unhide - Tool to find hidden processes and TCP/UDP ports from rootkits

Property Value
Distribution OpenMandriva Lx 2013.0
Repository OpenMandriva Contrib Release x86_64
Package name unhide
Package version 20110113
Package release 1-omv2013.0
Package architecture x86_64
Package type rpm
Installed size 59.14 KB
Download size 26.27 KB
Official Mirror abf-downloads.openmandriva.org
Unhide is a forensic tool to find hidden processes and TCP/UDP ports by
rootkits / LKMs or by another hidden technique. It includes two
utilities: unhide and unhide-tcp.
Unhide detects hidden processes using six techniques:
- Compare /proc vs /bin/ps output
- Compare info gathered from /bin/ps with info gathered by walking through
the procfs.
- Compare info gathered from /bin/ps with info gathered from syscalls
(syscall scanning).
- Full PIDs space occupation (PIDs bruteforcing)
- Reverse search, verify that all thread seen by ps are also seen by
the kernel ( /bin/ps output vs /proc, procfs walking and syscall )
- Quick compare /proc, procfs walking and syscall vs /bin/ps output.
Unhide-tcp identifies TCP/UDP ports that are listening but are not listed
in /bin/netstat through brute forcing of all TCP/UDP ports available.


Package Version Architecture Repository
unhide-20110113-1-omv2013.0.i586.rpm 20110113 i586 OpenMandriva Contrib Release
unhide - - -


Name Value
libc.so.6()(64bit) -
libc.so.6(GLIBC_2.2.5)(64bit) -
libc.so.6(GLIBC_2.3)(64bit) -
libc.so.6(GLIBC_2.3.4)(64bit) -
libc.so.6(GLIBC_2.4)(64bit) -
libpthread.so.0()(64bit) -
libpthread.so.0(GLIBC_2.2.5)(64bit) -


Name Value
unhide == 20110113-1:2013.0


Type URL
Binary Package unhide-20110113-1-omv2013.0.x86_64.rpm
Source Package unhide-20110113-1.src.rpm

Install Howto

  1. Enable OpenMandriva Contrib Release repository on Install and Remove Software
  2. Update packages list:
    # urpmi.update -a
  3. Install unhide rpm package:
    # urpmi unhide




2011-02-08 - Jani V?limaa <wally@mandriva.org> 20110113-1mdv2011.0
+ Revision: 636928
- new version 20110113
- fix url and source tags
2010-11-14 - Jani V?limaa <wally@mandriva.org> 20100819-2mdv2011.0
+ Revision: 597542
- build with LDFLAGS
- add symlink for man page too
2010-09-25 - Jani V?limaa <wally@mandriva.org> 20100819-1mdv2011.0
+ Revision: 580960
- new version 20100819
- fix license and description
2010-08-02 - Jani V?limaa <wally@mandriva.org> 20100201-1mdv2011.0
+ Revision: 565116
- fix source tag
- import unhide

See Also

Package Description
uniconvertor-1.1.5-4-omv2013.0.x86_64.rpm Universal vector graphics translator
unignuplot-2.0-8-omv2013.0.noarch.rpm Simplify the command line interface with GNUPlot
unity-asset-pool-0.8.23-1-omv2013.0.noarch.rpm Pool of assets for Unity (icons)
unix2dos-2.2-11-omv2013.0.x86_64.rpm UNIX to DOS text file format converter
unknown-horizons-2013.2-1-omv2013.0.noarch.rpm A popular economy and city building 2D RTS game
unknown-horizons-data-2013.2-1-omv2013.0.noarch.rpm Games data for the unknown-horizons game
unpackssi-20030612-1-omv2013.0.x86_64.rpm .SSI File Unpacker
unrtf-0.21.2-1-omv2013.0.x86_64.rpm RTF to other formats converter
unsermake-0.4-5-omv2013.0.noarch.rpm Buildsystem utility to supersed auto* tools
unshield-0.6-4-omv2013.0.x86_64.rpm A program to extract InstallShield cabinet files
up-0.3-12-omv2013.0.x86_64.rpm Displays the uptime in a human readable format
updateads-1.0-5-omv2013.0.noarch.rpm Update BIND ad server listings
upse-1.0.0-6-omv2013.0.x86_64.rpm Playstation sound emulator
upstart-0.6.3-1-omv2013.0.x86_64.rpm An event-driven init system
uptimed-0.3.17-1-omv2013.0.x86_64.rpm A daemon to record and keep track of system uptimes