LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-21-2011, 10:57 AM   #1
ButterflyMelissa
Senior Member
 
Registered: Nov 2007
Location: Somewhere on my hard drive...
Distribution: Manjaro
Posts: 2,766
Blog Entries: 23

Rep: Reputation: 411Reputation: 411Reputation: 411Reputation: 411Reputation: 411
openme - what is that?


Hi,

Maybe not a question for this very forum...but I have a paranoid mind...

I scan the local folder once in a while and I found a hidden foldercalled openme, is that for open M E ? does the folder invite me to open it up?

Any ideas?

Tnx

Thor

Edit : in the mean time, I did a virusscan (yea-yea, but I had to undergo windows once way back when so...) and that came up blank. So, what's for me to learn here?

Last edited by ButterflyMelissa; 04-21-2011 at 11:21 AM.
 
Old 04-21-2011, 11:53 AM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Quote:
scan the local folder once in a while and I found a hidden foldercalled openme
That is an interesting one. I have never heard of it. While it is rare for Linux systems to experience viruses there are other forms of problem ware, like trojen horses, etc.
Before doing much with it, I would check who owns the file, what are the permissions on it and is it executable, where is it located and is the location suspicious? I would also look for a setuid or setguid, which could indicate that it will operate with elevated permissions.

As long as nothing appears really out of the ordinary, like being in a /tmp file, owned by root with setuid, I would think you should be able to open the file with an editor like Vim and be reasonably safe. Just be sure to do so from an ordinary user account and don't execute the file.

Last edited by Noway2; 04-21-2011 at 11:54 AM. Reason: fixed misworded sentance
 
Old 04-21-2011, 11:56 AM   #3
paulsm4
LQ Guru
 
Registered: Mar 2004
Distribution: SusE 8.2
Posts: 5,863
Blog Entries: 1

Rep: Reputation: Disabled
Q: You haven't been playing "Open Middle Earth", have you ?

PS:
Check out your "mystery directory" from the command line. Provided you don't double-click on anything from a GUI, you should be safe. "ls -la", "less", "file" and "strings" are your friends
 
Old 04-21-2011, 12:13 PM   #4
ButterflyMelissa
Senior Member
 
Registered: Nov 2007
Location: Somewhere on my hard drive...
Distribution: Manjaro
Posts: 2,766

Original Poster
Blog Entries: 23

Rep: Reputation: 411Reputation: 411Reputation: 411Reputation: 411Reputation: 411
Thanks guys...

Hey! there is a game called "Open Middle Earth" now???

Well, I seem to be owner-and-all of the thing, it has a "cache" folder, in there are some folders, all seem to be from around the time I first installed the system...

If it's "bad" - the time stamps could have been different.

Eh - false alarm, it seemed, but nothing learned...

@ Noway2 - I've seen a virus in action on a corp lan - messy , if there's one word for it. That is why I moved (ya know MV as it completely) to Linux, the only thing humming here...

Lemme close the thread...thanking you guys for the reactions! I do appreciate this!

Thor
 
  


Reply

Tags
openme


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration