unhide-20110113-2-omv2015.0.i586.rpm


Advertisement

Description

unhide - Tool to find hidden processes and TCP/UDP ports from rootkits

Property Value
Distribution OpenMandriva Lx 3.0
Repository OpenMandriva Contrib Release i586
Package name unhide
Package version 20110113
Package release 2-omv2015.0
Package architecture i586
Package type rpm
Installed size 53.51 KB
Download size 23.56 KB
Official Mirror abf-downloads.openmandriva.org
Unhide is a forensic tool to find hidden processes and TCP/UDP ports by
rootkits / LKMs or by another hidden technique. It includes two
utilities: unhide and unhide-tcp.
Unhide detects hidden processes using six techniques:
- Compare /proc vs /bin/ps output
- Compare info gathered from /bin/ps with info gathered by walking through
the procfs.
- Compare info gathered from /bin/ps with info gathered from syscalls
(syscall scanning).
- Full PIDs space occupation (PIDs bruteforcing)
- Reverse search, verify that all thread seen by ps are also seen by
the kernel ( /bin/ps output vs /proc, procfs walking and syscall )
- Quick compare /proc, procfs walking and syscall vs /bin/ps output.
Unhide-tcp identifies TCP/UDP ports that are listening but are not listed
in /bin/netstat through brute forcing of all TCP/UDP ports available.

Alternatives

Package Version Architecture Repository
unhide-20110113-2-omv2015.0.x86_64.rpm 20110113 x86_64 OpenMandriva Contrib Release
unhide - - -

Requires

Name Value
libc.so.6 -
libc.so.6(GLIBC_2.0) -
libc.so.6(GLIBC_2.1) -
libc.so.6(GLIBC_2.3) -
libc.so.6(GLIBC_2.3.4) -
libc.so.6(GLIBC_2.4) -
libpthread.so.0 -
libpthread.so.0(GLIBC_2.0) -
libpthread.so.0(GLIBC_2.1) -

Provides

Name Value
unhide == 20110113-2:2015.0

Download

Type URL
Binary Package unhide-20110113-2-omv2015.0.i586.rpm
Source Package unhide-20110113-2.src.rpm

Install Howto

  1. Enable OpenMandriva Contrib Release repository on Install and Remove Software
  2. Update packages list:
    # urpmi.update -a
  3. Install unhide rpm package:
    # urpmi unhide

Files

Path
/usr/sbin/unhide
/usr/sbin/unhide-linux26
/usr/sbin/unhide-tcp
/usr/share/doc/unhide/LEEME.txt
/usr/share/doc/unhide/README.txt
/usr/share/doc/unhide/changelog
/usr/share/man/man8/unhide-linux26.8.xz
/usr/share/man/man8/unhide-tcp.8.xz
/usr/share/man/man8/unhide.8.xz

See Also

Package Description
uniconvertor-1.1.5-6-omv2015.0.i586.rpm Universal vector graphics translator
unignuplot-2.0-9-omv2015.0.noarch.rpm Simplify the command line interface with GNUPlot
unison-2.40.102-2-omv2015.0.i586.rpm File-synchronization tool for Unix and Windows
unity-asset-pool-0.8.23-2-omv2015.0.noarch.rpm Pool of assets for Unity (icons)
unix2dos-2.2-12-omv2015.0.i586.rpm UNIX to DOS text file format converter
unixcw-3.1.1-1-omv2015.0.i586.rpm Shared library for Morse programs
unknown-horizons-2013.2-1-omv2013.0.noarch.rpm A popular economy and city building 2D RTS game
unknown-horizons-data-2013.2-1-omv2013.0.noarch.rpm Games data for the unknown-horizons game
unpackssi-20030612-2-omv2015.0.i586.rpm .SSI File Unpacker
unpaper-0.4.2-2-omv2015.0.i586.rpm Post-processing scanned and photocopied book pages
unrtf-0.21.9-2-omv2015.0.i586.rpm RTF to other formats converter
unsermake-0.4-6-omv2015.0.noarch.rpm Buildsystem utility to supersed auto* tools
unshield-0.6-5-omv2015.0.i586.rpm A program to extract InstallShield cabinet files
unvanquished-0.47.0-1-omv2015.0.i586.rpm Sci-fi RTS and FPS game
unvanquished-data-0.47.0-1-omv2015.0.noarch.rpm Sci-fi RTS and FPS game
Advertisement
Advertisement