Linux vps-61133.fhnet.fr 4.9.0-19-amd64 #1 SMP Debian 4.9.320-2 (2022-06-30) x86_64
Apache/2.4.25 (Debian)
Server IP : 93.113.207.21 & Your IP : 216.73.216.35
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
sbin /
Delete
Unzip
Name
Size
Permission
Date
Action
a2disconf
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2dismod
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2dissite
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2enconf
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2enmod
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2ensite
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2query
9.64
KB
-rwxr-xr-x
2022-03-18 13:54
accessdb
10.23
KB
-rwxrwxrwx
2016-12-13 14:10
add-shell
860
B
-rwxrwxrwx
2017-04-02 19:10
addgnupghome
3.01
KB
-rwxrwxrwx
2019-02-07 21:57
addgroup
33.7
KB
-rwxrwxrwx
2016-06-27 00:55
adduser
33.7
KB
-rwxrwxrwx
2016-06-27 00:55
anacron
34.02
KB
-rwxr-xr-x
2017-05-29 18:36
apache2
651.16
KB
-rwxr-xr-x
2022-03-18 13:54
apache2ctl
7.05
KB
-rwxr-xr-x
2019-10-13 17:39
apachectl
7.05
KB
-rwxr-xr-x
2019-10-13 17:39
applygnupgdefaults
2.17
KB
-rwxrwxrwx
2019-02-07 21:57
arp
62.03
KB
-rwxrwxrwx
2016-12-26 06:58
arpaname
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
arpd
46.84
KB
-rwxrwxrwx
2017-11-24 10:22
aspell-autobuildhash
13.22
KB
-rwxrwxrwx
2016-10-10 11:58
backup-manager
6.94
KB
-rwxrwxrwx
2016-08-23 12:51
bacula-console
44.77
KB
-rwxr-xr-x
2020-08-26 20:03
bacula-fd
239.47
KB
-rwxr-xr-x
2020-08-26 20:03
bconsole
44.77
KB
-rwxr-xr-x
2020-08-26 20:03
biosdecode
18.82
KB
-rwxrwxrwx
2016-09-01 04:59
bsmtp
18.52
KB
-rwxr-xr-x
2020-08-26 20:03
btraceback
2.27
KB
-rwxr-xr-x
2020-08-26 20:03
check_forensic
952
B
-rwxr-xr-x
2011-04-26 17:10
chgpasswd
57.8
KB
-rwxr-xr-x
2021-03-17 10:27
chpasswd
49.9
KB
-rwxr-xr-x
2021-03-17 10:27
chroot
38.88
KB
-rwxrwxrwx
2017-02-22 13:23
clamd
202.1
KB
-rwxr-xr-x
2022-05-27 11:18
clamonacc
190.09
KB
-rwxr-xr-x
2022-05-27 11:18
convertquota
71.74
KB
-rwxrwxrwx
2018-02-24 07:55
cpgr
52
KB
-rwxr-xr-x
2021-03-17 10:27
cppw
52
KB
-rwxr-xr-x
2021-03-17 10:27
cron
47.48
KB
-rwxr-xr-x
2021-10-29 22:04
dbconfig-generate-include
12.37
KB
-rwxrwxrwx
2017-01-05 20:23
dbconfig-load-include
5.57
KB
-rwxrwxrwx
2017-01-05 20:23
ddns-confgen
17.99
KB
-rwxr-xr-x
2022-03-19 14:43
delgroup
15.43
KB
-rwxrwxrwx
2016-06-27 00:55
deluser
15.43
KB
-rwxrwxrwx
2016-06-27 00:55
dmidecode
102.49
KB
-rwxrwxrwx
2016-09-01 04:59
dnssec-checkds
10.66
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-coverage
28.07
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-dsfromkey
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-dsfromkey-pkcs11
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-importkey
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-importkey-pkcs11
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keyfromlabel
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keyfromlabel-pkcs11
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keygen
62
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keygen-pkcs11
62
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-revoke
46
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-revoke-pkcs11
46
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-settime
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-settime-pkcs11
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-signzone
102.03
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-signzone-pkcs11
102.03
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-verify
46.01
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-verify-pkcs11
46.01
KB
-rwxr-xr-x
2022-03-19 14:43
dovecot
86.09
KB
-rwxr-xr-x
2021-01-05 13:19
dpkg-preconfigure
3.52
KB
-rwxrwxrwx
2017-05-21 19:08
dpkg-reconfigure
4.23
KB
-rwxrwxrwx
2017-05-21 19:08
e2freefrag
10.07
KB
-rwxrwxrwx
2020-07-25 11:03
e4crypt
22.07
KB
-rwxrwxrwx
2020-07-25 11:03
e4defrag
25.99
KB
-rwxrwxrwx
2020-07-25 11:03
edquota
80.11
KB
-rwxrwxrwx
2018-02-24 07:55
fdformat
30.66
KB
-rwxrwxrwx
2018-03-07 19:29
filefrag
14.02
KB
-rwxrwxrwx
2020-07-25 11:03
genccode
10.59
KB
-rwxr-xr-x
2021-10-12 12:29
gencmn
10.64
KB
-rwxr-xr-x
2021-10-12 12:29
genl
50.79
KB
-rwxrwxrwx
2017-11-24 10:22
gennorm2
43.38
KB
-rwxr-xr-x
2021-10-12 12:29
genrandom
10
KB
-rwxr-xr-x
2022-03-19 14:43
gensprep
18.98
KB
-rwxr-xr-x
2021-10-12 12:29
groupadd
57.86
KB
-rwxr-xr-x
2021-03-17 10:27
groupdel
53.65
KB
-rwxr-xr-x
2021-03-17 10:27
groupmems
53.84
KB
-rwxr-xr-x
2021-03-17 10:27
groupmod
68.22
KB
-rwxr-xr-x
2021-03-17 10:27
grpck
53.77
KB
-rwxr-xr-x
2021-03-17 10:27
grpconv
49.65
KB
-rwxr-xr-x
2021-03-17 10:27
grpunconv
49.65
KB
-rwxr-xr-x
2021-03-17 10:27
grub-bios-setup
790.19
KB
-rwxrwxrwx
2019-06-12 13:20
grub-install
996.58
KB
-rwxrwxrwx
2019-06-12 13:20
grub-macbless
777.88
KB
-rwxrwxrwx
2019-06-12 13:20
grub-mkconfig
7.82
KB
-rwxrwxrwx
2019-06-12 13:20
grub-mkdevicemap
204.47
KB
-rwxrwxrwx
2019-06-12 13:20
grub-probe
790.19
KB
-rwxrwxrwx
2019-06-12 13:20
grub-reboot
4.01
KB
-rwxrwxrwx
2019-06-12 13:20
grub-set-default
3.48
KB
-rwxrwxrwx
2019-06-12 13:20
httxt2dbm
9.99
KB
-rwxr-xr-x
2022-03-18 13:54
iconvconfig
22.66
KB
-rwxrwxrwx
2019-02-06 22:17
icupkg
19.18
KB
-rwxr-xr-x
2021-10-12 12:29
inetd
34.38
KB
-rwxrwxrwx
2017-01-02 11:49
install-sgmlcatalog
4.44
KB
-rwxrwxrwx
2016-11-07 08:06
invoke-rc.d
17.69
KB
-rwxrwxrwx
2017-05-02 12:20
ip6tables-apply
6.85
KB
-rwxrwxrwx
2017-04-12 11:41
iptables-apply
6.85
KB
-rwxrwxrwx
2017-04-12 11:41
irqbalance
55.38
KB
-rwxrwxrwx
2017-03-10 19:56
isc-hmac-fixup
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
ispell-autobuildhash
15.39
KB
-rwxrwxrwx
2016-10-10 11:58
ldattach
30.71
KB
-rwxrwxrwx
2018-03-07 19:29
locale-gen
1.5
KB
-rwxrwxrwx
2017-07-31 16:32
logrotate
75.27
KB
-rwxrwxrwx
2017-01-07 19:54
logwatch
58
KB
-rwxr-xr-x
2017-01-21 17:44
make-ssl-cert
3.78
KB
-rwxrwxrwx
2017-04-28 21:58
mkinitramfs
10.01
KB
-rwxrwxrwx
2017-04-26 03:00
mklost+found
9.99
KB
-rwxrwxrwx
2020-07-25 11:03
mysqld
17.05
MB
-rwxr-xr-x
2021-03-22 19:49
named
622.24
KB
-rwxr-xr-x
2022-03-19 14:43
named-checkconf
34.19
KB
-rwxr-xr-x
2022-03-19 14:43
named-checkzone
30.19
KB
-rwxr-xr-x
2022-03-19 14:43
named-compilezone
30.19
KB
-rwxr-xr-x
2022-03-19 14:43
named-journalprint
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
named-pkcs11
622.24
KB
-rwxr-xr-x
2022-03-19 14:43
named-rrchecker
13.99
KB
-rwxr-xr-x
2022-03-19 14:43
netfilter-persistent
1.05
KB
-rwxr-xr-x
2020-05-02 21:33
newusers
78.43
KB
-rwxr-xr-x
2021-03-17 10:27
nfnl_osf
13.99
KB
-rwxrwxrwx
2017-04-12 11:41
nginx
1.01
MB
-rwxr-xr-x
2021-06-07 21:02
nologin
5.99
KB
-rwxr-xr-x
2021-03-17 10:27
nsec3hash
10
KB
-rwxr-xr-x
2022-03-19 14:43
ntp-keygen
73.77
KB
-rwxrwxrwx
2018-02-15 12:45
ntp-wait
3.13
KB
-rwxrwxrwx
2018-02-15 12:45
ntpd
713.22
KB
-rwxrwxrwx
2018-02-15 12:45
ntpdate
75.17
KB
-rwxrwxrwx
2018-02-15 12:45
ntpdate-debian
534
B
-rwxrwxrwx
2018-02-15 12:45
ntptime
18.12
KB
-rwxrwxrwx
2018-02-15 12:45
ownership
10.13
KB
-rwxrwxrwx
2016-09-01 04:59
pam-auth-update
19.03
KB
-rwxrwxrwx
2017-05-27 17:44
pam_getenv
2.82
KB
-rwxrwxrwx
2017-05-27 17:44
pam_timestamp_check
10.37
KB
-rwxrwxrwx
2017-05-27 17:44
paperconfig
4.07
KB
-rwxrwxrwx
2016-11-11 12:28
passenger-memory-stats
5.65
KB
-rwxrwxrwx
2019-03-17 19:40
passenger-status
10.68
KB
-rwxrwxrwx
2019-03-17 19:40
phpdismod
7.11
KB
-rwxrwxrwx
2017-01-01 20:43
phpenmod
7.11
KB
-rwxrwxrwx
2017-01-01 20:43
phpquery
6.26
KB
-rwxrwxrwx
2017-01-01 20:43
pkcs11-destroy
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
pkcs11-keygen
15.58
KB
-rwxr-xr-x
2022-03-19 14:43
pkcs11-list
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
pkcs11-tokens
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
pma-configure
299
B
-rwxr-xr-x
2020-10-23 11:41
pma-secure
157
B
-rwxr-xr-x
2020-10-23 11:41
postalias
17.99
KB
-rwxr-xr-x
2020-02-16 20:59
postcat
14.06
KB
-rwxr-xr-x
2020-02-16 20:59
postconf
175.28
KB
-rwxr-xr-x
2020-02-16 20:59
postdrop
14.12
KB
-rwxr-sr-x
2020-02-16 20:59
postfix
14.07
KB
-rwxr-xr-x
2020-02-16 20:59
postfix-add-filter
4.9
KB
-rwxrwxrwx
2020-02-16 20:59
postfix-add-policy
3.83
KB
-rwxrwxrwx
2020-02-16 20:59
postkick
9.99
KB
-rwxr-xr-x
2020-02-16 20:59
postlock
9.99
KB
-rwxr-xr-x
2020-02-16 20:59
postlog
10.15
KB
-rwxr-xr-x
2020-02-16 20:59
postmap
17.99
KB
-rwxr-xr-x
2020-02-16 20:59
postmulti
26.38
KB
-rwxr-xr-x
2020-02-16 20:59
postqueue
22.07
KB
-rwxr-sr-x
2020-02-16 20:59
postsuper
22.32
KB
-rwxr-xr-x
2020-02-16 20:59
posttls-finger
34.09
KB
-rwxrwxrwx
2020-02-16 20:59
pure-authd
18.41
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd
161.4
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd-control
1.68
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd-virtualchroot
165.4
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd-wrapper
12.16
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpwho
22.02
KB
-rwxrwxrwx
2016-12-08 13:28
pure-mrtginfo
9.99
KB
-rwxrwxrwx
2016-12-08 13:28
pure-quotacheck
14.01
KB
-rwxrwxrwx
2016-12-08 13:28
pure-uploadscript
14.26
KB
-rwxrwxrwx
2016-12-08 13:28
pwck
49.84
KB
-rwxr-xr-x
2021-03-17 10:27
pwconv
45.74
KB
-rwxr-xr-x
2021-03-17 10:27
pwunconv
41.72
KB
-rwxr-xr-x
2021-03-17 10:27
qmqp-sink
13.99
KB
-rwxrwxrwx
2020-02-16 20:59
qmqp-source
18.01
KB
-rwxrwxrwx
2020-02-16 20:59
qshape
12.55
KB
-rwxrwxrwx
2020-02-16 20:59
quot
67.48
KB
-rwxrwxrwx
2018-02-24 07:55
quota_nld
75.8
KB
-rwxrwxrwx
2018-02-24 07:55
quotastats
14.38
KB
-rwxrwxrwx
2018-02-24 07:55
quotatool
26.45
KB
-rwxrwxrwx
2014-12-21 21:54
readprofile
18.59
KB
-rwxrwxrwx
2018-03-07 19:29
remove-default-ispell
2.86
KB
-rwxrwxrwx
2016-10-10 11:58
remove-default-wordlist
2.86
KB
-rwxrwxrwx
2016-10-10 11:58
remove-shell
904
B
-rwxrwxrwx
2017-04-02 19:10
repquota
72.05
KB
-rwxrwxrwx
2018-02-24 07:55
rmail
13.99
KB
-rwxrwxrwx
2020-02-16 20:59
rmt
55.03
KB
-rwxr-xr-x
2021-11-27 22:50
rmt-tar
55.03
KB
-rwxr-xr-x
2021-11-27 22:50
rndc
29.99
KB
-rwxr-xr-x
2022-03-19 14:43
rndc-confgen
17.99
KB
-rwxr-xr-x
2022-03-19 14:43
rpc.rquotad
75.96
KB
-rwxrwxrwx
2018-02-24 07:55
rsyslogd
636.3
KB
-rwxr-xr-x
2022-05-20 21:25
rtcwake
42.81
KB
-rwxrwxrwx
2018-03-07 19:29
safe_finger
10.08
KB
-rwxrwxrwx
2016-12-26 00:08
select-default-ispell
3.23
KB
-rwxrwxrwx
2016-10-10 11:58
select-default-wordlist
3.21
KB
-rwxrwxrwx
2016-10-10 11:58
sendmail
26.15
KB
-rwxr-xr-x
2020-02-16 20:59
service
9.83
KB
-rwxrwxrwx
2017-05-02 12:20
setquota
84.11
KB
-rwxrwxrwx
2018-02-24 07:55
smartctl
663.63
KB
-rwxrwxrwx
2016-07-30 19:10
smartd
591.07
KB
-rwxrwxrwx
2016-07-30 19:10
smtp-sink
30.93
KB
-rwxrwxrwx
2020-02-16 20:59
smtp-source
22.02
KB
-rwxrwxrwx
2020-02-16 20:59
snmpd
30.01
KB
-rwxr-xr-x
2020-08-04 17:15
split-logfile
2.36
KB
-rwxr-xr-x
2022-03-18 13:54
sshd
772.48
KB
-rwxrwxrwx
2019-07-15 15:32
tarcat
936
B
-rwxr-xr-x
2021-11-27 22:50
tcpd
10
KB
-rwxrwxrwx
2016-12-26 00:08
tcpdchk
22.13
KB
-rwxrwxrwx
2016-12-26 00:08
tcpdmatch
18.04
KB
-rwxrwxrwx
2016-12-26 00:08
tcpdump
1007.6
KB
-rwxr-xr-x
2020-11-10 15:22
tcptraceroute
1.56
KB
-rwxrwxrwx
2016-08-29 17:45
tcptraceroute.db
1.56
KB
-rwxrwxrwx
2016-08-29 17:45
traceroute
67.16
KB
-rwxrwxrwx
2016-08-29 17:45
try-from
10
KB
-rwxrwxrwx
2016-12-26 00:08
tsig-keygen
17.99
KB
-rwxr-xr-x
2022-03-19 14:43
tunelp
26.61
KB
-rwxrwxrwx
2018-03-07 19:29
tzconfig
106
B
-rwxr-xr-x
2019-10-11 09:23
ufw
4.4
KB
-rwx------
2017-01-10 22:16
unhide
38.26
KB
-rwxrwxrwx
2019-12-17 18:08
unhide-linux
38.26
KB
-rwxrwxrwx
2019-12-17 18:08
unhide-posix
10
KB
-rwxrwxrwx
2019-12-17 18:08
unhide-tcp
18.85
KB
-rwxrwxrwx
2019-12-17 18:08
unhide.rb
13.97
KB
-rwxrwxrwx
2015-11-09 01:23
unhide_rb
14.09
KB
-rwxrwxrwx
2019-12-17 18:08
update-ca-certificates
4.85
KB
-rwxr-xr-x
2021-03-13 18:38
update-catalog
9.15
KB
-rwxrwxrwx
2016-11-07 08:06
update-default-aspell
1
KB
-rwxrwxrwx
2016-10-10 11:58
update-default-ispell
9.68
KB
-rwxrwxrwx
2016-10-10 11:58
update-default-wordlist
7.5
KB
-rwxrwxrwx
2016-10-10 11:58
update-dictcommon-aspell
1
KB
-rwxrwxrwx
2016-10-10 11:58
update-dictcommon-hunspell
782
B
-rwxrwxrwx
2016-10-10 11:58
update-grub
64
B
-rwxrwxrwx
2019-06-12 13:20
update-grub2
64
B
-rwxrwxrwx
2019-06-12 13:20
update-gsfontmap
450
B
-rwxr-xr-x
2022-05-01 17:15
update-inetd
6.05
KB
-rwxrwxrwx
2017-01-15 12:37
update-initramfs
8.02
KB
-rwxrwxrwx
2017-03-06 23:42
update-locale
2.99
KB
-rwxrwxrwx
2016-03-21 00:45
update-mime
8.84
KB
-rwxrwxrwx
2016-05-01 13:20
update-passwd
30.41
KB
-rwxrwxrwx
2017-01-16 16:52
update-rc.d
15.69
KB
-rwxrwxrwx
2017-05-02 12:20
update-xmlcatalog
16.88
KB
-rwxrwxrwx
2016-11-07 15:53
upgrade-from-grub-legacy
1.49
KB
-rwxrwxrwx
2019-06-12 13:20
useradd
119.29
KB
-rwxr-xr-x
2021-03-17 10:27
userdel
82.49
KB
-rwxr-xr-x
2021-03-17 10:27
usermod
119.1
KB
-rwxr-xr-x
2021-03-17 10:27
validlocale
1.73
KB
-rwxrwxrwx
2016-03-21 00:45
vigr
60.22
KB
-rwxr-xr-x
2021-03-17 10:27
vipw
60.22
KB
-rwxr-xr-x
2021-03-17 10:27
visudo
200.34
KB
-rwxr-xr-x
2021-01-23 10:10
vpddecode
14.27
KB
-rwxrwxrwx
2016-09-01 04:59
warnquota
84.11
KB
-rwxrwxrwx
2018-02-24 07:55
xqmstats
14.36
KB
-rwxrwxrwx
2018-02-24 07:55
zic
42.54
KB
-rwxrwxrwx
2019-02-06 22:17
Save
Rename
#!/usr/bin/ruby -w # Try to find running processes using different methods, and report # processes found through some means but not through others. # # Exit code 2 means something fishy was detected. # # Exit code 1 means something went wrong. # Copyright 2009 by Johan Walles, johan.walles@gmail.com # # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation, either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program. If not, see <http://www.gnu.org/licenses/>. require 'set' require 'fiddle/import' require 'fiddle/struct' # Support for libc functions not covered by the standard Ruby # libraries module LibC if RUBY_VERSION =~ /^1\.8/ extend Fiddle::Importable else extend Fiddle::Importer end dlload "libc.so.6" # PID scanning functions extern "int getsid(int)" extern "int sched_getscheduler(int)" extern "int sched_getparam(int, void*)" extern "int sched_rr_get_interval(int, void*)" extern "int sched_getaffinity(int, int, void*)" extern "int readlink(char *, char *, int)" extern "int kill(int, int)" # We want to ask sysinfo about the number of active PIDs. This # result struct has been taken from the sysinfo(2) Linux man page. SysInfoData = struct [ "long uptime", "long loads[3]", "long totalram", "long freeram", "long sharedram", "long bufferram", "long totalswap", "long freeswap", "short procs", "long padding[42]" ] extern "int