Skip to content

Instantly share code, notes, and snippets.


Kondo Uchio udzura

View GitHub Profile
udzura / SECKUN 2021
Last active Nov 21, 2021
SECKUN 2021/ProSec-IT 2021 コンテナ演習資料(公開版)
View SECKUN 2021

SECKUN 2021/ProSec-IT 2021 コンテナ演習資料(公開版)


九州大学のSECKUN 2021/ProSec-IT(enPiT-Pro) 2021の共通カリキュラムにおいて、近藤 @udzura が担当したコンテナ概要の授業にて使用した教材です。


udzura / pty.rb
Created May 6, 2021
dup2 を自分で使う場合
View pty.rb
require 'fiddle/import'
module Dupper
extend Fiddle::Importer
dlload ''
extern 'int dup2(int oldfd, int newfd);'
require 'pty'
master, tty =

@udzura のやってきたこと



<script async class="speakerdeck-embed" data-id="a52bd0069cd447a78681bc951d76aca6" data-ratio="1.77777777777778" src="//"></script>
View env.bash
## CONTAINER RUNTIME MEETUP #3 working environment
$ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 20.10
Release: 20.10
Codename: groovy
$ uname -a
Linux ubuntu-groovy 5.8.0-38-generic #43-Ubuntu SMP Tue Jan 12 12:42:13 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
$ runc -v
View bpf-die.log
bpf(BPF_MAP_CREATE, {map_type=BPF_MAP_TYPE_ARRAY, key_size=4, value_size=32, max_entries=1, map_flags=0, inner_map_fd=0, map_name="", map_ifindex=0, btf_fd=0, btf_key_type_id=0, btf_value_type_id=0}, 120) = 4
bpf(BPF_PROG_LOAD, {prog_type=BPF_PROG_TYPE_SOCKET_FILTER, insn_cnt=5, insns=0x7ffffd20c790, license="GPL", log_level=0, log_size=0, log_buf=NULL, kern_version=KERNEL_VERSION(0, 0, 0), prog_flags=0, prog_name="", prog_ifindex=0, expected_attach_type=BPF_CGROUP_INET_INGRESS, prog_btf_fd=0, func_info_rec_size=0, func_info=NULL, func_info_cnt=0, line_info_rec_size=0, line_info=NULL, line_info_cnt=0, attach_btf_id=0, attach_prog_fd=0}, 120) = -1 EPERM (Operation not permitted)
View Gemfile
source ""
gem "rack"
gem "sinatra"
# gem "pry"
View tmux.conf
# This file is owned by Uchio KONDO
# esc
unbind-key C-b
set-option -g prefix C-]
bind-key C-] send-prefix
# Act like Vim
set-window-option -g mode-keys vi
from bcc import BPF
code = """
#include <linux/elf.h>
struct data_t {
unsigned char magic[EI_NIDENT];
u64 type;
u64 offset;
u64 addr;
View ZZ-log.console
$ ./chkheap
Run bpftrace background and hit return:
55a46e740000-55a46e741000 r-xp 00000000 08:01 22338 /home/vagrant/chkheap
55a46e940000-55a46e941000 r--p 00000000 08:01 22338 /home/vagrant/chkheap
55a46e941000-55a46e942000 rw-p 00001000 08:01 22338 /home/vagrant/chkheap
55a4705d0000-55a4705f1000 rw-p 00000000 00:00 0 [heap]
7f341d659000-7f341d840000 r-xp 00000000 08:01 21679 /lib/x86_64-linux-gnu/
7f341d840000-7f341da40000 ---p 001e7000 08:01 21679 /lib/x86_64-linux-gnu/