<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Forum du club des développeurs et IT Pro - Sécurité</title>
		<link>https://www.developpez.net/forums/</link>
		<description>Vos questions sur la sécurité sous Linux/Unix</description>
		<language>fr</language>
		<lastBuildDate>Tue, 01 Sep 2026 22:03:30 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>15</ttl>
		<image>
			<url>https://forum.developpez.be/images/misc/rss.png</url>
			<title>Forum du club des développeurs et IT Pro - Sécurité</title>
			<link>https://www.developpez.net/forums/</link>
		</image>
		<item>
			<title>ouvrir une session root</title>
			<link>https://www.developpez.net/forums/showthread.php?t=2185377&amp;goto=newpost</link>
			<pubDate>Sun, 30 Aug 2026 17:39:57 GMT</pubDate>
			<description>Bonjour 
 
Sur kubuntu...</description>
			<content:encoded><![CDATA[<div>Bonjour<br />
<br />
Sur kubuntu j'essaie d'ouvrir une session avec le compte root et l'accès m'est refusé.<br />
Je voudrais juste savoir si c'est normal ou si j'ai loupé un truc :)<br />
<br />
Merci d'avance</div>

]]></content:encoded>
			<category domain="https://www.developpez.net/forums/f331/systemes/linux/securite/">Sécurité</category>
			<dc:creator>Papy214</dc:creator>
			<guid isPermaLink="true">https://www.developpez.net/forums/d2185377/systemes/linux/securite/ouvrir-session-root/</guid>
		</item>
		<item>
			<title>Darkmoon : une plateforme open source de pentest autonome par IA à 50 agents, qui garde toutes les données en</title>
			<link>https://www.developpez.net/forums/showthread.php?t=2184985&amp;goto=newpost</link>
			<pubDate>Tue, 04 Aug 2026 13:13:43 GMT</pubDate>
			<description><![CDATA[*Darkmoon : l'ancienne...]]></description>
			<content:encoded><![CDATA[<div><b><font size="4">Darkmoon : l'ancienne distribution Cygwin de sécurité devient une plateforme open source de pentest autonome par IA, forte de 50 agents spécialisés</font></b><br />
<br />
<b><font size="1"><font color="#0000CD">Le projet toulousain d'ASC-IT, distribué sous GPLv3, mise sur une anonymisation locale des données pour faire tourner des agents offensifs sans jamais envoyer le code ni le trafic vers un modèle hébergé à l'étranger</font></font></b><br />
<br />
<br />
Les lecteurs qui suivent le projet Darkmoon depuis ses débuts le connaissaient sous une tout autre forme. À l'origine, Darkmoon était une distribution GNU/Cygwin portable pour Windows, orientée « toolbox » de développement. En 2023, son auteur en a fait une version orientée sécurité offensive, toujours basée sur Cygwin, en y portant de nombreux outils de pentest habituellement utilisés sous Linux (l'ancien dépôt et sa documentation Developpez restent en ligne). Cette approche s'est heurtée à des limites de compatibilité propres à Cygwin. Le projet a alors été entièrement repensé sur WSL, avec un serveur MCP (Model Context Protocol) et une console TUI pour piloter des agents d'IA. C'est cette nouvelle plateforme, désormais très éloignée de la distribution d'origine, qui vient de franchir un cap avec un ensemble de 50 agents spécialisés.<br />
<br />
Pour rappel, une nouvelle génération d'outils de pentest « autonomes » a émergé depuis 2024 : XBOW, Strix, Shannon, PentAGI, HexStrike AI ou encore NodeZero confient à un modèle de langage le soin d'enchaîner reconnaissance, exploitation et rapport. La plupart partagent deux caractéristiques : ils se concentrent surtout sur la couche web, et ils envoient les données de la cible vers un modèle hébergé dans le cloud, le plus souvent aux États-Unis. C'est précisément sur ces deux points que Darkmoon prend le contre-pied.<br />
<br />
<br />
<b><font size="3">Une passerelle d'anonymisation pour ne rien envoyer au modèle</font></b><br />
<br />
La fonction que l'équipe met le plus en avant est une &quot;Privacy Gateway&quot;. Le constat de départ est simple : pour raisonner, un agent IA a besoin de voir les données de la cible (adresses IP, noms de machines, identifiants, parfois le code source). Les envoyer à un modèle tiers, souvent hébergé hors d'Europe, est rédhibitoire pour une banque, un hôpital, un industriel ou un acteur souverain. La conformité l'interdit, les clients l'interdisent, et dans certains secteurs la loi l'interdit.<br />
<br />
Le mécanisme retenu repose sur une tokenisation déterministe suivie d'une réhydratation locale. Concrètement, avant que quoi que ce soit n'atteigne le modèle, chaque valeur réelle est remplacée par un marqueur stable : une adresse IP devient IP_PRIVATE_001, un nom de machine devient HOST_INTERNAL_001, et ainsi de suite. Le modèle raisonne sur la structure sans jamais voir la valeur réelle. Celle-ci n'est réinjectée que localement, au moment précis où un outil s'exécute, puis de nouveau masquée au retour. Toute tentative d'exfiltration est bloquée. Darkmoon peut par ailleurs fonctionner entièrement sur un modèle local (Ollama, llama.cpp), ce qui rend l'ensemble compatible avec un environnement isolé (air gap). Le code et le trafic restent ainsi sur l'infrastructure de l'utilisateur.<br />
<br />
Pour un public attentif à la souveraineté des données, l'argument est direct : là où les outils concurrents transmettent le contexte d'un test d'intrusion à un modèle américain ou chinois, Darkmoon garde tout en local.<br />
<br />
<br />
<b><font size="3">50 agents spécialisés</font></b><br />
<br />
La particularité de Darkmoon est l'étendue de son périmètre. Là où la concurrence se limite le plus souvent aux applications web, le dépôt compte aujourd'hui 50 agents de méthodologie, écrits en Markdown lisible et auditable, orchestrés par un agent chef (« pentest »). Le maillage couvre notamment :<br />
<br />
<ul><li style=""> le web et les CMS : agents dédiés à WordPress, Drupal, Joomla, Magento, PrestaShop, Moodle, ainsi qu'aux stacks Node.js/Angular, PHP, Flask, Spring Boot, ASP.NET, Ruby, Go et GraphQL ;</li><li style=""> le cloud public et privé : AWS, Azure, GCP, Entra ID ;</li><li style=""> l'infrastructure interne et l'identité : Active Directory, PKI/ADCS, SSO/IdP, VPN et accès distant, pare-feu et réseau, MDM ;</li><li style=""> les conteneurs et l'orchestration : Kubernetes, Docker, registres de conteneurs, plateformes de conteneurs, GitOps ;</li><li style=""> la chaîne CI/CD et l'IaC : GitHub, GitLab, Jenkins, Ansible, Terraform ;</li><li style=""> les données et les secrets : bases SQL et NoSQL, messagerie/cache, stockage, sauvegardes, HashiCorp Vault ;</li><li style=""> l'embarqué et le mobile : firmware, objets connectés, applications mobiles ;</li><li style=""> et d'autres surfaces : hyperviseurs, messagerie d'entreprise, observabilité.</li></ul><br />
<br />
Le dispatch est déclenché par un artefact concret et non par une simple inférence : un agent ne se lance que sur une preuve tangible (une clé qui fuit, un port ouvert, une image de firmware), ce qui limite les faux positifs. Quelques exemples parlants tirés des retours publiés : trois agents lancés en parallèle attaquent simultanément un coffre Vault, un registre de conteneurs et un socket Docker exposé ; un agent Terraform lit un fichier d'état et y relève 16 vulnérabilités, dont 10 critiques ; un agent firmware ouvre une image, en extrait mots de passe et portes dérobées, puis obtient un accès root sur l'objet en direct. La plateforme sait aussi enchaîner les couches : un secret oublié dans l'historique Git qui remonte jusqu'à un accès AWS, ou une SSRF transformée en accès initial sur GCP.<br />
<br />
<br />
<b><font size="3">Des mesures reproductibles sur différents laboratoire</font></b><br />
<br />
Chaque découverte est accompagnée d'une preuve d'exploitation (la commande jouée et son résultat brut), ce qui rend les résultats reproductibles. Le banc d'essai de référence est OWASP Juice Shop, une application web délibérément vulnérable, maintenue par l'OWASP à des seules fins de formation et de test (et non une cible réelle, ce qui écarte toute question de légalité). En boîte noire et sur un modèle local, Darkmoon y rapporte 57 vulnérabilités ; une vidéo de démonstration de cette exécution autonome est disponible:<br />
<br />

<div class="video-container"><iframe class="restrain" title="YouTube video player" width="560" height="315" allowfullscreen src="//www.youtube.com/embed/1bFRVuMkZzY?wmode=transparent&amp;fs=1" frameborder="0"></iframe></div>
<br />
<br />
D'autres campagnes publiées font état de 22 découvertes sur un couple PostgreSQL/MySQL, ou de 16 sur un fichier d'état Terraform. L'auteur documente également ses tests sur des environnements de démonstration tiers, comme celui d'OpenNHP, avec la méthodologie associée.<br />
<br />
Sur le plan de la comparaison, Darkmoon se distingue moins par un score brut que par deux axes rarement réunis : la capacité à fonctionner sur un modèle local sans exfiltration de données, et l'étendue du périmètre (du web à l'Active Directory, du cloud au firmware, en passant par le CI/CD). Les outils comme Strix ou Shannon, souvent cités pour leurs résultats, opèrent en cloud et se concentrent sur d'autres axes ; l'équipe publie ses conditions de test en clair et invite à contester ou reproduire les chiffres.<br />
<br />
<br />
<b><font size="3">Open source, dockerisé et pensé pour le DevSecOps</font></b><br />
<br />
Darkmoon est publié sous licence GPLv3 et s'installe en auto-hébergement via docker-compose. Le projet fournit également une intégration à la chaîne CI/CD : un dépôt de démonstration montre un déclenchement du test d'intrusion via GitHub Actions, avec remontée des résultats sous forme d'artefacts. L'ensemble s'adresse donc autant à l'équipe sécurité qu'aux pipelines DevSecOps.<br />
<br />
Le développement reste actif : les derniers commits ajoutent de nouveaux agents et corrigent des références d'outils avant l'exécution, afin d'éviter qu'un binaire mal nommé ne fasse échouer un vecteur. Le projet est développé à Toulouse par ASC-IT.<br />
<br />
<br />
<b><font size="3">Une couverture dans la presse spécialisée</font></b><br />
<br />
Depuis sa publication, le projet a été présenté par plusieurs médias spécialisés en sécurité et en logiciel libre, en France comme à l'étranger. <a rel="nofollow" href="https://www.helpnetsecurity.com/2026/06/29/darkmoon-open-source-ai-pentesting-platform/" target="_blank">Help Net Security</a> et <a rel="nofollow" href="https://cybersecuritynews.com/darkmoon-penetration-testing-platform/" target="_blank">Cyber Security News</a> ont détaillé son fonctionnement, de même que <a rel="nofollow" href="https://securitybrief.co.uk/story/asc-it-launches-darkmoon-to-hide-target-data-from-ai" target="_blank">SecurityBrief</a> au Royaume-Uni, <a rel="nofollow" href="https://www.linuxlinks.com/darkmoon-ai-powered-autonomous-penetration-testing-platform/" target="_blank">LinuxLinks</a> et <a rel="nofollow" href="https://letsdatascience.com/news/darkmoon-launches-open-source-autonomous-pentesting-platform-57a84b7f" target="_blank">Let's Data Science</a>, ainsi qu'en français <a rel="nofollow" href="https://www.undernews.fr/hacking-hacktivisme/darkmoon-plateforme-open-source-gplv3-de-pentest-autonome.html" target="_blank">UnderNews</a>. Ces articles reviennent tous sur le même parti pris : garder les données de la cible hors du modèle, là où le reste du marché s'appuie sur des modèles hébergés dans le cloud. L'équipe s'en tient par ailleurs à des mesures reproductibles et à des conditions de test publiées, plutôt qu'à des effets d'annonce.<br />
<br />
Darkmoon est par ailleurs recensé par le projet de veille <a rel="nofollow" href="https://github.com/simon-p-j-r/LLM4Pentest" target="_blank">LLM4Pentest</a>, qui cartographie les outils de pentest fondés sur les LLM et retient notamment ses sous-agents spécialisés, sa couverture de l'Active Directory et de Kubernetes, et l'orchestration de plus de 80 outils via MCP.<br />
<br />
<br />
<b><font size="3">Et vous ?</font></b><br />
<br />
:fleche: Que pensez-vous de l'approche par anonymisation locale des données pour le pentest par IA ?<br />
:fleche: Un périmètre aussi large (web, cloud, AD, conteneurs, CI/CD, firmware) vous paraît-il pertinent, ou préférez-vous des outils spécialisés ?<br />
:fleche: La souveraineté des données pèse-t-elle dans votre choix d'un outil de sécurité ?<br />
<br />
<br />
<b><font size="3">Sources</font></b><br />
<br />
<ul><li style=""> Dépôt GitHub du projet : <a rel="nofollow" href="https://github.com/ASCIT31/Dark-Moon" target="_blank">https://github.com/ASCIT31/Dark-Moon</a></li><li style=""> Site et blog technique (études de cas, méthodologie, comparaisons) : <a rel="nofollow" href="https://www.dark-moon.org/blog" target="_blank">https://www.dark-moon.org/blog</a></li><li style=""> Documentation historique du projet sur Developpez.com : <a href="https://johntheripper.developpez.com/darkmoon-project/" target="_blank">https://johntheripper.developpez.com/darkmoon-project/</a></li></ul></div>

]]></content:encoded>
			<category domain="https://www.developpez.net/forums/f331/systemes/linux/securite/">Sécurité</category>
			<dc:creator>john_the_ripper</dc:creator>
			<guid isPermaLink="true">https://www.developpez.net/forums/d2184985/systemes/linux/securite/darkmoon-plateforme-open-source-pentest-autonome-ia-50-agents-garde-toutes-donnees/</guid>
		</item>
		<item>
			<title>Linux Hydra JSON page web protegée par password</title>
			<link>https://www.developpez.net/forums/showthread.php?t=2184953&amp;goto=newpost</link>
			<pubDate>Sun, 02 Aug 2026 11:32:14 GMT</pubDate>
			<description><![CDATA[Bonjour, 
 
j'ai créée une...]]></description>
			<content:encoded><![CDATA[<div>Bonjour,<br />
<br />
j'ai créée une page web avec identifiant password crée chez WIX :<br />
<a rel="nofollow" href="https://reyjp81.wixsite.com/sport-articles/espace-membres-prive" target="_blank">https://reyjp81.wixsite.com/sport-ar...-membres-prive</a><br />
Il y a du JSON<br />
<br />
je teste l'outil Hydra sous Kali Linux. Après install de VirtualBox.<br />
J'ai généré le fichier password qui contient le mot de passe :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">crunch <span style="color: #cc66cc;">3</span> <span style="color: #cc66cc;">3</span> ABCDEFGHIJKLMNOPQRSTUVWXYZ <span style="color: #339933;">-o</span> password.txt</code><hr />
</div>Avec Burp suite, j'obtiens ceci :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code"><span style="color: black">&#123;</span><span style="color: #FF0000;">&quot;password&quot;</span>:<span style="color: #FF0000;">&quot;JUL&quot;</span>,<span style="color: #FF0000;">&quot;pageId&quot;</span>:<span style="color: #FF0000;">&quot;pubhb&quot;</span>,<span style="color: #FF0000;">&quot;metaSiteId&quot;</span>:<span style="color: #FF0000;">&quot;fb98b4a7-f08b-4a2e-8b69-524306a8e106&quot;</span>,<span style="color: #FF0000;">&quot;siteId&quot;</span>:<span style="color: #FF0000;">&quot;bddd9820-dab1-48ec-a278-aefb50dcfaec&quot;</span><span style="color: black">&#125;</span></code><hr />
</div>J'ai testé la commande hydra suivant pour découvrir le password :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">hydra <span style="color: #339933;">-l</span> <span style="color: #FF0000;">''</span> <span style="color: #339933;">-f</span> <span style="color: #339933;">-V</span> <span style="color: #339933;">-P</span> password.txt site-pages.wix.com https-post-form <span style="color: #FF0000;">&quot;/_api/wix-public-html-info-webapp/resolve_protected_page_urls?siteRevision=8:{<span style="color: #800000;">\&quot;</span>password<span style="color: #800000;">\&quot;</span>\:<span style="color: #800000;">\&quot;</span>^PASS^<span style="color: #800000;">\&quot;</span>,<span style="color: #800000;">\&quot;</span>pageId<span style="color: #800000;">\&quot;</span>\:<span style="color: #800000;">\&quot;</span>pubhb<span style="color: #800000;">\&quot;</span>,<span style="color: #800000;">\&quot;</span>metaSiteId<span style="color: #800000;">\&quot;</span>\:<span style="color: #800000;">\&quot;</span>fb98b4a7-f08b-4a2e-8b69-524306a8e106<span style="color: #800000;">\&quot;</span>,<span style="color: #800000;">\&quot;</span>siteId<span style="color: #800000;">\&quot;</span>\:<span style="color: #800000;">\&quot;</span>bddd9820-dab1-48ec-a278-aefb50dcfaec<span style="color: #800000;">\&quot;</span>}\:S=<span style="color: #800000;">\&quot;</span>success<span style="color: #800000;">\&quot;</span>\:true:H=Origin\:https\://reyjp81.wixsite.com/sport-articles:H=Accept\:*/*:H=Content-Type\:application/json&quot;</span></code><hr />
</div>Mais ça ne fonctionne pas. Ca me dit que tous les mots de passe du fichier password sont valides.<br />
Faut il échapper chaque : et chaque &quot; dans cette séquence :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">\:<span style="color: #339933;">S</span>=<span style="color: #808080;">\&quot;</span>success<span style="color: #808080;">\&quot;</span>\:true:<span style="color: #339933;">H</span>=Origin\:https\:<span style="color: black">//</span>reyjp81.wixsite.com<span style="color: black">/</span>sport-articles:<span style="color: #339933;">H</span>=Accept\:<span style="color: black">*/*</span>:<span style="color: #339933;">H</span>=Content-Type\:application<span style="color: black">/</span>json<span style="color: #FF0000;">&quot;</span></code><hr />
</div>Une aide pour faire fonctionner ce code serait la bienvenue.</div>

]]></content:encoded>
			<category domain="https://www.developpez.net/forums/f331/systemes/linux/securite/">Sécurité</category>
			<dc:creator>Noddles</dc:creator>
			<guid isPermaLink="true">https://www.developpez.net/forums/d2184953/systemes/linux/securite/linux-hydra-json-page-web-protegee-password/</guid>
		</item>
		<item>
			<title>Le certificat https neutralise le firewall UFW</title>
			<link>https://www.developpez.net/forums/showthread.php?t=2183481&amp;goto=newpost</link>
			<pubDate>Wed, 29 Apr 2026 11:36:07 GMT</pubDate>
			<description>Bonjour, 
 
Je tente de...</description>
			<content:encoded><![CDATA[<div>Bonjour,<br />
<br />
Je tente de bloquer un visiteur indésirable, qui fouille régulièrement mon site web, hébergé sur un VPS Linux Ubuntu, chez OVH Strasbourg.<br />
Son IP commence par 188.143.x.x, les deux derniers octets changent, d'une visite à l'autre.<br />
<br />
Je n'utilise jamais les ports par défaut.<br />
Dans le certificat ssl_gateway d'OVH, j'ai remplacé le port http 80 par le port 12345, et programmé Apache2 pour l'écouter.<br />
Ca fonctionne, c'est parfait !<br />
<br />
J'ai donc programmé une règle UFW<br />
ufw insert 4 deny from 188.143.0.0/16 to any port 12345 proto tcp<br />
<br />
Ok, elle apparaît bien dans la liste des ufw status numbered<br />
[ 4] Anywhere                   DENY IN     188.143.0.0/16<br />
Les trois premiers ne sont que des DENY du même genre.<br />
<br />
Ce matin, je constate qu'il passe toujours.<br />
<br />
Mon IP commence toujours par 111.222, que m'alloue mon FAI,<br />
telle que le révèle la superglobale PHP $_SERVER['REMOTE_ADDR']<br />
<br />
Intrigué, je me bloque moi-même en https, pour faire un test<br />
ufw insert 2 deny from 111.222.0.0/16 to any port 12345 proto tcp<br />
[ 2] 12345/tcp                  DENY IN     111.222.0.0/16<br />
<br />
Ensuite, je surfe sur mon VPS, auquel j'ai toujours accès, alors que je me suis interdit l'accès au port http.<br />
Même après un redémarrage d'Apache2 et d'UFW.<br />
<br />
Visiblement, la règle [2] DENY d'UFW ne me bloque pas du tout.<br />
Je me demande si ce n'est pas dû au certificat ssl gateway.<br />
Car mon nom de domaine monDomaine.be pointe sur le certificat, chez dns.be,<br />
qui, à son tour, désigne l'IP et le port http 12345 de mon VPS.<br />
<br />
Est ce que le certificat OVH ssl_gateway ne masquerait pas la véritable IP de mes visiteurs http, paralysant, ainsi, le firewall UFW ?<br />
Je ne parle pas des autres services (ssh, mysql, ...) qui ne sont pas concernés par le certificat.<br />
<br />
Alors que pourtant la superglobale PHP $_SERVER['REMOTE_ADDR'] la détecte bien.<br />
Pour qu'il la détecte, je me souviens d'avoir du installer (il y a quatre ans) un fichier dans la config de PHP<br />
Sans quoi, tous mes visiteurs avaient la REMOTE_ADDR du certificat.<br />
<br />
Comment configurer UFW pour qu'il filtre les demandes en HTTP sur base de l'IP réelle du visiteur ?<br />
Afin de bloquer les &#128023; qui &#128061;fouillent impunément mon site web.<br />
Si PHP affiche bien l'IP réelle du visiteur, UFW doit aussi pouvoir y avoir accès.<br />
<br />
Merci.<br />
Christian.</div>

