Skip to content

Instantly share code, notes, and snippets.

@pmdpaula
Created November 19, 2020 17:57
Show Gist options
  • Save pmdpaula/7a05d4fad4667eb0c625b2bbf68a10f9 to your computer and use it in GitHub Desktop.
Save pmdpaula/7a05d4fad4667eb0c625b2bbf68a10f9 to your computer and use it in GitHub Desktop.
508 execve("/usr/bin/ping", ["ping", "www.microsoft.com"], 0x7ffdcd296320 /* 34 vars */) = 0
508 access("/etc/suid-debug", F_OK) = -1 ENOENT (No such file or directory)
508 brk(NULL) = 0x55ee83ade000
508 arch_prctl(0x3001 /* ARCH_??? */, 0x7ffd2431a720) = -1 EINVAL (Invalid argument)
508 fcntl(0, F_GETFD) = 0
508 fcntl(1, F_GETFD) = 0
508 fcntl(2, F_GETFD) = 0
508 access("/etc/suid-debug", F_OK) = -1 ENOENT (No such file or directory)
508 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
508 openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=47091, ...}) = 0
508 mmap(NULL, 47091, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f615229e000
508 close(3) = 0
508 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libcap.so.2", O_RDONLY|O_CLOEXEC) = 3
508 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300#\0\0\0\0\0\0"..., 832) = 832
508 fstat(3, {st_mode=S_IFREG|0644, st_size=31120, ...}) = 0
508 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f615229c000
508 mmap(NULL, 33112, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f6152293000
508 mprotect(0x7f6152295000, 20480, PROT_NONE) = 0
508 mmap(0x7f6152295000, 12288, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f6152295000
508 mmap(0x7f6152298000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x5000) = 0x7f6152298000
508 mmap(0x7f615229a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x6000) = 0x7f615229a000
508 close(3) = 0
508 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libgcrypt.so.20", O_RDONLY|O_CLOEXEC) = 3
508 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\305\0\0\0\0\0\0"..., 832) = 832
508 fstat(3, {st_mode=S_IFREG|0644, st_size=1168056, ...}) = 0
508 mmap(NULL, 1171400, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f6152175000
508 mmap(0x7f6152181000, 843776, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7f6152181000
508 mmap(0x7f615224f000, 249856, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xda000) = 0x7f615224f000
508 mmap(0x7f615228c000, 28672, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x116000) = 0x7f615228c000
508 close(3) = 0
508 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 3
508 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 G\0\0\0\0\0\0"..., 832) = 832
508 fstat(3, {st_mode=S_IFREG|0644, st_size=101320, ...}) = 0
508 mmap(NULL, 113280, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f6152159000
508 mprotect(0x7f615215d000, 81920, PROT_NONE) = 0
508 mmap(0x7f615215d000, 65536, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f615215d000
508 mmap(0x7f615216d000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14000) = 0x7f615216d000
508 mmap(0x7f6152171000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x17000) = 0x7f6152171000
508 mmap(0x7f6152173000, 6784, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f6152173000
508 close(3) = 0
508 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
508 read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360q\2\0\0\0\0\0"..., 832) = 832
508 pread64(3, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784
508 pread64(3, "\4\0\0\0\20\0\0\0\5\0\0\0GNU\0\2\0\0\300\4\0\0\0\3\0\0\0\0\0\0\0", 32, 848) = 32
508 pread64(3, "\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\363\377?\332\200\270\27\304d\245n\355Y\377\t\334"..., 68, 880) = 68
508 fstat(3, {st_mode=S_IFREG|0755, st_size=2029224, ...}) = 0
508 pread64(3, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784
508 pread64(3, "\4\0\0\0\20\0\0\0\5\0\0\0GNU\0\2\0\0\300\4\0\0\0\3\0\0\0\0\0\0\0", 32, 848) = 32
508 pread64(3, "\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\363\377?\332\200\270\27\304d\245n\355Y\377\t\334"..., 68, 880) = 68
508 mmap(NULL, 2036952, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f6151f67000
508 mprotect(0x7f6151f8c000, 1847296, PROT_NONE) = 0
508 mmap(0x7f6151f8c000, 1540096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x25000) = 0x7f6151f8c000
508 mmap(0x7f6152104000, 303104, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x19d000) = 0x7f6152104000
508 mmap(0x7f615214f000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1e7000) = 0x7f615214f000
508 mmap(0x7f6152155000, 13528, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f6152155000
508 close(3) = 0
508 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libgpg-error.so.0", O_RDONLY|O_CLOEXEC) = 3
508 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`L\0\0\0\0\0\0"..., 832) = 832
508 fstat(3, {st_mode=S_IFREG|0644, st_size=137584, ...}) = 0
508 mmap(NULL, 139872, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f6151f44000
508 mmap(0x7f6151f48000, 77824, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f6151f48000
508 mmap(0x7f6151f5b000, 40960, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x17000) = 0x7f6151f5b000
508 mmap(0x7f6151f65000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x20000) = 0x7f6151f65000
508 close(3) = 0
508 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f6151f42000
508 arch_prctl(ARCH_SET_FS, 0x7f6151f43040) = 0
508 mprotect(0x7f615214f000, 12288, PROT_READ) = 0
508 mprotect(0x7f6151f65000, 4096, PROT_READ) = 0
508 mprotect(0x7f6152171000, 4096, PROT_READ) = 0
508 mprotect(0x7f615228c000, 8192, PROT_READ) = 0
508 mprotect(0x7f615229a000, 4096, PROT_READ) = 0
508 mprotect(0x55ee835f1000, 4096, PROT_READ) = 0
508 mprotect(0x7f61522d7000, 4096, PROT_READ) = 0
508 munmap(0x7f615229e000, 47091) = 0
508 brk(NULL) = 0x55ee83ade000
508 brk(0x55ee83aff000) = 0x55ee83aff000
508 prctl(PR_CAPBSET_READ, CAP_MAC_OVERRIDE) = 1
508 prctl(PR_CAPBSET_READ, 0x30 /* CAP_??? */) = -1 EINVAL (Invalid argument)
508 prctl(PR_CAPBSET_READ, 0x28 /* CAP_??? */) = -1 EINVAL (Invalid argument)
508 prctl(PR_CAPBSET_READ, CAP_BLOCK_SUSPEND) = 1
508 prctl(PR_CAPBSET_READ, 0x26 /* CAP_??? */) = -1 EINVAL (Invalid argument)
508 prctl(PR_CAPBSET_READ, CAP_AUDIT_READ) = 1
508 capget({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, NULL) = 0
508 capget({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, {effective=0, permitted=0, inheritable=0}) = 0
508 capget({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, NULL) = 0
508 capset({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, {effective=0, permitted=0, inheritable=0}) = 0
508 prctl(PR_SET_KEEPCAPS, 1) = 0
508 getuid() = 1000
508 setuid(1000) = 0
508 prctl(PR_SET_KEEPCAPS, 0) = 0
508 getuid() = 1000
508 geteuid() = 1000
508 openat(AT_FDCWD, "/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=3035952, ...}) = 0
508 mmap(NULL, 3035952, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151c5c000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=2996, ...}) = 0
508 read(3, "# Locale name alias data base.\n#"..., 4096) = 2996
508 read(3, "", 4096) = 0
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_IDENTIFICATION", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=252, ...}) = 0
508 mmap(NULL, 252, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f61522d6000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.cache", O_RDONLY) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=27002, ...}) = 0
508 mmap(NULL, 27002, PROT_READ, MAP_SHARED, 3, 0) = 0x7f61522a3000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MEASUREMENT", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=23, ...}) = 0
508 mmap(NULL, 23, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f61522a2000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_TELEPHONE", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=47, ...}) = 0
508 mmap(NULL, 47, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f61522a1000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_ADDRESS", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=131, ...}) = 0
508 mmap(NULL, 131, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f61522a0000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_NAME", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=62, ...}) = 0
508 mmap(NULL, 62, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f615229f000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_PAPER", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=34, ...}) = 0
508 mmap(NULL, 34, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f615229e000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MESSAGES", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MESSAGES/SYS_LC_MESSAGES", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=48, ...}) = 0
508 mmap(NULL, 48, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151c5b000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MONETARY", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=270, ...}) = 0
508 mmap(NULL, 270, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151c5a000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_COLLATE", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=1518110, ...}) = 0
508 mmap(NULL, 1518110, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151ae7000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_TIME", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=3360, ...}) = 0
508 mmap(NULL, 3360, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151ae6000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_NUMERIC", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=50, ...}) = 0
508 mmap(NULL, 50, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151ae5000
508 close(3) = 0
508 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_CTYPE", O_RDONLY|O_CLOEXEC) = 3
508 fstat(3, {st_mode=S_IFREG|0644, st_size=201272, ...}) = 0
508 mmap(NULL, 201272, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6151ab3000
508 close(3) = 0
508 capget({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, NULL) = 0
508 capget({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, {effective=0, permitted=0, inheritable=0}) = 0
508 socket(AF_INET, SOCK_DGRAM, IPPROTO_ICMP) = -1 EACCES (Permission denied)
508 socket(AF_INET, SOCK_RAW, IPPROTO_ICMP) = -1 EPERM (Operation not permitted)
508 socket(AF_INET6, SOCK_DGRAM, IPPROTO_ICMPV6) = -1 EACCES (Permission denied)
508 socket(AF_INET6, SOCK_RAW, IPPROTO_ICMPV6) = -1 EPERM (Operation not permitted)
508 write(2, "ping: ", 6) = 6
508 write(2, "socket", 6) = 6
508 openat(AT_FDCWD, "/usr/share/locale/C.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
508 openat(AT_FDCWD, "/usr/share/locale/C.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
508 openat(AT_FDCWD, "/usr/share/locale/C/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
508 openat(AT_FDCWD, "/usr/share/locale-langpack/C.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
508 openat(AT_FDCWD, "/usr/share/locale-langpack/C.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
508 openat(AT_FDCWD, "/usr/share/locale-langpack/C/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
508 write(2, ": Operation not permitted", 25) = 25
508 write(2, "\n", 1) = 1
508 close(1) = 0
508 close(2) = 0
508 exit_group(2) = ?
508 +++ exited with 2 +++
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment