Skip to content

Instantly share code, notes, and snippets.

@therealkenc
Created November 2, 2019 03:17
Show Gist options
  • Save therealkenc/be6f072908bb58b31475560332f07d29 to your computer and use it in GitHub Desktop.
Save therealkenc/be6f072908bb58b31475560332f07d29 to your computer and use it in GitHub Desktop.
70 execve("/mnt/c/WINDOWS/system32/cmd.exe", ["cmd.exe", "/c", "echo hello"], 0x7ffdd4a5cde8 /* 20 vars */) = 0
70 arch_prctl(ARCH_SET_FS, 0x29b800) = 0
70 set_tid_address(0x29b838) = 70
70 brk(NULL) = 0x2032000
70 brk(0x2033000) = 0x2033000
70 sched_getaffinity(0, 128, [0, 1, 2, 3, 4, 5, 6, 7]) = 32
70 getpid() = 70
70 getcwd("/mnt/c/Users/there", 4096) = 19
70 uname({sysname="Linux", nodename="DESKTOP-BNN97ME", ...}) = 0
70 socket(AF_UNIX, SOCK_SEQPACKET, 0) = 3
70 connect(3, {sa_family=AF_UNIX, sun_path="/run/WSL/7_interop"}, 110) = 0
70 getcwd("/mnt/c/Users/there", 4096) = 19
70 open("/mnt/c/WINDOWS/system32/cmd.exe", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_PATH) = 4
70 readlink("/proc/self/fd/4", "/mnt/c/WINDOWS/system32/cmd.exe", 4095) = 31
70 fstat(4, {st_mode=S_IFREG|0555, st_size=289792, ...}) = 0
70 stat("/mnt/c/WINDOWS/system32/cmd.exe", {st_mode=S_IFREG|0555, st_size=289792, ...}) = 0
70 close(4) = 0
70 open("/proc/self/mountinfo", O_RDONLY) = 4
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="31 25 8:16 / / rw,relatime maste"..., iov_len=1024}], 2) = 1024
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="d,nodev,noexec,relatime - cgroup"..., iov_len=1024}], 2) = 1024
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="p/hugetlb rw,nosuid,nodev,noexec"..., iov_len=1024}], 2) = 448
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="", iov_len=1024}], 2) = 0
70 close(4) = 0
70 getcwd("/mnt/c/Users/there", 4096) = 19
70 open("/proc/self/mountinfo", O_RDONLY) = 4
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="31 25 8:16 / / rw,relatime maste"..., iov_len=1024}], 2) = 1024
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="d,nodev,noexec,relatime - cgroup"..., iov_len=1024}], 2) = 1024
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="p/hugetlb rw,nosuid,nodev,noexec"..., iov_len=1024}], 2) = 448
70 readv(4, [{iov_base="", iov_len=0}, {iov_base="", iov_len=1024}], 2) = 0
70 close(4) = 0
70 ioctl(0, TCGETS, {B38400 opost isig icanon echo ...}) = 0
70 ioctl(1, TCGETS, {B38400 opost isig icanon echo ...}) = 0
70 ioctl(2, TCGETS, {B38400 opost isig icanon echo ...}) = 0
70 ioctl(0, TIOCGPGRP, [68]) = 0
70 getpgid(0) = 68
70 fstat(0, {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
70 fstat(1, {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
70 fstat(2, {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
70 ioctl(0, TIOCGWINSZ, {ws_row=31, ws_col=126, ws_xpixel=0, ws_ypixel=0}) = 0
70 ioctl(0, SNDCTL_TMR_START or TCSETS, {B38400 -opost -isig -icanon -echo ...}) = 0
70 dup(0) = 4
70 socket(AF_VSOCK, SOCK_STREAM|SOCK_CLOEXEC, 0) = 5
