View previous topic :: View next topic |
Author |
Message |
i92guboj Bodhisattva
Joined: 30 Nov 2004 Posts: 10315 Location: Córdoba (Spain)
|
Posted: Tue Sep 19, 2017 10:15 am Post subject: Any legit reason why wifite starts silently in background? |
|
|
Today, while I was profiling energy usage in my old t420 laptop I noticed that, from time to time, aircrack-ng appeared at the top of the list. Looking further, I noticed that wifite was also there, a bit lower in the list.
Both sucking quite a bit of wattage, by the way.
What worries me, however, is whether there's any legit reason why wifite launches itself. I have no idea how it's started, and I am certain that I didn't set that up myself. I greped in /etc and a few other places just to check, and nothing turned up that could be spawning wifite or aircrack.
I also noticed that sometimes the webcam module and the sound driver where at the top, even though I wasn't using anything related. This could be related to chrome-ware, though.
In any case, this smells bad, and calls for a disconnect and a serious revision, that is, unless someone here can explain why wifite was acting that way. rkhunter doesn't report anything obvious, but I truly have no idea why wifite fires up itself at random. I kill it and half an hour later it appears again. This seems quite strange to me.
By the way, I installed wifite from the pentoo overlay time ago to test the security of my home wifi and haven't used it much since then. I didn't even remember I had it installed. I tell you that because, even if the pentoo repositories have been tampered with, I haven't launched it for years.
Maybe I am missing something simple here...
Any idea is welcome |
|
Back to top |
|
|
Ant P. Watchman
Joined: 18 Apr 2009 Posts: 6920
|
Posted: Tue Sep 19, 2017 10:35 pm Post subject: |
|
|
Just a guess, but maybe it's hotplug-starting it when it sees the net.wlan script start? udev rules can do some unwanted things too. |
|
Back to top |
|
|
i92guboj Bodhisattva
Joined: 30 Nov 2004 Posts: 10315 Location: Córdoba (Spain)
|
Posted: Wed Sep 20, 2017 2:28 pm Post subject: |
|
|
Ant P. wrote: | Just a guess, but maybe it's hotplug-starting it when it sees the net.wlan script start? udev rules can do some unwanted things too. |
Thanks for the pointer
That's why I greped the whole /etc for signs of aircrack and wifite. So far, nothing turned out. I had one leftover network interface called "mon0", which surely is related to having used this software in the past. I probably set that up myself, even though I don't remember doing it. I can't tell if it's related, somehow, to this strange behavior.
I uninstalled the offending packages, and took some measures to avoid any harm. This laptop is under observation just for forensic purposes, but for the time being I haven't been able to find anything. |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|