Re: hidden processes?



2008/8/29 Zach Uram <netrek@xxxxxxxxx>:
I used the unhide package and found this result, should I be worried?
How can I stop these hidden processes?
I guess if I was you I would install rkhunter and chkrootkit.
Then launch chkrootkit, and 'rkhunter --check' to try to find if a
rootkit is installed on your system inside a Terminal administrator
window.

Could also be just a module, I don't really knows.

Joke: Maybe you could consider upgrading your rootkit to the new
version that knows how to avoid being detected by unhide. :-)

For myself, rkhunter give warning about inetd.
Looking to /etc/services, I found that Debian seems to like to have a
very big file with all known services rather than just add the
services needed. I don't even knows if other distributions does just
add the needed services.

And chkrootkit see that wpa_supplicant and dhclient are sniffing
packets on wireless lan device, which seems fine to me.


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • RE: Have I been hacked? Shadow file deleted
    ... chkrootkit and rkhunter do not report any problem. ... Shadow file deleted ... To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list ...
    (Fedora)
  • Re: chkrootkit and rkhunter are too old ?
    ... chkrootkit last version date from 30/09/2006 and rkhunter date ... Samhain are better then either but more involed in set-up. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • chkrootkit and rkhunter are too old ?
    ... I look for root kit checker. ... chkrootkit last version date from 30/09/2006 and rkhunter date ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Have I been hacked? Shadow file deleted
    ... What about nmap, maybe it could at least give you a port to investigate ... > chkrootkit and rkhunter do not report any problem. ... > On Behalf Of Marc M ...
    (Fedora)
  • Re: Possible Rootkit Or Just Paranoia?
    ... I just run 'Rkhunter' and received the warning below. ... I installed and ran chkrootkit and its showing infected ports in bindshell ... Portsentry was running when I preformed these test. ...
    (comp.unix.bsd.freebsd.misc)