[Gllug] Memory scanning

Richard Jones rich at annexia.org
Mon Sep 6 10:40:46 UTC 2010


On Mon, Sep 06, 2010 at 07:44:39AM +0100, Nix wrote:
> On 4 Sep 2010, Richard Jones spake thusly:
> 
> > On Sat, Sep 04, 2010 at 09:21:51PM +0100, James Courtier-Dutton wrote:
> >> On 4 September 2010 15:49, Richard Jones <rich at annexia.org> wrote:
> >> >
> >> > It's possible, though not simple, to do this from the hypervisor.  I
> >> > have written programs which scan the kernel for its version, look at
> >> > the process table and so on, and from there it's possible to scan the
> >> > executable pages of any process running of interest to you.  I did it
> >> > via this libvirt API:
> >> 
> >> May I have a copy of that program?
> >
> > Sure.  Be aware of the license.
> 
> Also, note the *language*, although this shouldn't have been too
> terribly much of a surprise ;)

You need your brain screwed on if you're going to be delving in the
internals of a virtual image.  Anyone capable of doing that isn't
going to have a problem picking up a new programming language.

Rich.

-- 
Richard Jones
Red Hat
-- 
Gllug mailing list  -  Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug




More information about the GLLUG mailing list