# mzek-scanproc

> linux: scan /proc for hidden processes

Latest version **1.0.0** (published 2021-08-23) · MIT license · 0 weekly downloads

## Install

```sh
npm install mzek-scanproc
pnpm add mzek-scanproc
yarn add mzek-scanproc
bun add mzek-scanproc
```

Provides the command `scanproc`.

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2021-08-23 |
| First published | 2021-08-23 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Unpacked size | 8.4 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | m-onz |
| Maintainers | mzek |
| Keywords | proc, hidden, processes |

## Links

- npm: https://www.npmjs.com/package/mzek-scanproc
- Repository: https://github.com/mzek/mzek-scanproc
- Homepage: https://github.com/mzek/mzek-scanproc#readme
- Issues: https://github.com/mzek/mzek-scanproc/issues
- npm.io page: https://npm.io/package/mzek-scanproc

## Alternatives

- [@sindresorhus/slugify](https://npm.io/package/@sindresorhus/slugify.md) — 3.7M weekly downloads
- [solid-js](https://npm.io/package/solid-js.md) — 2.7M weekly downloads
- [expo-glass-effect](https://npm.io/package/expo-glass-effect.md) — 2.5M weekly downloads
- [nanoassert](https://npm.io/package/nanoassert.md) — 780.8K weekly downloads
- [@ffmpeg/ffmpeg](https://npm.io/package/@ffmpeg/ffmpeg.md) — 529.5K weekly downloads

## Recent versions

- 1.0.0 (latest) — 2021-08-23

## README

# mzek-scanproc

This is a POC in scanning /proc for hidden processes on linux systems without brute forcing the PID address space..
I was checking out [this article](https://sysdig.com/blog/hiding-linux-processes-for-fun-and-profit/) and I
 created a process hiding kernel module that hides a node js process called `hidden.js`.

I realised that `fs.readdirSync` found the hidden PID that was invisible to `ps aux` or `lsof -ni` during
 my experimentation. This is way faster than iterating through the PID range but I'm not sure if its going 
 to catch every type of hidden processes or how it works yet.

I took inspiration from [this tool from sandfly security](https://www.sandflysecurity.com/blog/linux-stealth-rootkit-process-decloaking-tool-sandfly-processdecloak/) that iterates
 the PID range looking for processes that are hidden.

## install

```
npm i mzek-scanproc -g
```

create a kernel module and load it (see /notes).
```
$ cd ./notes
$ make
$ sudo mv libprocesshider.so /usr/local/lib/
$ echo /usr/local/lib/libprocesshider.so >> /etc/ld.so.preload
$ node hidden.js
```

extracted output showing the hidden PID

```js
{
 '/usr/bin/node',
    '/home/monz/Desktop/experiments/scanproc/hidden.js'
  ],
  execArgv: [],
  pid: 19435,
  ppid: 5363,
  execPath: '/usr/bin/node',
  debugPort: 9229,
  argv0: 'node',
  _preload_modules: [],
}
```

## check for hidden PIDs

```
$ scanproc
<mzek-scanproc>
<mzek-scanproc>
found hidden PIDs  [ 19435 ]
```

## investigation

* does this work with any time of hidden process or just node?
* how does node's fs module detect the PID that is hidden from `ps`?

Leave an issue if you know how this works.

## resources

* [sysdig article](https://sysdig.com/blog/hiding-linux-processes-for-fun-and-profit/)
* [libprocesshider](https://github.com/gianlucaborello/libprocesshider)
* [sandfly-processdecloak](https://github.com/sandflysecurity/sandfly-processdecloak)

---
_Source: https://npm.io/package/mzek-scanproc · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