70 bind(5, {sa_family=AF_VSOCK, sa_data="\0\0\377\377\377\377\377\377\377\377\0\0\0\0"}, 16) = 0
70 getsockname(5, {sa_family=AF_VSOCK, sa_data="\0\0b\4\0\0\377\377\377\377\0\0\0\0"}, [16]) = 0
70 listen(5, 4) = 0
70 write(3, "\6\0\0\0\253\0\0\0b\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 171) = 171
70 accept4(5, {sa_family=AF_VSOCK, sa_data="\0\0\374\0\0\200\377\377\377\377\0\0\0\0"}, [16], SOCK_CLOEXEC) = 6
70 accept4(5, {sa_family=AF_VSOCK, sa_data="\0\0\375\0\0\200\377\377\377\377\0\0\0\0"}, [16], SOCK_CLOEXEC) = 7
70 accept4(5, {sa_family=AF_VSOCK, sa_data="\0\0\376\0\0\200\377\377\377\377\0\0\0\0"}, [16], SOCK_CLOEXEC) = 8
70 accept4(5, {sa_family=AF_VSOCK, sa_data="\0\0\377\0\0\200\377\377\377\377\0\0\0\0"}, [16], SOCK_CLOEXEC) = 9
70 close(5) = 0
70 rt_sigprocmask(SIG_BLOCK, [INT WINCH], NULL, 8) = 0
70 signalfd4(-1, [INT WINCH], 8, 0) = 5
70 poll([{fd=0, events=POLLIN}, {fd=7, events=POLLIN}, {fd=8, events=POLLIN}, {fd=9, events=POLLIN}, {fd=5, events=POLLIN}], 5, -1) = 1 ([{fd=9, revents=POLLIN}])
70 recvfrom(9, "\t\0\0\0 \0\0\0", 8, MSG_WAITALL, NULL, NULL) = 8
70 brk(0x2035000) = 0x2035000
70 recvfrom(9, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 24, 0, NULL, NULL) = 24
70 poll([{fd=0, events=POLLIN}, {fd=7, events=POLLIN}, {fd=8, events=POLLIN}, {fd=9, events=POLLIN}, {fd=5, events=POLLIN}], 5, -1) = 1 ([{fd=7, revents=POLLIN}])
70 read(7, "\33[6n", 4096) = 4
70 write(1, "\33[6n", 4) = 4
70 poll([{fd=0, events=POLLIN}, {fd=7, events=POLLIN}, {fd=8, events=POLLIN}, {fd=9, events=POLLIN}, {fd=5, events=POLLIN}], 5, -1) = 1 ([{fd=0, revents=POLLIN}])
70 read(0, "\33[7;1R", 4096) = 6
70 write(6, "\33[7;1R", 6) = 6
70 poll([{fd=0, events=POLLIN}, {fd=7, events=POLLIN}, {fd=8, events=POLLIN}, {fd=9, events=POLLIN}, {fd=5, events=POLLIN}], 5, -1) = 1 ([{fd=7, revents=POLLIN}])
70 read(7, "\33[m\33]0;C:\\WINDOWS\\system32\\cmd.e"..., 4096) = 41
70 write(1, "\33[m\33]0;C:\\WINDOWS\\system32\\cmd.e"..., 41) = 41
70 poll([{fd=0, events=POLLIN}, {fd=7, events=POLLIN}, {fd=8, events=POLLIN}, {fd=9, events=POLLIN}, {fd=5, events=POLLIN}], 5, -1) = 3 ([{fd=7, revents=POLLIN}, {fd=8, revents=POLLIN}, {fd=9, revents=POLLIN}])
70 read(7, "", 4096) = 0
70 read(8, "", 4096) = 0
70 recvfrom(9, "\7\0\0\0\f\0\0\0", 8, MSG_WAITALL, NULL, NULL) = 8
70 recvfrom(9, "\0\0\0\0", 4, 0, NULL, NULL) = 4
70 poll([{fd=0, events=POLLIN}, {fd=-1}, {fd=-1}, {fd=9, events=POLLIN}, {fd=5, events=POLLIN}], 5, 0) = 1 ([{fd=9, revents=POLLIN}])
70 recvfrom(9, "", 8, MSG_WAITALL, NULL, NULL) = 0
70 poll([{fd=0, events=POLLIN}, {fd=-1}, {fd=-1}, {fd=-1}, {fd=5, events=POLLIN}], 5, 0) = 0 (Timeout)
70 close(3) = 0
70 close(5) = 0
70 close(6) = 0
70 close(7) = 0
70 close(8) = 0
70 close(9) = 0
70 ioctl(4, SNDCTL_TMR_START or TCSETS, {B38400 opost isig icanon echo ...}) = 0
70 close(4) = 0
70 exit_group(0) = ?
70 +++ exited with 0 +++
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment