I'm looking for a way to perform Hooking with seccomp or seccomp-bpf.
I want to set a rule so that when a syscall is performed (eg read) I can change the process or the answer that comes back from Syscall. And I must use seccomp.
Tnx
I'm looking for a way to perform Hooking with seccomp or seccomp-bpf.
I want to set a rule so that when a syscall is performed (eg read) I can change the process or the answer that comes back from Syscall. And I must use seccomp.
Tnx
Copyright © 2021 Jogjafile Inc.
I think what you want is to modify the
struct seccomp_data, however, this is a read-only struct.To bypass this restriction you can use BPF jointly with
ptrace, filter syscalls with BPF and modify them usingptrace.