[Gllug] Memory scanning
Richard Jones
rich at annexia.org
Mon Sep 6 10:40:46 UTC 2010
On Mon, Sep 06, 2010 at 07:44:39AM +0100, Nix wrote:
> On 4 Sep 2010, Richard Jones spake thusly:
>
> > On Sat, Sep 04, 2010 at 09:21:51PM +0100, James Courtier-Dutton wrote:
> >> On 4 September 2010 15:49, Richard Jones <rich at annexia.org> wrote:
> >> >
> >> > It's possible, though not simple, to do this from the hypervisor. I
> >> > have written programs which scan the kernel for its version, look at
> >> > the process table and so on, and from there it's possible to scan the
> >> > executable pages of any process running of interest to you. I did it
> >> > via this libvirt API:
> >>
> >> May I have a copy of that program?
> >
> > Sure. Be aware of the license.
>
> Also, note the *language*, although this shouldn't have been too
> terribly much of a surprise ;)
You need your brain screwed on if you're going to be delving in the
internals of a virtual image. Anyone capable of doing that isn't
going to have a problem picking up a new programming language.
Rich.
--
Richard Jones
Red Hat
--
Gllug mailing list - Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug
More information about the GLLUG
mailing list