LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-15-2006, 03:09 PM   #1
svarmido
Member
 
Registered: Apr 2006
Posts: 78

Rep: Reputation: 15
/dev/.udev? Googled, nothing. Searched here, nothing.


Running "rkhunter" brought my attention to this file -
/dev/.udev
/..
/db
/failed

Contents of /db;
block@hda
block@hda@hda1
block@hda@hda10

etc...

Doesn't matter at this point what is in /failed..

Deleting the file /dev/.udev prevents certain programs from running, including "system-config-services"...

Is this a "fake" file setup used by an intruder bypassing /var/run/udev?

svarmido
 
Old 10-15-2006, 04:19 PM   #2
kevkim55
Member
 
Registered: Dec 2005
Location: Edmonton
Distribution: BLFS, Gentoo
Posts: 353

Rep: Reputation: 32
If you are trying to know more about /dev/.udev, guess you should probably look into the udev source code ! Cheers !!
 
Old 10-15-2006, 07:02 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Is this a "fake" file setup used by an intruder bypassing /var/run/udev?
Most likely not, "man udev" for info and if you "grep udev rkhunter.conf" you'll see it's a common dir that can be excluded from scan.
 
Old 10-16-2006, 03:08 PM   #4
svarmido
Member
 
Registered: Apr 2006
Posts: 78

Original Poster
Rep: Reputation: 15
Most likely not? A pretty equivocal response. There is no reference to /dev/.udev anywhere in the man file, only /dev and /etc/udev/. Looking into the source code is not something I have the skill or knowledge to do.

Is /dev/.udev present in others Fedora Core 5 installs?

svarmido
 
Old 10-16-2006, 04:30 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Udev-102.tar.gz, RELEASE-NOTES, line 315:
The option "udev_db" does no longer exist. All udev state will be in /$udev_root/.udev/ now, there is no longer an option to set this to anything else. If the init script or something else used this value, just depend on this hardcoded path. But remember _all_content_ of this directory is still private to udev and can change at any time.
So this is the dir where Udev tools keep state.
 
Old 10-16-2006, 05:00 PM   #6
osor
HCL Maintainer
 
Registered: Jan 2006
Distribution: (H)LFS, Gentoo
Posts: 2,450

Rep: Reputation: 79
Quote:
Originally Posted by svarmido
Most likely not? A pretty equivocal response. There is no reference to /dev/.udev anywhere in the man file, only /dev and /etc/udev/. Looking into the source code is not something I have the skill or knowledge to do.

Is /dev/.udev present in others Fedora Core 5 installs?

svarmido
In older versions of udev, you could set the location of the udev database inside udev.conf (you could set the variable udev_db just like udev_root or udev_rules). If you read the RELEASE-NOTES (specifically lines 315-316), it says there is no longer an option to alter this variable (it will always be set to “/$udev_root/.udev/”) (ever since version 076).
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
udev: /dev/ directory over-populated - why? Yalla-One Slackware 3 08-13-2006 02:47 PM
why has udev swapped /dev/hdc and /dev/hdd ? chaosbear Linux - Hardware 2 08-09-2006 04:23 AM
What is /dev/.udev.tdb? Andriy Slackware 4 04-19-2006 03:13 AM
udev removes /dev/dsp? kushalkoolwal Debian 2 03-05-2006 04:46 PM
how to tell udev to make a dev jimdaworm Slackware 10 08-13-2004 08:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration