tomychen
341 天前
strace -o netstat.log netstat -antp
会发现 netstat 会去/proc/net/tcp(6) 读当时网络连接
至于隐藏就是 hook 了,至于 ring3 还是 ring0
```
open("/proc/net/tcp", O_RDONLY) = 3
read(3, " sl local_address rem_address "..., 4096) = 600
write(1, "tcp 0 0 0.0.0.0:22 "..., 101) = 101
write(1, "tcp 0 0 127.0.0.1:25"..., 101) = 101
write(1, "tcp 0 196 192.168.10.6"..., 101) = 101
read(3, "", 4096) = 0
close(3) = 0
```
read 进来,write 输出
hook 任保一个 syscall 都可以达到屏蔽输出的需求