Bypassing ptrace calls with LD_PRELOAD on Linux

Hello, Here's a quick article on how to bypass calls to ptrace when debugging a Linux executable. By calling ptrace with the PTRACE_TRACEME option, a process can detect if it's being debugged and execute different instructions. This an effective anti-debugging technique. For example, take the following C program: #include <stdio.h> #include <sys/ptrace.h> int main() { … Continue reading Bypassing ptrace calls with LD_PRELOAD on Linux