linuxÉó²éÀú³ÌËùÔÚ·¾¶
linux ÖÐÀú³ÌµÄ·¾¶¿ÉÒÔͨ¹ýÒÔÏÂÒªÁìÉó²é£º1. ʹÓà ps ÏÂÁî»ñÈ¡ÍêÕûÏÂÁîÐУ»2. Éó²é /proc ÎļþϵͳÖÐµÄ “cmdline” Îļþ£»3. ʹÓà ltrace ÏÂÁî¸ú×Ù execve ϵͳŲÓá£
ÔõÑùÉó²é Linux ÖÐÀú³ÌµÄ·¾¶
Linux ϵͳÖУ¬Àú³ÌµÄ·¾¶¿ÉÒÔͨ¹ýÒÔÏÂÒªÁìÉó²é£º
1. ʹÓà ps ÏÂÁî
ps ÏÂÁî¿ÉÒÔÏÔʾÕýÔÚÔËÐеÄÀú³ÌÐÅÏ¢£¬ÆäÖаüÀ¨Àú³ÌµÄ·¾¶£º
ps -ef | grep <process_name></process_name>
µÇ¼ºó¸´ÖÆ
ÆäÖУº
ÊÇÒª²éÕÒµÄÀú³ÌÃû³Æ¡£
-ef Ñ¡ÏîÏÔʾËùÓÐÕýÔÚÔËÐеÄÀú³Ì£¬²¢°üÀ¨ÍêÕûµÄÏÂÁîÐС£
ÀýÈ磬Ҫ²éÕÒÃûΪ “firefox” µÄÀú³ÌµÄ·¾¶£¬¿ÉÒÔÔËÐÐÒÔÏÂÏÂÁ
ps -ef | grep firefox
µÇ¼ºó¸´ÖÆ
2. ʹÓà /proc Îļþϵͳ
/proc Îļþϵͳ°üÀ¨Ò»¸öÌØÊâÎļþ£¬ÆäÖаüÀ¨Ã¿¸öÀú³ÌµÄÐÅÏ¢£¬°üÀ¨Æä·¾¶¡£¸ÃÎļþÃûΪ “cmdline”£¬Î»ÓÚÒÔÏÂĿ¼ÖУº
/proc/<pid>/cmdline</pid>
µÇ¼ºó¸´ÖÆ
ÆäÖУº
ÊÇÀú³ÌµÄÀú³Ì ID¡£
ÀýÈ磬ҪÉó²éÀú³Ì ID Ϊ 12345 µÄÀú³ÌµÄ·¾¶£¬¿ÉÒÔÔËÐÐÒÔÏÂÏÂÁ
cat /proc/12345/cmdline
µÇ¼ºó¸´ÖÆ
3. ʹÓà ltrace ÏÂÁî
ltrace ÏÂÁî¿ÉÒÔ¸ú×ÙÀú³ÌµÄϵͳŲÓ㬲¢ÏÔʾÀú³ÌËùÖ´ÐеÄÏÂÁîÐУ¬ÆäÖÐÒ²°üÀ¨Àú³ÌµÄ·¾¶¡£
ltrace -p <pid> -a execve</pid>
µÇ¼ºó¸´ÖÆ
ÆäÖУº
ÊÇÒª¸ú×ÙµÄÀú³ÌµÄÀú³Ì ID¡£
-a execve Ñ¡Ïî½ö¸ú×Ù execve ϵͳŲÓ㬸ÃŲÓÃÓÃÓÚÆô¶¯ÐÂÀú³Ì¡£
ÀýÈ磬Ҫ¸ú×ÙÀú³Ì ID Ϊ 12345 µÄÀú³ÌµÄÆô¶¯£¬¿ÉÒÔÔËÐÐÒÔÏÂÏÂÁ
ltrace -p 12345 -a execve
µÇ¼ºó¸´ÖÆ
ÒÔÉϾÍÊÇlinuxÉó²éÀú³ÌËùÔÚ·¾¶µÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