Binary Hacks - Dump process virtual memory

  1. get [pid] of process
  2. get the memory mappings cat /proc/[PID]/maps
  3. identify the memory range of interest
  4. connect gdb to pid and dump memory:
# perhaps need sudo

gdb --pid [PID] 

Then you can exam the dump with tools like hexdump.

Oct 16, 2023

[+] click to leave a comment [+]
the comment system on this blog works via email. The button
below will generate a mailto: link based on this page's url 
and invoke your email client - please edit the comment there!

[optional] even better, encrypt the email with my public key

- don't modify the subject field
- specify a nickname, otherwise your comment will be shown as   
- your email address will not be disclosed
- you agree that the comment is to be made public.
- to take down a comment, send the request via email.


Sharesnip via Rosano March 6, 2023

Free QR code generator and scanner.

Nikon F3/T via Corvid Cafe February 23, 2023

It's so pretty...

2022 year review via ellugar Logs January 9, 2023


Generated by openring from webring