sysinfo(void *)" end # A piece of scratch memory where system calls can fill in # information. What's written here is not interesting, it's just that # some of the PID scanning functions need a memory area to write into. scratch = "\0" * 1024 # Make sure our scratch buffer is large enough for sched_getaffinity() while LibC.sched_getaffinity(0, scratch.length, scratch) == -1 scratch = "\0" * (scratch.length * 2) end $proc_parent_pids = nil $proc_tasks = nil $ps_pids = nil $proc_readdir_pids = nil def setup # List all parent processes pointed out by anybody in /proc $proc_parent_pids = Set.new proc_dir = Dir.new("/proc") proc_dir.each do |proc_entry| next unless File.directory?("/proc/" + proc_entry) next unless proc_entry =~ /^[0-9]+$/ status_file = File.new("/proc/#{proc_entry}/status") begin status_file.each_line do |line| line.chomp! next unless line =~ /^ppid:\s+([0-9]+)$/i ppid = $1.to_i $proc_parent_pids << ppid break end ensure status_file.close end end proc_dir.close # List all thread pids in /proc $proc_tasks = {} proc_dir = Dir.new("/proc") proc_dir.each do |proc_entry| next unless File.directory?("/proc/" + proc_entry) next unless proc_entry =~ /^[0-9]+$/ task_dir = Dir.new("/proc/#{proc_entry}/task") begin task_dir.each do |task_pid| next unless task_pid =~ /^[0-9]+$/ # "true" means we *have* an executable exe = true begin # Store the *name* of the executable exe = File.readlink("/proc/#{proc_entry}/task/#{task_pid}/exe") rescue Errno::EACCES, Errno::ENOENT # This block intentionally left blank end $proc_tasks[task_pid.to_i] = exe end ensure task_dir.close end end proc_dir.close # List all PIDs displayed by ps $ps_pids = {} $ps_pids.default = false ps_stdout = IO.popen("ps axHo lwp,cmd", "r") ps_pid = ps_stdout.pid ps_stdout.each_line do |ps_line| ps_line.chomp! next unless ps_line =~ /^\s*([0-9]+)\s+([^ ]+).*$/ pid = $1.to_i exe = $2 $ps_pids[pid] = exe end ps_stdout.close # Remove the ps process itself from our pid list $ps_pids.delete ps_pid # List all pids found by readdir on /proc $proc_readdir_pids = Set.new Dir.open("/proc").each do |dir| next unless dir =~ /^[0-9]+$/ $proc_readdir_pids << dir.to_i end end # Return errno after last library call def get_errno() return Fiddle.respond_to?("last_error") ? Fiddle::last_error : Fiddle::last_error end # This array contains named PID detectors. Given a PID to examine they # can say: # * true (it exists) # * "some string" (it exists, and here is its name) # * false (it doesn't exist) # * nil (don't know) $pid_detectors = [ ["ps", proc { |pid| # Does "ps" list this pid? $ps_pids[pid] }], ["/proc naive", lambda { |pid| # Is there a /proc entry for this pid? File.directory?("/proc/#{pid}") }], ["/proc readdir", lambda { |pid| # Did we find this pid when listing the contents of /proc? if $proc_readdir_pids.include?(pid) true else nil end }], ["/proc opendir", lambda { |pid| # Is there a /proc entry for this pid that we can do opendir() on? begin Dir.open("/proc/#{pid}") true rescue Errno::ENOENT false end }], ["/proc/<pid>/status", lambda { |pid| # Parse the process name out of /proc/1234/status begin process_name = true File.open("/proc/#{pid}/status").each do |line| next unless line =~ /Name:[\t ]+(.*)$/ process_name = $1 break end process_name rescue Errno::ENOENT false end }], ["/proc readlink", lambda { |pid| # Read the /proc/1234/exe entry for this pid begin File.readlink("/proc/#{pid}/exe") rescue Errno::EACCES "<run unhide.rb as root to identify exe>" rescue Errno::ENOENT # Some kernel processes have unreadable symlinks in /proc/1234/pid, and # we can't tell "unreadable symlink" apart from "process doesn't exist" nil end }], ["/proc libc-readlink", lambda { |pid| # Is this process visible by the readlink libc function? # The result of this can differ from File.readlink() if # somebody has preloaded a library that overrides certain # libc functions as described here: # http://sourceforge.net/mailarchive/message.php?msg_id=28258660 length = LibC.readlink("/proc/#{pid}/exe", scratch, scratch.length) if length >= 0 scratch[0..(length - 1)] else case get_errno() when 2 # ENOENT # Some kernel processes have unreadable symlinks in /proc/1234/pid, and # we can't tell "unreadable symlink" apart from "process doesn't exist" nil when 13 # EACCES "<run unhide.rb as root to identify exe>" else raise "Unknown errno #{errno}" end end }], ["/proc tasks", proc { |pid| # Is there a /proc/1234/tasks/pid directory for # this pid? $proc_tasks[pid] }], ["/proc parent", proc { |pid| # Does any /proc entry point this pid out as a # parent pid? if $proc_parent_pids.include? pid true else nil end }], ["/proc chdir", proc { |pid| # Can we chdir into /proc/<pid>? begin Dir::chdir "/proc/#{pid}" true rescue Errno::ENOENT false end }], ["getsid()", proc { |pid| LibC.getsid(pid) != -1 }], ["getpgid()", proc { |pid| exists = true begin Process.getpgid(pid) rescue exists = false end exists }], ["getpriority()", proc { |pid| exists = true begin Process.getpriority(Process::PRIO_PROCESS, pid) rescue exists = false end exists }], ["sched_getparam()", proc { |pid| LibC.sched_getparam(pid, scratch) != -1 }], ["sched_getaffinity()", proc { |pid| LibC.sched_getaffinity(pid, scratch.length, scratch) != -1 }], ["sched_getscheduler()", proc { |pid| LibC.sched_getscheduler(pid) != -1 }], ["kill(pid, 0)", proc { |pid| if LibC.kill(pid, 0) == 0 true else case get_errno when 1 # EPERM true when 3 # ESRCH false else raise "Unknown errno #{errno}" end end }] ] found_something = false # Scan PIDs and report those found by some means but not others # # Returns a map of pids->warning strings def get_suspicious_pids(pids_to_scan = nil) if pids_to_scan == nil pid_max = File.new("/proc/sys/kernel/pid_max").gets.to_i pids_to_scan = (1..pid_max) end return_me = Hash.new pids_to_scan.each do |pid| pid_exists = {} $pid_detectors.each do |pid_detector| detector_name = pid_detector[0] detector_proc = pid_detector[1] pid_exists[detector_name] = detector_proc.call(pid) end # Is there consensus about the existence of this process? suspicious = false existence_consensus = nil pid_exists.values.each do |existence| # Always over-write "don't know" existence_consensus = existence if existence_consensus == nil # This one is undecisive, skip it next if existence == nil # Does the result of this test match the consensus? if existence_consensus == false unless existence == false suspicious = true break end else # Anything but "false" is considered to be true, can be a string # with a process name in it for example if existence == false suspicious = true break end end end if suspicious # Put output in a string and add it to the return result message = "Suspicious PID #{pid}:" $pid_detectors.each do |detector| detector_name = detector[0] detector_result = pid_exists[detector_name] next if detector_result == nil description = "" description = " (\"#{detector_result}\")" if detector_result.class == String message += sprintf("\n %s: %s%s", detector_result ? " Seen by" : "Invisible to", detector_name, description) end return_me[pid] = message end end return return_me end ## ## Main program starts here ## puts "Scanning for hidden processes..." setup # Check for unknown preloads. This will name the Jynx LD Poisoning # library. suspicious_mappings = Set.new File.open("/proc/self/maps").each do |line| next unless line =~ /[^\/]*(\/.*)$/ mapped_file = $1 next if File::exist? mapped_file suspicious_mappings << mapped_file end unless suspicious_mappings.empty? found_something = true STDERR.puts "I have a mapped file (or more) that I can't access! Results may be wrong." STDERR.puts "Check /etc/ld.so.preload or dynamic linker for compromise:" suspicious_mappings.each do |mapping| STDERR.puts " #{mapping}" end end # Verify PID count between ps and sysinfo() sysinfo = LibC::SysInfoData.malloc if LibC.sysinfo(sysinfo) == -1 STDERR.puts "Error: failed calling sysinfo()" exit 1 end if sysinfo.procs != $ps_pids.size $stderr.puts "ps and sysinfo() process count mismatch:" $stderr.puts " ps: #{$ps_pids.size} processes" $stderr.puts " sysinfo(): #{sysinfo.procs} processes" found_something = true end suspicious_pids = get_suspicious_pids unless suspicious_pids.empty? # Filter out false positives by testing all positives again. False # positives occur when we race with processes starting up or # shutting down. setup still_suspicious_pids = get_suspicious_pids(suspicious_pids.keys) still_suspicious_pids.keys.sort.each do |still_suspicious_pid| warning_text = suspicious_pids[still_suspicious_pid] next unless warning_text found_something = true $stderr.puts warning_text end end if found_something exit 2 else puts "No hidden processes found!" end