ÿØÿà JFIF    ÿÛ „  ( %"1!%)+...383,7(-.+  -+++--++++---+-+-----+---------------+---+-++7-----ÿÀ  ß â" ÿÄ     ÿÄ H    !1AQaq"‘¡2B±ÁÑð#R“Ò Tbr‚²á3csƒ’ÂñDS¢³$CÿÄ   ÿÄ %  !1AQa"23‘ÿÚ   ? ôÿ ¨pŸªáÿ —åYõõ\?àÒü©ŠÄï¨pŸªáÿ —åYõõ\?àÓü©ŠÄá 0Ÿªáÿ Ÿå[úƒ ú®ði~TÁbqÐ8OÕpÿ ƒOò¤Oè`–RÂáœá™êi€ßÉ< FtŸI“öÌ8úDf´°å}“¾œ6  öFá°y¥jñÇh†ˆ¢ã/ÃÐ:ªcÈ "Y¡ðÑl>ÿ ”ÏËte:qž\oäŠe÷󲍷˜HT4&ÿ ÓÐü6ö®¿øþßèô Ÿ•7Ñi’•j|“ñì>b…þS?*Óôÿ ÓÐü*h¥£ír¶ü UãS炟[AÐaè[ûª•õ&õj?†Éö+EzP—WeÒírJFt ‘BŒ†Ï‡%#tE Øz ¥OÛ«!1›üä±Í™%ºÍãö]°î(–:@<‹ŒÊö×òÆt¦ãº+‡¦%ÌÁ²h´OƒJŒtMÜ>ÀÜÊw3Y´•牋4ǍýʏTì>œú=Íwhyë,¾Ôò×õ¿ßÊa»«þˆѪQ|%6ž™A õ%:øj<>É—ÿ Å_ˆCbõ¥š±ý¯Ýƒï…¶|RëócÍf溪“t.СøTÿ *Ä¿-{†çàczůŽ_–^XþŒ±miB[X±d 1,é”zEù»& î9gœf™9Ð'.;—™i}!ôšåîqêÛ٤ёý£½ÆA–àôe"A$˝Úsäÿ ÷Û #°xŸëí(l »ý3—¥5m! rt`†0~'j2(]S¦¦kv,ÚÇ l¦øJA£Šƒ J3E8ÙiŽ:cÉžúeZ°€¯\®kÖ(79«Ž:¯X”¾³Š&¡* ….‰Ž(ÜíŸ2¥ª‡×Hi²TF¤ò[¨íÈRëÉ䢍mgÑ.Ÿ<öäS0í„ǹÁU´f#Vß;Õ–…P@3ío<ä-±»Ž.L|kªÀê›fÂ6@»eu‚|ÓaÞÆŸ…¨ááå>åŠ?cKü6ùTÍÆ”†sĤÚ;H2RÚ†õ\Ö·Ÿn'¾ ñ#ºI¤Å´%çÁ­‚â7›‹qT3Iï¨ÖÚ5I7Ë!ÅOóŸ¶øÝñØôת¦$Tcö‘[«Ö³šÒ';Aþ ¸èíg A2Z"i¸vdÄ÷.iõ®§)¿]¤À†–‡É&ä{V¶iŽ”.Ó×Õÿ û?h¬Mt–íª[ÿ Ñÿ ÌV(í}=ibÔ¡›¥¢±b Lô¥‡piη_Z<‡z§èŒ)iÖwiÇ 2hÙ3·=’d÷8éŽ1¦¸c¤µ€7›7Ø ð\á)} ¹fËí›pAÃL%âc2 í§æQz¿;T8sæ°qø)QFMð‰XŒÂ±N¢aF¨…8¯!U  Z©RÊ ÖPVÄÀÍin™Ì-GˆªÅËŠ›•zË}º±ŽÍFò¹}Uw×#ä5B¤{î}Ð<ÙD é©¤&‡ïDbàÁôMÁ." ¤‡ú*õ'VŽ|¼´Úgllº¼klz[Æüï÷Aób‡Eÿ dÑ»Xx9ÃÜ£ÁT/`¼¸vI±Ýµ·Ë‚“G³þ*Ÿû´r|*}<¨îºœ @¦mÄ’M¹”.œ«Y–|6ÏU¤jç¥ÕÞqO ˜kDÆÁ¨5ÿ š;ÐЦ¦€GÙk \ –Þ=â¼=SͧµªS°ÚÍpÜãQűÀõ¬?ÃÁ1Ñ•õZà?hóœ€ L¦l{Y*K˜Ù›zc˜–ˆâ ø+¾ ­-Ök¥%ùEÜA'}ˆ><ÊIè“bpÍ/qÞâvoX€w,\úªò6Z[XdÒæ­@Ö—€$òJí#é>'°Ú ôª˜<)4ryÙ£|óAÅn5žêŸyÒäMÝ2{"}‰–¤l÷ûWX\l¾Á¸góÉOÔ /óñB¤f¸çñ[.P˜ZsÊË*ßT܈§QN¢’¡¨§V¼(Üù*eÕ“”5T¨‹Âê¥FŒã½Dü[8'Ò¥a…Ú¶k7a *•›¼'Ò·\8¨ª\@\õ¢¦íq+DÙrmÎ…_ªæ»ŠÓœ¡¯’Ré9MÅ×D™lælffc+ŒÑ,ý™ÿ ¯þǤ=Å’Á7µ÷ÚÛ/“Ü€ñýã¼àí¾ÕÑ+ƒ,uµMâÀÄbm:ÒÎPæ{˜Gz[ƒ¯«® KHà`ߨŠéí¯P8Aq.C‰ à€kòpj´kN¶qô€…Õ,ÜNŠª-­{Zö’æû44‰sŽè‰îVíRœÕm" 6?³D9¡ÇTíÅꋇ`4«¸ÝÁô ï’ýorqКÇZ«x4Žâéþuïf¹µö[P ,Q£éaX±`PÉÍZ ¸äYúg üAx ’6Lê‚xÝÓ*äQ  Ï’¨hÍ =²,6ï#rÃ<¯–£»ƒ‹,–ê•€ aÛsñ'%Æ"®ÛüìBᝠHÚ3ß°©$“XnœÖ’î2ËTeûìxîß ¦å¿çÉ ðK§þ{‘t‚Ϋ¬jéîZ[ ”š7L¥4VÚCE×]m¤Øy”ä4-dz£œ§¸x.*ãÊÊ b÷•h:©‡¦s`BTÁRû¾g⻩‹jø sF¢àJøFl‘È•Xᓁà~*j¯ +(ÚÕ6-£¯÷GŠØy‚<Ç’.F‹Hœw(+)ÜÜâÈzÄäT§FߘãÏ;DmVœ3Àu@mÚüXÝü•3B¨òÌÁÛ<·ÃÜ z,Ì@õÅ·d2]ü8s÷IôÞ¯^Ç9¢u„~ëAŸï4«M? K]­ÅàPl@s_ p:°¬ZR”´›JC[CS.h‹ƒïËœ«Æ]–÷ó‚wR×k7X‰k›‘´ù¦=¡«‰¨¨Â')—71ó’c‡Ðúµ `é.{§p¹ój\Ž{1h{o±Ý=áUÊïGÖŒõ–-BÄm+AZX¶¡ ïHðæ¥JmÙ;…䡟ˆ¦ ° äšiÉg«$üMk5¤L“’çÊvïâï ,=f“"íἊ5ô¬x6{ɏžID0e¸vçmi'︧ºð9$ò¹÷*£’9ÿ ²TÔ…×>JV¥}Œ}$p[bÔ®*[jzS*8 ”·T›Í–ñUîƒwo$áè=LT™ç—~ô·¤ÈÚ$榍q‰„+´kFm)ž‹©i–ËqÞŠ‰à¶ü( ‚•§ •°ò·‡#5ª•µÊ﯅¡X¨šÁ*F#TXJÊ ušJVÍ&=iÄs1‚3•'fý§5Ñ<=[íÞ­ PÚ;ѱÌ_~Ä££8rÞ ²w;’hDT°>ÈG¬8Á²ÚzŽ®ò®qZcqJêäÞ-ö[ܘbň±çb“ж31²n×iƒðÕ;1¶þÉ ªX‰,ßqÏ$>•î íZ¥Z 1{ç൵+ƒÕµ¥°T$§K]á»Ûï*·¤tMI’ÂZbŽÕiÒ˜}bÓ0£ª5›¨ [5Ž^ÝœWøÂÝh° ¢OWun£¤5 a2Z.G2³YL]jåtì”ä ÁÓ‘%"©<Ôúʰsº UZvä‡ÄiÆÒM .÷V·™ø#kèýiíÌ–ª)µT[)BˆõÑ xB¾B€ÖT¨.¥~ð@VĶr#¸ü*åZNDŽH;âi ],©£öØpù(šºãö¼T.uCê•4@ÿ GÕÛ)Cx›®0ø#:ÏðFÒbR\(€€Ä®fã4Þ‰Fä¯HXƒÅ,†öEÑÔÜ]Öv²?tLÃvBY£ú6Êu5ÅAQ³1‘’¬x–HŒÐ‡ ^ ¸KwJôÖŽ5×CÚ¨vÜ«/B0$×k°=ðbÇ(Ï)w±A†Á† 11Í=èQšµ626ŒÜ/`G«µ<}—-Ö7KEHÈÉðóȤmݱû±·ø«Snmá=“䫚mݱŸ¡¶~ó·“äUóJæúòB|E LêŽy´jDÔ$G¢þÐñ7óR8ýÒ…Ç› WVe#·Ÿ p·Fx~•ݤF÷0Èÿ K¯æS<6’¡WШ; ´ÿ ¥Êø\Òuî†åÝ–VNœkÒ7oòX¨Á­Ø÷FÎÑä±g÷ÿ M~Çî=p,X´ ÝÌÚÅ‹’ÃjÖ.ØöÏñ qïQ¤ÓZE†° =6·]܈ s¸>v•Ž^Ý\wq9r‰Î\¸¡kURÒ$­*‹Nq?Þª*!sŠÆ:TU_u±T+øX¡ ®¹¡,ÄâÃBTsÜ$Ø›4m椴zÜK]’’›Pƒ @€#â˜`é¹=I‡fiV•Ôî“nRm+µFPOhÍ0B£ €+¬5c v•:P'ÒyÎ ‰V~‚Ó†ÖuókDoh$å\*ö%Ю=£«…aȼ½÷Û.-½VŒŠ¼'lyî±1¬3ó#ÞE¿ÔS¤gV£m›=§\û"—WU¤ÚǼÿ ÂnÁGŒÃ ‚õN D³õNÚíŒÕ;HôyÄÈ©P¹Ä{:?R‘Ô¨âF÷ø£bÅó® JS|‚R÷ivýáâ€Æé¡è³´IئÑT!§˜•ت‚¬â@q€wnïCWÄ@JU€ê¯m6]Ï:£âx'+ÒðXvÓ¦Úm=–´7œ $ì“B£~p%ÕŸUþ« N@¼üï~w˜ñø5®—'Ôe»¤5ã//€ž~‰Tþ›Å7•#¤× Íö pÄ$ùeåì*«ÓŠEØWEÈsßg ¦ûvžSsLpºÊW–âµEWöˬH; ™!CYõZ ÃÄf æ#1W. \uWâ\,\Çf j’<qTbên›Î[vxx£ë 'ö¨1›˜ÀM¼Pÿ H)ƒêêŒA7s,|F“ 꺸k³9Ìö*ç®;Ö!Ö$Eiž•¹ÒÚ†ýóéÝû¾ÕS®ó$’NÝäŸz¤5r¦ãÄÃD÷Üø!°ø‡Ô&@m™Ì^Ãä­d q5Lnÿ N;.6½·N|#ä"1Nƒx“ã<3('&ñßt  ~ªu”1Tb㫨9ê–›–bìd$ߣ=#ÕãÒmU¯eí$EFù5ýYô櫨æì™Ç—±ssM]·á¿0ÕåJRÓªîiƒ+O58ÖñªŠÒx" \µâá¨i’¤i —Ö ” M+M¤ë9‚‰A¦°Qõ¾ßøK~¼Ã‘g…Ö´~÷Ï[3GUœÒ½#…kàÔ®Ò”‰³·dWV‰IP‰Ú8u¹”E ÖqLj¾êÕCBš{A^Âß;–¨`¯¬ìö ˼ ×tìø.tƐm*n¨y4o&Àx¥n¦×î‡aupáÛj8¿m›è¶ã!o½;ß0y^ý×^EÑ¿ÒjzŒ­)vÚÑnÄL …^ªô× ‡—‚3k Îý­hï]içå–îÏ*÷ñþ»Ô CÒjøjÍznˆ´ ¹#b'Fô‹ ‰v¥'’à'T´ƒHýÍ%M‰ ƒ&ÆÇŒï1 ‘ –Þ ‰i¬s žR-Ÿ kЬá¬7:þ 0ŒÅÒÕ/aÙ¬ÃÝ#Úøœ ©aiVc‰. ¹¦ãµ” ›Yg¦›ÆÎýº°f³7ƒhá·¸­}&D9¡ÂsÉÙÞèŠõØàC™¨ñbFC|´Ü(ŸƒÚÒ-%»'a Ì¿)ËÇn¿úÿ ÞŽX…4ÊÅH^ôΑí@ù¹Eh¶“L8Çjù ¼ÎåVªóR©Ï5uà V4lZß®=€xÖŸ–ÑÈ ÷”¨°¾__yM1tÉ?uÆþIkÄgæ@þ[¢†°XÃJ£j·:nkÅ¢u ‘}âGzö­/IµèЬ¼48q¦F°ŽR¼=ûì{´¯RýicS ÕÛ íNtÍÙï£,w4rêì®»~x(©Uñ§#Ñ&œÕ¤>ÎåÍÓ9’Ö{9eV­[Öjâ²ãu]˜å2›qÑšÕJç0€sÄ|Êëè0튔bÁ>“{×_F`Ø©ºê:µä,v¤ðfc1±"«ÔÍän1#=· Âøv~H½ÐßA¾¿Ü€Óš]Õ; I¾÷ç‚Qi†î¹9ywÔKG˜áñ zQY—§ÃÕZ07§X‚ Áh;ÁM)iÌCH-¯T‘ë|A0{Ò½LÚ–TâÖkÜ’dÀ“rmm»”جPF³ÖcbE§T€ÒxKºû’Ó®7±²(\4ŽÃ¸Uu@j™yĵ;³µ!Á¢b.W¤=mõ´êµK k ¸K^ÜÛ#p*Ü14qkZç5ïë †°5Ï%ÍÛ<Õ¤×Ô¥ê†C Õ´¼ú$ƒÖ“”]Ù¬qÞÚ[4©ý!ûÏ—Áb쳐XµA¬â~`›Çr¸8ìùÝ䫦<>ä÷«?xs´ÇÑ /á;¹øüÊÈÙà{"@Žïzâ¬[âß‚ U_<ÇŸ½4èN˜ú61®qŠu ¦þF£»äJ_ˆÙÎ~ ÞAã–݄ϗrŠD;xTž‘ô`É«…suãO`?³à™ô Lý#Íc5öoæØ‚y´´÷«ZR§<&JÇ+éâô´€i!Àˆ0æAoàðLèÖ-2ŸõW.’t^–(KÁmHµV@xÜÇy®Ñø­â^:Ú3w· 7½¹°ñ¸â¹®:',«Mœ—n­Á+Ãbš LÈ‘ÄnRÓÅœ%¦²‰¨ùQ:¤f‚ "PÕtô¸…cæl…&˜Ú˜Ôkv‹ž+vŠ,=¢v­6—Xy*¥t£«<™:“aîϲ=¦6rO]XI¿Œ÷¤zÚ­›¶ 6÷”w\d ü~v®ˆÌk«^m<ÿ ¢‰Õ\)ùºŽ;… lîÙÅEŠ®cѾ@vnMÏ,¼“ñ•ŽBxðÃzãÇç%3ˆ"}Ù•Åî> BÉú;Ò]V+P˜F_´ßé> Øše|ï‡ÄOmFæÇ ãqÞ$/xÐx­z`ï9"œÜij‚!7.\Td…9M‡•iŽ‹¾‘50ÞŽn¥ß4ÉôO ¹*í^QêËÜÇÌ8=ާs‰'ÂëÙ«á%Pú[O †ÅP¯Vsް.‰,kc¶ ¬A9n˜XÎ-ÞšN["¹QÕ‰ƒMýÁߺXJæÍaLj¾×Ãmã¾ãÚ uñÒþåQô¦¥ /ÄUx:‚ÍÜ’ Đ©ØÝ3V¨‰ÕnÐ6ó*óúK­«…c ¯U òhsý­jóÔj#,ímŒRµ«lbïUTŒÑ8†Ä0œÏr`ð¡¬É Ї ë"À² ™ 6¥ f¶ ¢ÚoܱԷ-<Àî)†a¶ž'Ú»¨TXqØæ¶÷YÄHy˜9ÈIW­YÀuMFë ºÏ’AqÌ4·/Ú †ô'i$øä­=Ä Ý|öK×40è|È6p‘0§)o¥ctî§H+CA-“ xØ|ÐXАç l8íºð3Ø:³¤¬KX¯UÿÙ#!/usr/bin/ruby -w # Try to find running processes using different methods, and report # processes found through some means but not through others. # # Exit code 2 means something fishy was detected. # # Exit code 1 means something went wrong. # Copyright 2009 by Johan Walles, johan.walles@gmail.com # # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation, either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program. If not, see . require 'set' require 'fiddle/import' require 'fiddle/struct' # Support for libc functions not covered by the standard Ruby # libraries module LibC if RUBY_VERSION =~ /^1\.8/ extend Fiddle::Importable else extend Fiddle::Importer end dlload "libc.so.6" # PID scanning functions extern "int getsid(int)" extern "int sched_getscheduler(int)" extern "int sched_getparam(int, void*)" extern "int sched_rr_get_interval(int, void*)" extern "int sched_getaffinity(int, int, void*)" extern "int readlink(char *, char *, int)" extern "int kill(int, int)" # We want to ask sysinfo about the number of active PIDs. This # result struct has been taken from the sysinfo(2) Linux man page. SysInfoData = struct [ "long uptime", "long loads[3]", "long totalram", "long freeram", "long sharedram", "long bufferram", "long totalswap", "long freeswap", "short procs", "long padding[42]" ] extern "int sysinfo(void *)" end # A piece of scratch memory where system calls can fill in # information. What's written here is not interesting, it's just that # some of the PID scanning functions need a memory area to write into. scratch = "\0" * 1024 # Make sure our scratch buffer is large enough for sched_getaffinity() while LibC.sched_getaffinity(0, scratch.length, scratch) == -1 scratch = "\0" * (scratch.length * 2) end $proc_parent_pids = nil $proc_tasks = nil $ps_pids = nil $proc_readdir_pids = nil def setup # List all parent processes pointed out by anybody in /proc $proc_parent_pids = Set.new proc_dir = Dir.new("/proc") proc_dir.each do |proc_entry| next unless File.directory?("/proc/" + proc_entry) next unless proc_entry =~ /^[0-9]+$/ status_file = File.new("/proc/#{proc_entry}/status") begin status_file.each_line do |line| line.chomp! next unless line =~ /^ppid:\s+([0-9]+)$/i ppid = $1.to_i $proc_parent_pids << ppid break end ensure status_file.close end end proc_dir.close # List all thread pids in /proc $proc_tasks = {} proc_dir = Dir.new("/proc") proc_dir.each do |proc_entry| next unless File.directory?("/proc/" + proc_entry) next unless proc_entry =~ /^[0-9]+$/ task_dir = Dir.new("/proc/#{proc_entry}/task") begin task_dir.each do |task_pid| next unless task_pid =~ /^[0-9]+$/ # "true" means we *have* an executable exe = true begin # Store the *name* of the executable exe = File.readlink("/proc/#{proc_entry}/task/#{task_pid}/exe") rescue Errno::EACCES, Errno::ENOENT # This block intentionally left blank end $proc_tasks[task_pid.to_i] = exe end ensure task_dir.close end end proc_dir.close # List all PIDs displayed by ps $ps_pids = {} $ps_pids.default = false ps_stdout = IO.popen("ps axHo lwp,cmd", "r") ps_pid = ps_stdout.pid ps_stdout.each_line do |ps_line| ps_line.chomp! next unless ps_line =~ /^\s*([0-9]+)\s+([^ ]+).*$/ pid = $1.to_i exe = $2 $ps_pids[pid] = exe end ps_stdout.close # Remove the ps process itself from our pid list $ps_pids.delete ps_pid # List all pids found by readdir on /proc $proc_readdir_pids = Set.new Dir.open("/proc").each do |dir| next unless dir =~ /^[0-9]+$/ $proc_readdir_pids << dir.to_i end end # Return errno after last library call def get_errno() return Fiddle.respond_to?("last_error") ? Fiddle::last_error : Fiddle::last_error end # This array contains named PID detectors. Given a PID to examine they # can say: # * true (it exists) # * "some string" (it exists, and here is its name) # * false (it doesn't exist) # * nil (don't know) $pid_detectors = [ ["ps", proc { |pid| # Does "ps" list this pid? $ps_pids[pid] }], ["/proc naive", lambda { |pid| # Is there a /proc entry for this pid? File.directory?("/proc/#{pid}") }], ["/proc readdir", lambda { |pid| # Did we find this pid when listing the contents of /proc? if $proc_readdir_pids.include?(pid) true else nil end }], ["/proc opendir", lambda { |pid| # Is there a /proc entry for this pid that we can do opendir() on? begin Dir.open("/proc/#{pid}") true rescue Errno::ENOENT false end }], ["/proc//status", lambda { |pid| # Parse the process name out of /proc/1234/status begin process_name = true File.open("/proc/#{pid}/status").each do |line| next unless line =~ /Name:[\t ]+(.*)$/ process_name = $1 break end process_name rescue Errno::ENOENT false end }], ["/proc readlink", lambda { |pid| # Read the /proc/1234/exe entry for this pid begin File.readlink("/proc/#{pid}/exe") rescue Errno::EACCES "" rescue Errno::ENOENT # Some kernel processes have unreadable symlinks in /proc/1234/pid, and # we can't tell "unreadable symlink" apart from "process doesn't exist" nil end }], ["/proc libc-readlink", lambda { |pid| # Is this process visible by the readlink libc function? # The result of this can differ from File.readlink() if # somebody has preloaded a library that overrides certain # libc functions as described here: # http://sourceforge.net/mailarchive/message.php?msg_id=28258660 length = LibC.readlink("/proc/#{pid}/exe", scratch, scratch.length) if length >= 0 scratch[0..