1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
|
#include <linux/init.h>
#include <linux/module.h>
#include <linux/printk.h>
#include <linux/proc_fs.h>
// #define NAME "keylogger"
#define NAME "_test_module"
ssize_t proc_read(struct file *file, char __user *user, size_t size, loff_t *off);
ssize_t proc_write(struct file *file, const char __user *user, size_t size, loff_t *off);
static struct proc_dir_entry *proc = NULL;
static const struct proc_ops proc_fops = {
.proc_read = proc_read,
.proc_write = proc_write,
};
static char *msg_buf = NULL;
#define COPY_TO_USER(_msg, _len) \
if(copy_to_user(user, _msg, _len)) return -EFAULT; \
*off += _len; \
user += _len;
ssize_t proc_read(struct file *file, char __user *user, size_t size, loff_t *off)
{
printk("FILE READ KEK\n");
if (*off > 0) return 0; // we have already written
if(msg_buf == NULL) {
COPY_TO_USER("You have no previous messages\n", 30);
return 30;
}
size_t len = strlen(msg_buf);
if(size < (len + 24)) return 0;
COPY_TO_USER("Your last message was: ", 23);
COPY_TO_USER(msg_buf, len);
COPY_TO_USER("\n", 1);
return len + 24;
}
ssize_t proc_write(struct file *file, const char __user *user, size_t size, loff_t *off)
{
printk("FIEL WRITE KEK\n");
kfree(msg_buf);
if((msg_buf = kmalloc(size + 1, GFP_KERNEL)) == NULL) {
return -ENOMEM;
}
if(copy_from_user(msg_buf, user, size)) {
return -EFAULT;
}
msg_buf[size] = '\0';
if(msg_buf[size-1] == '\n') msg_buf[size-1] = '\0';
return size;
}
static int __init init_keylogger(void)
{
printk("Init Kek\n");
if((proc = proc_create(NAME, 0666, NULL, &proc_fops)) == NULL)
return -ENOMEM;
return 0;
}
static void __exit exit_keylogger(void)
{
printk("Exit Kek\n");
proc_remove(proc);
kfree(msg_buf);
}
module_init(init_keylogger);
module_exit(exit_keylogger);
MODULE_LICENSE("GPL");
MODULE_AUTHOR("Kartofen");
MODULE_DESCRIPTION("A simple keylogger kernel module");
|