Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Any legit reason why wifite starts silently in background?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Unsupported Software
View previous topic :: View next topic  
Author Message
i92guboj
Bodhisattva
Bodhisattva


Joined: 30 Nov 2004
Posts: 10306
Location: Córdoba (Spain)

PostPosted: Tue Sep 19, 2017 10:15 am    Post subject: Any legit reason why wifite starts silently in background? Reply with quote

Today, while I was profiling energy usage in my old t420 laptop I noticed that, from time to time, aircrack-ng appeared at the top of the list. Looking further, I noticed that wifite was also there, a bit lower in the list.

Both sucking quite a bit of wattage, by the way.

What worries me, however, is whether there's any legit reason why wifite launches itself. I have no idea how it's started, and I am certain that I didn't set that up myself. I greped in /etc and a few other places just to check, and nothing turned up that could be spawning wifite or aircrack.

I also noticed that sometimes the webcam module and the sound driver where at the top, even though I wasn't using anything related. This could be related to chrome-ware, though.

In any case, this smells bad, and calls for a disconnect and a serious revision, that is, unless someone here can explain why wifite was acting that way. rkhunter doesn't report anything obvious, but I truly have no idea why wifite fires up itself at random. I kill it and half an hour later it appears again. This seems quite strange to me.

By the way, I installed wifite from the pentoo overlay time ago to test the security of my home wifi and haven't used it much since then. I didn't even remember I had it installed. I tell you that because, even if the pentoo repositories have been tampered with, I haven't launched it for years.

Maybe I am missing something simple here...

Any idea is welcome :)
_________________
Gentoo Handbook | My website
Back to top
View user's profile Send private message
Ant P.
Watchman
Watchman


Joined: 18 Apr 2009
Posts: 5877

PostPosted: Tue Sep 19, 2017 10:35 pm    Post subject: Reply with quote

Just a guess, but maybe it's hotplug-starting it when it sees the net.wlan script start? udev rules can do some unwanted things too.
Back to top
View user's profile Send private message
i92guboj
Bodhisattva
Bodhisattva


Joined: 30 Nov 2004
Posts: 10306
Location: Córdoba (Spain)

PostPosted: Wed Sep 20, 2017 2:28 pm    Post subject: Reply with quote

Ant P. wrote:
Just a guess, but maybe it's hotplug-starting it when it sees the net.wlan script start? udev rules can do some unwanted things too.


Thanks for the pointer :)

That's why I greped the whole /etc for signs of aircrack and wifite. So far, nothing turned out. I had one leftover network interface called "mon0", which surely is related to having used this software in the past. I probably set that up myself, even though I don't remember doing it. I can't tell if it's related, somehow, to this strange behavior.

I uninstalled the offending packages, and took some measures to avoid any harm. This laptop is under observation just for forensic purposes, but for the time being I haven't been able to find anything.
_________________
Gentoo Handbook | My website
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Unsupported Software All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum