Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
A process owned by root looking for .*history files
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
ferg
Guru
Guru


Joined: 15 Nov 2002
Posts: 538
Location: Cambridge, UK

PostPosted: Wed Oct 02, 2024 7:11 pm    Post subject: A process owned by root looking for .*history files Reply with quote

I just noticed a process yesterday searching across my filesystem for *.history files. I noticed it as I plugged in a USB drive (from a Time machine backup on OS X) and after afew minutes tried to umount it without any luck as a process was locking it.

When I looked this process was running:

Code:
root     22815 22325  9 Oct01 ?        01:13:34 /usr/bin/find // ! -fstype nfs -name .*history -size 0


I immediately killed the process and then regretted it as I have no idea what was running it.

Today I noticed the same process running. I assume this is some hack attempt looking through user's history files to glean some useful information.

I pulled the ethernet cable as soon as I saw this process, but could now do with some assistance in identifying where it comes from. I looked through all cron folders and logs and there's nothing. But there again I do not really know what I'm looking for!

This box (running a daily updated Gentoo) has SSH open to my LAN although no root login. The only user has only key logins enabled. Also no ports are forwarded. It does have tailscale installed and running.
Thanks!
_________________
Climb up it, kayak down it + make sure it runs on GNU/Linux
"cease to exist, giving my goodbye, drive my car into the ocean,
you think I'm dead, but i sail away, on a wave of mutilation!"
Back to top
View user's profile Send private message
ferg
Guru
Guru


Joined: 15 Nov 2002
Posts: 538
Location: Cambridge, UK

PostPosted: Wed Oct 02, 2024 8:33 pm    Post subject: Reply with quote

Ahhh. I'm a bit daft aren't I!

I missed the "-size 0" from that process. I just thought it was some process that was looking for history files.

However, it's more likely to be something looking for empty history files. Which would be evidence that somebody has hacked a box and tried to hide their steps. Does Chkrootkit do something like this? I wonder why I've never noticed this before.
_________________
Climb up it, kayak down it + make sure it runs on GNU/Linux
"cease to exist, giving my goodbye, drive my car into the ocean,
you think I'm dead, but i sail away, on a wave of mutilation!"
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum