Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
syscall::connect:entry
/execname == "Echofon"/
{
this->sock = (struct sockaddr_in *)copyin(arg1, arg2);
port = this->sock->sin_port;
ip = this->sock->sin_addr.s_addr;
printf("%s %d %d.%d.%d.%d\n", execname, port, (ip >> 0) & 0xff, (ip >> 8) & 0xff, (ip >> 16) & 0xff, (ip >> 24) & 0xff);
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.