LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 06-25-2002, 02:52 AM   #1
LinuxGeek
Member
 
Registered: Jun 2002
Posts: 302

Rep: Reputation: 31
Spyware Detection Under Linux


I was just wondering how if there was a way to make sure that the software that I am using does not contact a server without me knowing (eg. isn't spyware). I'm referring mostly to applications in which you are not given the source code (ex. Realplayer). I heard somewhere that you can set up an out-going file that monitors this (I read this on comp.os.linux.advocacy) but there were no details and the author could not be contacted. Thanks for your time...
 
Old 06-25-2002, 02:58 AM   #2
JaseP
Senior Member
 
Registered: Jun 2002
Location: Eastern PA, USA
Distribution: K/Ubuntu 18.04-14.04, Scientific Linux 6.3-6.4, Android-x86, Pretty much all distros at one point...
Posts: 1,802

Rep: Reputation: 157Reputation: 157
How about not using RealPlayer or any other program where the source is not provided???

There are alternatives to most of that stuff.

Besides, monitoring of hacking and spyware is mostly a function of setting up the proper security protocols, and monitoring log files to search for suspicious activity. I personally don't bother. My machine is a home machine that isn't too susceptible to outside attack. It's not like Linux is Windoze or anything!!!
 
Old 06-26-2002, 03:42 PM   #3
LinuxGeek
Member
 
Registered: Jun 2002
Posts: 302

Original Poster
Rep: Reputation: 31
Any other solutions? Waiting to hear from you...
 
Old 06-26-2002, 05:15 PM   #4
manaskb
Member
 
Registered: Jan 2002
Location: India
Distribution: Suse , Mandrake
Posts: 121

Rep: Reputation: 15
If you have just a user access on a system ( ie no root access) and say a spyware is installed by the admin then there is nothing much you can do but shout. For instance on a office desktop a spyware may be installed depending on a company's policy.

On a system where you have root access and you have installed it and maintain it, even if a sypware is installed you take a shot at detecting it and removing it.

There can be 2 kinds of sypywares:
1. one that sends information from your system to a remote one. This will have to open a socket connection to a remote system. Ypu can do the following things to detect/protect yourself -
a. install firewall with careful rules
b. you can use netstat -a to find out if any unexpected socket is open
If you see you have a suspicious socket open or suspicious traffic going out then you can choose to sniff the packets using ethereal and see what is going on. If you think thatit is a spyware then remove that application from your system.

2. one that keeps logs("hidden") on the host system itself, so that activity on the system can be latter inspected. Linux apps have all sorts of logs, but if it a spyware then it'll put the logs in some non standard place. This kind of spyware can be difficult to detect if cleaverly written. The spyware may not be even keeping the logs locally but say on a nfs mounted storage. The only foolproof way of detecting this is using "top" watch out for any suspicious( some program that you do not know of) program that is running.

Lets hear what other people have to say on this issue.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Spyware On Linux dj9928 Linux - Software 2 04-16-2005 05:31 PM
spyware in linux? ungua Linux - Security 26 01-11-2005 05:20 PM
Can Linux have spyware? ProtoformX Linux - General 4 03-15-2004 06:51 AM
spyware in Linux? moger Linux - General 1 01-27-2004 04:39 PM
Linux and spyware mfarley Linux - General 3 08-14-2003 12:48 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 04:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration