Package : unhide > RPM : unhide-20110113-1.mga1.i586.rpm
Basic items
InstallName | unhide |
Version | 20110113 |
Release | 1.mga1 |
URL | http://www.unhide-forensics.info/ |
Group | System/Configuration/Other |
Summary | Tool to find hidden processes and TCP/UDP ports from rootkits |
Size | 50KB |
Arch | i586 |
License | GPLv3+ |
Description
Unhide is a forensic tool to find hidden processes and TCP/UDP ports by
rootkits / LKMs or by another hidden technique. It includes two
utilities: unhide and unhide-tcp.
Unhide detects hidden processes using six techniques:
- Compare /proc vs /bin/ps output
- Compare info gathered from /bin/ps with info gathered by walking through
the procfs.
- Compare info gathered from /bin/ps with info gathered from syscalls
(syscall scanning).
- Full PIDs space occupation (PIDs bruteforcing)
- Reverse search, verify that all thread seen by ps are also seen by
the kernel ( /bin/ps output vs /proc, procfs walking and syscall )
- Quick compare /proc, procfs walking and syscall vs /bin/ps output.
Unhide-tcp identifies TCP/UDP ports that are listening but are not listed
in /bin/netstat through brute forcing of all TCP/UDP ports available.
rootkits / LKMs or by another hidden technique. It includes two
utilities: unhide and unhide-tcp.
Unhide detects hidden processes using six techniques:
- Compare /proc vs /bin/ps output
- Compare info gathered from /bin/ps with info gathered by walking through
the procfs.
- Compare info gathered from /bin/ps with info gathered from syscalls
(syscall scanning).
- Full PIDs space occupation (PIDs bruteforcing)
- Reverse search, verify that all thread seen by ps are also seen by
the kernel ( /bin/ps output vs /proc, procfs walking and syscall )
- Quick compare /proc, procfs walking and syscall vs /bin/ps output.
Unhide-tcp identifies TCP/UDP ports that are listening but are not listed
in /bin/netstat through brute forcing of all TCP/UDP ports available.
Media information
Distribution release | Mageia 2 |
Media name | core-release |
Media arch | i586 |
Advanced items
Source RPM | unhide-20110113-1.mga1.src.rpm |
Build time | 2011-02-08 21:04:22 |
Changelog | View in Sophie |
Files | View in Sophie |
Dependencies | View in Sophie |