Bug#531315: Please try with unhide.rb

Christoph Anton Mitterer christoph.anton.mitterer at lmu.de
Fri Jan 4 15:11:07 UTC 2013


On Fri, 2013-01-04 at 15:46 +0100, Johan Walles wrote:
> Can you post the output of running unhide.rb (from the package of the same
> name) on the system where you're seeing false positives with aptitude?
I checked with unhide.rb ... and it shows no hidden processeds when
aptitude is running (i.e. it is in the package list view... I must admit
that I do not exactly remember what I did back then in aptitude).

I've also checked again with "normal" unhide... and while it shows 1
hidden process... it seems not to be connected with aptitude running.



> The ruby version is much faster than the C version and is much less prone
> to false positives.
But doesn't the ruby version check much less?



Anyway... from that I'd guess we could close this bug.


Cheers,
Chris.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3811 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/forensics-devel/attachments/20130104/ae20c290/attachment.bin>


More information about the forensics-devel mailing list