(length - 1)] else case get_errno() when 2 # ENOENT # Some kernel processes have unreadable symlinks in /proc/1234/pid, and # we can't tell "unreadable symlink" apart from "process doesn't exist" nil when 13 # EACCES "" else raise "Unknown errno #{errno}" end end }], ["/proc tasks", proc { |pid| # Is there a /proc/1234/tasks/pid directory for # this pid? $proc_tasks[pid] }], ["/proc parent", proc { |pid| # Does any /proc entry point this pid out as a # parent pid? if $proc_parent_pids.include? pid true else nil end }], ["/proc chdir", proc { |pid| # Can we chdir into /proc/? begin Dir::chdir "/proc/#{pid}" true rescue Errno::ENOENT false end }], ["getsid()", proc { |pid| LibC.getsid(pid) != -1 }], ["getpgid()", proc { |pid| exists = true begin Process.getpgid(pid) rescue exists = false end exists }], ["getpriority()", proc { |pid| exists = true begin Process.getpriority(Process::PRIO_PROCESS, pid) rescue exists = false end exists }], ["sched_getparam()", proc { |pid| LibC.sched_getparam(pid, scratch) != -1 }], ["sched_getaffinity()", proc { |pid| LibC.sched_getaffinity(pid, scratch.length, scratch) != -1 }], ["sched_getscheduler()", proc { |pid| LibC.sched_getscheduler(pid) != -1 }], ["kill(pid, 0)", proc { |pid| if LibC.kill(pid, 0) == 0 true else case get_errno when 1 # EPERM true when 3 # ESRCH false else raise "Unknown errno #{errno}" end end }] ] found_something = false # Scan PIDs and report those found by some means but not others # # Returns a map of pids->warning strings def get_suspicious_pids(pids_to_scan = nil) if pids_to_scan == nil pid_max = File.new("/proc/sys/kernel/pid_max").gets.to_i pids_to_scan = (1..pid_max) end return_me = Hash.new pids_to_scan.each do |pid| pid_exists = {} $pid_detectors.each do |pid_detector| detector_name = pid_detector[0] detector_proc = pid_detector[1] pid_exists[detector_name] = detector_proc.call(pid) end # Is there consensus about the existence of this process? suspicious = false existence_consensus = nil pid_exists.values.each do |existence| # Always over-write "don't know" existence_consensus = existence if existence_consensus == nil # This one is undecisive, skip it next if existence == nil # Does the result of this test match the consensus? if existence_consensus == false unless existence == false suspicious = true break end else # Anything but "false" is considered to be true, can be a string # with a process name in it for example if existence == false suspicious = true break end end end if suspicious # Put output in a string and add it to the return result message = "Suspicious PID #{pid}:" $pid_detectors.each do |detector| detector_name = detector[0] detector_result = pid_exists[detector_name] next if detector_result == nil description = "" description = " (\"#{detector_result}\")" if detector_result.class == String message += sprintf("\n %s: %s%s", detector_result ? " Seen by" : "Invisible to", detector_name, description) end return_me[pid] = message end end return return_me end ## ## Main program starts here ## puts "Scanning for hidden processes..." setup # Check for unknown preloads. This will name the Jynx LD Poisoning # library. suspicious_mappings = Set.new File.open("/proc/self/maps").each do |line| next unless line =~ /[^\/]*(\/.*)$/ mapped_file = $1 next if File::exist? mapped_file suspicious_mappings << mapped_file end unless suspicious_mappings.empty? found_something = true STDERR.puts "I have a mapped file (or more) that I can't access! Results may be wrong." STDERR.puts "Check /etc/ld.so.preload or dynamic linker for compromise:" suspicious_mappings.each do |mapping| STDERR.puts " #{mapping}" end end # Verify PID count between ps and sysinfo() sysinfo = LibC::SysInfoData.malloc if LibC.sysinfo(sysinfo) == -1 STDERR.puts "Error: failed calling sysinfo()" exit 1 end if sysinfo.procs != $ps_pids.size $stderr.puts "ps and sysinfo() process count mismatch:" $stderr.puts " ps: #{$ps_pids.size} processes" $stderr.puts " sysinfo(): #{sysinfo.procs} processes" found_something = true end suspicious_pids = get_suspicious_pids unless suspicious_pids.empty? # Filter out false positives by testing all positives again. False # positives occur when we race with processes starting up or # shutting down. setup still_suspicious_pids = get_suspicious_pids(suspicious_pids.keys) still_suspicious_pids.keys.sort.each do |still_suspicious_pid| warning_text = suspicious_pids[still_suspicious_pid] next unless warning_text found_something = true $stderr.puts warning_text end end if found_something exit 2 else puts "No hidden processes found!" end