Go LD_PRELOAD backdoor experiment
github.com
github.com
Of course, you can't, as an ordinary user, start system executables with elevated privileges and set LD_PRELOAD.
Obviously LD_PRELOAD isn't parsed by suid binaries.
(Also no accusation to the original author intended. It's just relevant and fun to the parent message.)
I think it also demonstrates how easy it is to write something similar to Telnet in Go.
Although, if anyone reading this has never heard of LD_PRELOAD, take a look at a better resource than this link because it can be a powerful debugging and testing tool.
Looks like you can somewhat generically write C-ABI shared libraries in C: https://blog.filippo.io/building-python-modules-with-go-1-5/
This has been one of the reasons I've been writing/learning Rust instead of Go, and I'm glad to see competition :)
I did try hooking __libc_start_main, but had difficulty using dl.Sym() with it. I wasn't sure if I converted the function signature to Go incorrectly or if it's a limitation of dl.Sym().
This was the error I was hitting: https://github.com/rainycape/dl/blob/484344929c1867aec9517b5...
So I chose a method with a simpler function signature I found using ltrace, just to get it working as an experiment.
In C++, constructors on static global objects get run automatically (via this mechanism), so if Go has something similar, that would work. (Stable) Rust goes out of its way to make you not able to do this because it's an anti-pattern, but there's a stupid trick if you can assume GNU: https://github.com/geofft/redhook/blob/master/src/lib.rs#L34...
Alternatively, you can just write an __attribute__((constructor)) function in C that calls an exported Go function that in turn calls `go backdoor()`, and link them all together.