[問題] 用rkhunter後門檢測得到的結果

看板Linux作者 (sheshark)時間13年前 (2012/09/06 09:33), 編輯推噓1(109)
留言10則, 3人參與, 最新討論串1/1
有幾個warning 281 [09:17:35] /usr/bin/unhide.rb [ Warning ] 282 [09:17:35] Warning: The command '/usr/bin/unhide.rb' has been replaced by a script: /usr/bin/unhide.rb: Ruby script, ASCII text 287 [09:17:35] /sbin/chkconfig [ Warning ] 288 [09:17:35] Warning: The command '/sbin/chkconfig' has been replaced by a sc ript: /sbin/chkconfig: a /usr/bin/perl script, ASCII text executable 1660 [09:22:28] Checking for enabled inetd services [ Warning ] 1661 [09:22:28] Warning: Found enabled inetd service: gds_db 1752 [09:23:22] Checking for hidden files and directories [ Warning ] 1753 [09:23:22] Warning: Hidden directory found: /dev/.udev 1754 [09:23:22] Warning: Hidden file found: /dev/.initramfs: symbolic link to `/ run/initramfs' 我中木馬了嗎?我的電腦現在只有53端口是開的,我還是感覺到我電腦上有木馬。 -- 心情不好,做做瑜伽吧,伸伸懶腰,心情會變好的。 -- ※ 發信站: 批踢踢實業坊(ptt.cc) ◆ From: 171.112.144.243

09/07 00:00, , 1F
09/07 00:00, 1F

09/07 08:08, , 2F
那么說是沒問題了?
09/07 08:08, 2F

09/07 08:12, , 3F
只看懂部分內容
09/07 08:12, 3F

09/08 02:01, , 4F
其實指令的部份不見得寫warning就一定有問題
09/08 02:01, 4F

09/08 02:02, , 5F
像我朋友的機器su的權限都會自己改過 然後每次rkhunt
09/08 02:02, 5F

09/08 02:02, , 6F
-er去檢查su的時候都會寫warning 但是實際上su根本不
09/08 02:02, 6F

09/08 02:03, , 7F
會被一般使用者啟動 所以其實是沒有問題的
09/08 02:03, 7F

09/08 02:03, , 8F
推測rkhunter對指令有一個檢驗的機制 看是否warning
09/08 02:03, 8F

09/08 02:03, , 9F
但就指令的這個部份就算測了結果是warning也不見得一
09/08 02:03, 9F

09/08 02:04, , 10F
定有必要性的問題
09/08 02:04, 10F
文章代碼(AID): #1GH_rVRi (Linux)