[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] How to Nail a hidden process.



"MAHESH PATIL" <mahesh_patil_99@xxxxxxxxx> wrote:
> my doubt :  Whether any process running in a system
> can hide from  ps -aux.

Yes, if a hacker used a rootkit to get into your system, then installed a
LKM (Loadable Kernel Module).  See the program LCAP which can prevent this
(to a degree) and grab the program Lsof (stands for LiSt of Open Files,
clever, eh?) and run it and see if you can find anything.  Once you've done
that report your findings and we can be of further assistance.

--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/