]]></content:encoded>
			<category domain="https://www.developpez.net/forums/f331/systemes/linux/securite/">Sécurité</category>
			<dc:creator>cmascart</dc:creator>
			<guid isPermaLink="true">https://www.developpez.net/forums/d2183481/systemes/linux/securite/certificat-https-neutralise-firewall-ufw/</guid>
		</item>
		<item>
			<title>Problème bizarre ce matin</title>
			<link>https://www.developpez.net/forums/showthread.php?t=2181045&amp;goto=newpost</link>
			<pubDate>Fri, 19 Dec 2025 11:37:54 GMT</pubDate>
			<description><![CDATA[Bonjour, 
 
D'habitude j'ai...]]></description>
			<content:encoded><![CDATA[<div>Bonjour,<br />
<br />
D'habitude j'ai ça, après un <span style="font-family: monospace; padding: 2px; background: #ddd; display: inline-block"><span style="color: #0080ff;">ps</span> ax</span> :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code"><table cellspacing="0" cellpadding="0"><tr><td valign="top" width="33"><div style="border: 1px dashed gray; padding-left: 5px; padding-right: 5px; margin-right: 5px; text-align: right; font-family: monospace">1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br /></div></td><td valign="top"><pre style="margin: 0">   ...
   <span style="color: #cc66cc;">1342</span> ?        Ss     <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>sbin<span style="color: black">/</span>cupsd <span style="color: #339933;">-l</span>
   <span style="color: #cc66cc;">1347</span> ?        Sl     <span style="color: #cc66cc;">0</span>:00 package-update-indicator
   <span style="color: #cc66cc;">1364</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>colord
   <span style="color: #cc66cc;">1380</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>upowerd
   <span style="color: #cc66cc;">1395</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>gvfs-udisks2-volume-monitor
   <span style="color: #cc66cc;">1407</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>gvfs-afc-volume-monitor
   <span style="color: #cc66cc;">1413</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>gvfs-gphoto2-volume-monitor
   <span style="color: #cc66cc;">1418</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>gvfs-goa-volume-monitor
   <span style="color: #cc66cc;">1423</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>gvfs-mtp-volume-monitor
   <span style="color: #cc66cc;">1429</span> ?        Ssl    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>packagekitd
   <span style="color: #cc66cc;">1434</span> ?        Sl     <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>libexec<span style="color: black">/</span>gvfsd-trash <span style="color: #339933;">--spawner</span> :<span style="color: #cc66cc;">1.9</span> <span style="color: black">/</span>org<span style="color: black">/</span>gtk<span style="color: black">/</span>gvfs<span style="color: black">/</span>exec_spaw<span style="color: black">/</span><span style="color: #cc66cc;">0</span>
   <span style="color: #cc66cc;">1458</span> ?        Sl     <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>menu-cache<span style="color: black">/</span>menu-cached <span style="color: black">/</span>run<span style="color: black">/</span>user<span style="color: black">/</span><span style="color: #cc66cc;">0</span><span style="color: black">/</span>menu-cached-:<span style="color: #cc66cc;">0</span>
   <span style="color: #cc66cc;">1542</span> ?        Sl     <span style="color: #cc66cc;">0</span>:00 lxterminal
   <span style="color: #cc66cc;">1545</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Ss     <span style="color: #cc66cc;">0</span>:00 <span style="color: #0080ff;">bash</span>
   <span style="color: #cc66cc;">1629</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    R+     <span style="color: #cc66cc;">0</span>:00 <span style="color: #0080ff;">ps</span> ax</pre></td></tr></table></code><hr />
</div>qui m'inspire confiance.<br />
Le problème aujourd'hui c'est quand je lance le navigareur FireFox, car 3 fenêtres apparaissent en haut à droite de l'écran :<br />
<br />
<img src="https://www.developpez.net/forums/attachments/p672653d1766143959/systemes/linux/securite/probleme-bizarre-matin/3alertes.png/" border="0" alt="Nom : 3alertes.png
Affichages : 363
Taille : 44,5 Ko"  style="float: CONFIG" /><br />
<br />
qui n'inspirent pas du tout confiance !<br />
<br />
Jusqu'à hier tout allait bien, alors que faire sous Linux Debian 12.12 ? <br />
<br />
Il n'y a rien de particulier dans <span style="font-family: monospace; padding: 2px; background: #ddd; display: inline-block"><span style="color: black">/</span>usr<span style="color: black">/</span>share<span style="color: black">/</span>applications</span>, voilà les fichiers les plus récents :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code"><table cellspacing="0" cellpadding="0"><tr><td valign="top" width="26"><div style="border: 1px dashed gray; padding-left: 5px; padding-right: 5px; margin-right: 5px; text-align: right; font-family: monospace">1<br />2<br />3<br /></div></td><td valign="top"><pre style="margin: 0"><span style="color: #339933;">-rw-r--r--</span> <span style="color: #cc66cc;">1</span>  <span style="color: #cc66cc;">3826</span>  <span style="color: #cc66cc;">9</span> d&eacute;c.  <span style="color: #cc66cc;">23</span>:02 firefox-esr.desktop
<span style="color: #339933;">-rw-r--r--</span> <span style="color: #cc66cc;">1</span>  <span style="color: #cc66cc;">9692</span> <span style="color: #cc66cc;">11</span> d&eacute;c.  <span style="color: #cc66cc;">11</span>:<span style="color: #cc66cc;">10</span> thunderbird.desktop
<span style="color: #339933;">-rw-r--r--</span> <span style="color: #cc66cc;">1</span> <span style="color: #cc66cc;">26910</span> <span style="color: #cc66cc;">14</span> d&eacute;c.  <span style="color: #cc66cc;">18</span>:<span style="color: #cc66cc;">10</span> mimeinfo.cache</pre></td></tr></table></code><hr />
</div>Le lancement de FF se situant là-dedans : <span style="font-family: monospace; padding: 2px; background: #ddd; display: inline-block"><span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr</span>,<br />
j'y jette un coup d'œil mais ça n'est pas intéressant : voilà ce que montre un <span style="font-family: monospace; padding: 2px; background: #ddd; display: inline-block"><span style="color: #0080ff;">ps</span> ax</span> :<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code"><table cellspacing="0" cellpadding="0"><tr><td valign="top" width="33"><div style="border: 1px dashed gray; padding-left: 5px; padding-right: 5px; margin-right: 5px; text-align: right; font-family: monospace">1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br /></div></td><td valign="top"><pre style="margin: 0">   ...
   <span style="color: #cc66cc;">1687</span> ?        Sl     <span style="color: #cc66cc;">0</span>:01 leafpad <span style="color: black">&lt;&lt;&lt;</span> lanc&eacute; par moi pour prendre des notes
   <span style="color: #cc66cc;">2337</span> ?        I      <span style="color: #cc66cc;">0</span>:00 <span style="color: black">&#91;</span>kworker<span style="color: black">/</span><span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">2</span>-events<span style="color: black">&#93;</span>
   <span style="color: #cc66cc;">2571</span> ?        I      <span style="color: #cc66cc;">0</span>:00 <span style="color: black">&#91;</span>kworker<span style="color: black">/</span>u2:<span style="color: #cc66cc;">0</span>-events_unbound<span style="color: black">&#93;</span>
   <span style="color: #cc66cc;">2572</span> ?        I      <span style="color: #cc66cc;">0</span>:00 <span style="color: black">&#91;</span>kworker<span style="color: black">/</span>u2:<span style="color: #cc66cc;">1</span>-ext4-rsv-conversion<span style="color: black">&#93;</span>
   <span style="color: #cc66cc;">3022</span> ?        I      <span style="color: #cc66cc;">0</span>:00 <span style="color: black">&#91;</span>kworker<span style="color: black">/</span><span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">1</span>-events<span style="color: black">&#93;</span>
   <span style="color: #cc66cc;">3036</span> ?        I      <span style="color: #cc66cc;">0</span>:00 <span style="color: black">&#91;</span>kworker<span style="color: black">/</span><span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">3</span>-events<span style="color: black">&#93;</span>
   <span style="color: #cc66cc;">3057</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:04 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr
   <span style="color: #cc66cc;">3062</span> ?        Sl     <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>crashhelper <span style="color: #cc66cc;">3057</span> <span style="color: #cc66cc;">9</span> <span style="color: black">/</span>tmp<span style="color: black">/</span> <span style="color: #cc66cc;">11</span>
   <span style="color: #cc66cc;">3115</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-parentBuildID</span> <span style="color: #cc66cc;">20251201132345</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:
   <span style="color: #cc66cc;">3116</span> ?        Ss     <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>lib<span style="color: black">/</span>systemd<span style="color: black">/</span>systemd-timedated
   <span style="color: #cc66cc;">3133</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-isForBrowser</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">41407</span> <span style="color: #339933;">-prefMapHa</span>
   <span style="color: #cc66cc;">3137</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-parentBuildID</span> <span style="color: #cc66cc;">20251201132345</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:
   <span style="color: #cc66cc;">3175</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-isForBrowser</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">50445</span> <span style="color: #339933;">-prefMapHa</span>
   <span style="color: #cc66cc;">3223</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-parentBuildID</span> <span style="color: #cc66cc;">20251201132345</span> <span style="color: #339933;">-sandboxingKind</span>
   <span style="color: #cc66cc;">3225</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-isForBrowser</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">42882</span> <span style="color: #339933;">-prefMapHa</span>
   <span style="color: #cc66cc;">3247</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-isForBrowser</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">42939</span> <span style="color: #339933;">-prefMapHa</span>
   <span style="color: #cc66cc;">3249</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-isForBrowser</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">42939</span> <span style="color: #339933;">-prefMapHa</span>
   <span style="color: #cc66cc;">3371</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">1</span>    Ss     <span style="color: #cc66cc;">0</span>:00 <span style="color: #0080ff;">bash</span>
   <span style="color: #cc66cc;">3403</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">0</span>    Sl+    <span style="color: #cc66cc;">0</span>:00 <span style="color: black">/</span>usr<span style="color: black">/</span>lib<span style="color: black">/</span>firefox-esr<span style="color: black">/</span>firefox-esr <span style="color: #339933;">-contentproc</span> <span style="color: #339933;">-isForBrowser</span> <span style="color: #339933;">-prefsHandle</span> <span style="color: #cc66cc;">0</span>:<span style="color: #cc66cc;">42939</span> <span style="color: #339933;">-prefMapHa</span>
   <span style="color: #cc66cc;">3423</span> pts<span style="color: black">/</span><span style="color: #cc66cc;">1</span>    R+     <span style="color: #cc66cc;">0</span>:00 <span style="color: #0080ff;">ps</span> ax</pre></td></tr></table></code><hr />
</div>Ce qui est amusant, c'est le comportement du machin : tout à l'heure il m'a balancé 3 fenêtres en même temps, j'ai rebooté et là il a pris son temps pour en afficher une, puis encore du temps pour la deuxième et enfin encore du temps pour la troisième.<br />
<br />
Si quelqu'un a une solution...<br />
<br />
PS : les images ne sont pas toujours les mêmes.</div>


	<div style="padding:10px">

	

	
		<fieldset class="fieldset">
			<legend>Images attachées</legend>
				<div style="padding:10px">
				<img class="attach" src="https://www.developpez.net/forums/attachments/p672653d1766143959/systemes/linux/securite/probleme-bizarre-matin/3alertes.png/" alt="" />&nbsp;
			</div>
		</fieldset>
	

	

	

	</div>
]]></content:encoded>
			<category domain="https://www.developpez.net/forums/f331/systemes/linux/securite/">Sécurité</category>
			<dc:creator>Jipété</dc:creator>
			<guid isPermaLink="true">https://www.developpez.net/forums/d2181045/systemes/linux/securite/probleme-bizarre-matin/</guid>
		</item>
		<item>
			<title>comment faire en sortes que les fichiers php.bak ne soient pas téléchargeable ?</title>
			<link>https://www.developpez.net/forums/showthread.php?t=2180038&amp;goto=newpost</link>
			<pubDate>Thu, 23 Oct 2025 09:24:43 GMT</pubDate>
			<description>bonjour, 
 
sur certains cms,...</description>
			<content:encoded><![CDATA[<div>bonjour,<br />
<br />
sur certains cms, je crée un .bak des fichiers de config .php (où ya le mdp en clair de la bdd/admin...etc).<br />
comment faire en sortes que le .bak ne soient pas téléchargeable via le navigateur (si par malchance un pirate le cherche)?<br />
<br />
merci de votre conseil.</div>

]]></content:encoded>
			<category domain="https://www.developpez.net/forums/f331/systemes/linux/securite/">Sécurité</category>
			<dc:creator>Invité</dc:creator>
			<guid isPermaLink="true">https://www.developpez.net/forums/d2180038/systemes/linux/securite/faire-sortes-fichiers-php-bak-ne-soient-telechargeable/</guid>
		</item>
	</channel>
</rss>
