#!/usr/bin/perl -w use strict; my $i; for $i (0..65536) { #test -f $i/cmdline && (cat $i/cmdline; echo $i); if (-f "/proc/$i/exe") { my $target = readlink "/proc/$i/exe"; if (! -f $target) { open F, "< /proc/$i/cmdline"; my @data = ; print "ALERT: '@data' is running (pid $i)\n"; close F; local $/ = "\x00"; open F, "< /proc/$i/environ"; @data = ; print "ALERT: 'environment: @data'\n"; close F; }; }; };