On 08.04.2011 14:47, Wayne Topa wrote:
> On 04/07/2011 10:50 PM, James Brown wrote:
>> `unhide` define that there is a hidden process in my system, but don't
>> indicate it concretely:
>>> ~$ sudo unhide sys
>>> Unhide 20100201
>>> http://www.security-projects.com/?Unhide
>>>
>>>
>>>[*]Searching for Hidden processes through kill(..,0) scanning
>>>
>>>[*]Searching for Hidden processes through comparison of results of
>>> system calls
>>>
>>>[*]Searching for Hidden processes through getpriority() scanning
>>>
>>>[*]Searching for Hidden processes through getpgid() scanning
>>>
>>>[*]Searching for Hidden processes through getsid() scanning
>>>
>>>[*]Searching for Hidden processes through sched_getaffinity() scanning
>>>
>>>[*]Searching for Hidden processes through sched_getparam() scanning
>>>
>>>[*]Searching for Hidden processes through sched_getscheduler() scanning
>>>
>>>[*]Searching for Hidden processes through sched_rr_get_interval()
>>> scanning
>>>
>>>[*]Searching for Hidden processes through sysinfo() scanning
>>>
>>> HIDDEN Processes Found: 1
>>
>>
>> How can I find out what is that process?
>>
>>
>
> Maybe
> unhide-posix sys
>
> Which works here with version 20100201-1
>
> WT
>
>
I tried it. That command works wrong: it defineds as "hidden" all
processes in my system which I can see in `top` or `ps ax`.
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 4D9F38E2.9000706@gmail.com">http://lists.debian.org/4D9F38E2.9000706@gmail.com
04-10-2011, 06:02 PM
James Brown
What is the hidden process?
On 08.04.2011 07:20, green wrote:
> James Brown wrote at 2011-04-07 21:50 -0500:
>> `unhide` define that there is a hidden process in my system, but don't
>> indicate it concretely:
>
>> HIDDEN Processes Found: 1
>
> Hmm, interesting. Same result here with sys method, buth nothing is detected
> using the proc and brute methods.
As I can see I have that report about one hidden process permanently.
But when I am running the transmission-daemon on my system I have many
hidden procceses through `unhide brute`.
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 4DA1F0A1.6030804@gmail.com">http://lists.debian.org/4DA1F0A1.6030804@gmail.com