
open("/usr/bin/gufw", O_RDONLY) = 3
fcntl(3, F_DUPFD, 10) = 10
close(3) = 0
fcntl(10, F_SETFD, FD_CLOEXEC) = 0
geteuid() = 1000
getegid() = 1000
rt_sigaction(SIGINT, NULL, {SIG_DFL, [], 0}, 8) = 0
rt_sigaction(SIGINT, {0x55a2582cb540, ~[RTMIN RT_1], SA_RESTORER, 0x7f641d1cf4b0}, NULL, 8) = 0
rt_sigaction(SIGQUIT, NULL, {SIG_DFL, [], 0}, 8) = 0
rt_sigaction(SIGQUIT, {SIG_DFL, ~[RTMIN RT_1], SA_RESTORER, 0x7f641d1cf4b0}, NULL, 8) = 0
rt_sigaction(SIGTERM, NULL, {SIG_DFL, [], 0}, 8) = 0
rt_sigaction(SIGTERM, {SIG_DFL, ~[RTMIN RT_1], SA_RESTORER, 0x7f641d1cf4b0}, NULL, 8) = 0
read(10, "#!/bin/sh\nc_user=$(whoami)\npkexe"..., 8192) = 55
pipe([3, 4]) = 0
clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7f641d7619d0) = 6358
close(4) = 0
--- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=6358, si_uid=1000, si_status=0, si_utime=0, si_stime=0} ---
rt_sigreturn({mask=[]}) = 0
read(3, "prs-player\n", 128) = 11
read(3, "", 128) = 0
close(3) = 0
wait4(-1, [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], 0, NULL) = 6358
stat("/usr/local/sbin/pkexec", 0x7ffdd17f0100) = -1 ENOENT (No such file or directory)
stat("/usr/local/bin/pkexec", 0x7ffdd17f0100) = -1 ENOENT (No such file or directory)
stat("/usr/sbin/pkexec", 0x7ffdd17f0100) = -1 ENOENT (No such file or directory)
stat("/usr/bin/pkexec", {st_mode=S_IFREG|S_ISUID|0755, st_size=23376, ...}) = 0
clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7f641d7619d0) = 6359
wait4(-1, openjdk version "1.8.0_151"
OpenJDK Runtime Environment (build 1.8.0_151-8u151-b12-0ubuntu0.16.04.2-b12)
OpenJDK 64-Bit Server VM (build 25.151-b12, mixed mode)
/usr/bin/gufw-pkexec: line 15: 6365 Bus error python ${LOCATIONS[${i}]} $1
[{WIFEXITED(s) && WEXITSTATUS(s) == 0}], 0, NULL) = 6359
--- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=6359, si_uid=0, si_status=0, si_utime=2, si_stime=1} ---
rt_sigreturn({mask=[]}) = 6359
read(10, "", 8192) = 0
exit_group(0) = ?
+++ exited with 0 +++
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment