Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Linux
[Top] [All Lists]

Re: How to make a core dump?

Subject: Re: How to make a core dump?
Date: Sun, 5 Sep 2004 12:34:01 -0400 (EDT)
The following is for sun solaris. For other OS, such
as Linux or other Unix, there must be similar
commands. 

# dumpadm       
to define the dump device and savecore directory. Make
sure the save core directory has enough space to save
the image of the memory. 

# savecore ¨CL          
to save a crash dump of the OS into savecore directory



 --- Alexander Morozov <amorozov@pisem.net> wrote: 
Hello everyone,
recently my friend have found a malcious program
running on his
web-server. After some actions i thought it would be
helpful to make
its core dump, but i couldn't figure out how to do
this. The only
thing that came to mind was attaching to it with
gdb, stopping
it and dumping regions of memory manually (using
memory map in
/proc/pid/mem). It went fine, i copied all segments
but it would be much
better to have standart core dump, to be able to use
usual programms on
it later. I remember, that several years ago default
behaviour of a
program running under linux was dumping itself on
SIGSEGV.
And I wonder, how was this fullfilled, was it
feature of glibc to catch
SIGV and write a dump? Or was it made by the kernel?

Alexander Morozov
 

______________________________________________________________________ 
Post your free ad now! http://personals.yahoo.ca

<Prev in Thread] Current Thread [Next in Thread>