Skip to content

Instantly share code, notes, and snippets.

@Firebasky
Forked from Dbof/memdump.py
Created December 14, 2024 16:41
Show Gist options
  • Save Firebasky/7da6288721c8482881c2222c5fa0198c to your computer and use it in GitHub Desktop.
Save Firebasky/7da6288721c8482881c2222c5fa0198c to your computer and use it in GitHub Desktop.

Revisions

  1. @Dbof Dbof revised this gist Mar 26, 2021. No changes.
  2. @Dbof Dbof created this gist Mar 26, 2021.
    35 changes: 35 additions & 0 deletions memdump.py
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,35 @@
    #! /usr/bin/env python3
    import sys
    import re

    if __name__ == "__main__":

    if len(sys.argv) != 2:
    print('Usage:', sys.argv[0], '<process PID>', file=sys.stderr)
    exit(1)

    pid = sys.argv[1]

    # maps contains the mapping of memory of a specific project
    map_file = f"/proc/{pid}/maps"
    mem_file = f"/proc/{pid}/mem"

    # output file
    out_file = f'{pid}.dump'

    # iterate over regions
    with open(map_file, 'r') as map_f, open(mem_file, 'rb', 0) as mem_f, open(out_file, 'wb') as out_f:
    for line in map_f.readlines(): # for each mapped region
    m = re.match(r'([0-9A-Fa-f]+)-([0-9A-Fa-f]+) ([-r])', line)
    if m.group(3) == 'r': # readable region
    start = int(m.group(1), 16)
    end = int(m.group(2), 16)
    mem_f.seek(start) # seek to region start
    print(hex(start), '-', hex(end))
    try:
    chunk = mem_f.read(end - start) # read region contents
    out_f.write(chunk) # dump contents to standard output
    except OSError:
    print(hex(start), '-', hex(end), '[error,skipped]', file=sys.stderr)
    continue
    print(f'Memory dump saved to {out_file}')