LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-26-2016, 03:25 PM   #1
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Rep: Reputation: 0
New Trojan Spies on Linux Users by Taking Screenshots and Recording Audio - be aware!!!


'Dr.Web, a Russian antivirus maker, has detected a new threat against Linux users, the Linux.Ekocms.1 trojan, which includes special features that allow it to take screengrabs and record audio.' ~ Softpedia

http://news.softpedia.com/news/new-t...o-499113.shtml

If you run Tripwire - then you can add the file paths to check for the trojan.
 
Old 01-26-2016, 05:07 PM   #2
Keith Hedger
Senior Member
 
Registered: Jun 2010
Location: Wiltshire, UK
Distribution: Void, Linux From Scratch, Slackware64
Posts: 3,155

Rep: Reputation: 857Reputation: 857Reputation: 857Reputation: 857Reputation: 857Reputation: 857Reputation: 857
broken link
 
Old 01-26-2016, 05:10 PM   #3
Keith Hedger
Senior Member
 
Registered: Jun 2010
Location: Wiltshire, UK
Distribution: Void, Linux From Scratch, Slackware64
Posts: 3,155

Rep: Reputation: 857Reputation: 857Reputation: 857Reputation: 857Reputation: 857Reputation: 857Reputation: 857
As every post the OP has made sings the praises of tripwire I assume he's a dev, so anything he has to say really should be taken with a pinch of salt
 
Old 01-26-2016, 05:59 PM   #4
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,150

Rep: Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125Reputation: 4125
Looks like it (allegedly) will use random paths.
 
Old 01-27-2016, 12:25 AM   #5
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Original Poster
Rep: Reputation: 0
I try to post the link again.

Code:
http://news.softpedia.com/news/new-trojan-spies-on-linux-users-by-taking-screenshots-and-recording-audio-499113.shtml
 
Old 01-27-2016, 12:28 AM   #6
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,665

Rep: Reputation: Disabled
They fail to describe how it infects the computer. Probably needs to be installed by user.
 
Old 01-27-2016, 12:30 AM   #7
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Original Poster
Rep: Reputation: 0
As every post the OP has made sings the praises of tripwire I assume he's a dev, so anything he has to say really should be taken with a pinch of salt

I don't know what issue you have with me, but i am a linux beginner using Ubuntu home desktop.
I want to know if i have intrusion, then there is as i understand it two options, Aide or Tripwire, both doing the same thing.
Now i was lucky getting help and support from another member at Ubuntu Forum Org to install and configurate tripwire as beginner which made me very happy.

Cheers
 
Old 01-27-2016, 12:53 AM   #8
ardvark71
LQ Veteran
 
Registered: Feb 2015
Location: USA
Distribution: Lubuntu 14.04, 22.04, Windows 8.1 and 10
Posts: 6,282
Blog Entries: 4

Rep: Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842
Quote:
Originally Posted by pompado View Post
'Dr.Web, a Russian antivirus maker, has detected a new threat against Linux users, the Linux.Ekocms.1 trojan, which includes special features that allow it to take screengrabs and record audio.' ~ Softpedia

http://news.softpedia.com/news/new-t...o-499113.shtml

If you run Tripwire - then you can add the file paths to check for the trojan.
Hi...

Thank you for letting us know.

Regards...
 
Old 01-27-2016, 05:44 AM   #9
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by pompado View Post
I want to know if i have intrusion, then there is as i understand it two options, Aide or Tripwire, both doing the same thing.

Cheers
So, what's wrong with afick?
 
Old 01-27-2016, 12:35 PM   #10
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by pompado View Post
As every post the OP has made sings the praises of tripwire I assume he's a dev, so anything he has to say really should be taken with a pinch of salt

I don't know what issue you have with me, but i am a linux beginner using Ubuntu home desktop.
I want to know if i have intrusion, then there is as i understand it two options, Aide or Tripwire, both doing the same thing.
Now i was lucky getting help and support from another member at Ubuntu Forum Org to install and configurate tripwire as beginner which made me very happy.
keith hedger is simply stating the facts (everybody can see your posting history), and i agree with "taking it with a pinch of salt".

i also don't trust in statements like "if you want this and that (on any given computer system) you have the choice between 2 large software company products" and "choosing product X has made me happy".

as the previous poster pointed out, on linux there's usually many different solutions to a problem.
 
Old 01-28-2016, 12:41 AM   #11
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by salasi View Post
So, what's wrong with afick?
Hello, did not know it was Another IDS system with the name Afick, looks great and i will read about it.
At first glance it really looks great.

Cheers
 
Old 01-28-2016, 01:27 AM   #12
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by salasi View Post
So, what's wrong with afick?
It's not Samhain? ;-p
 
Old 01-28-2016, 01:41 AM   #13
jamison20000e
Senior Member
 
Registered: Nov 2005
Location: ...uncanny valley... infinity\1975; (randomly born:) Milwaukee, WI, US( + travel,) Earth&Mars (I wish,) END BORDER$!◣◢┌∩┐ Fe26-E,e...
Distribution: any GPL that work on freest-HW; has been KDE, CLI, Novena-SBC but open.. http://goo.gl/NqgqJx &c ;-)
Posts: 4,888
Blog Entries: 2

Rep: Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567
http://www.fail2ban.org/wiki/index.php/Main_Page ?
 
Old 01-28-2016, 04:29 AM   #14
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by unSpawn View Post
It's not Samhain? ;-p
That would be a fair point (is a fair point), if we were discussing what is best. However, the OP states

Quote:
...as i understand it two options, Aide or Tripwire...
and to disprove that, all that has to be done is to state that there is another option. afick is another option and is a 'tripwire work alike' and is slightly less unmaintained (there have been changes within living memory, even though it may be that those are only correcting issues that tripwire, which from a functional point of view they are copying, didn't have).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Linux Trojan captures audio and takes screenshots LXer Syndicated Linux News 0 01-20-2016 06:31 PM
LXer: Snowden to the IETF: Please make an internet for users, not the spies LXer Syndicated Linux News 0 07-21-2015 12:52 AM
LXer: Ubuntu One taking care of Windows users ... not so much users of other Linux distributions LXer Syndicated Linux News 0 08-26-2010 09:30 PM
Recording audio with Linux spoody_goon Linux - General 13 01-03-2004 11:19 PM
Recording audio with linux karim Linux - Software 0 10-06-2003 07:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:40 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration