解决阿里云主机受到攻击的问题 2

解决阿里云主机受到攻击的问题

详细解决方案

/etc/profile 文件中添加:

sed -i 's/^\([^#].*scrypt\)/# \1/' /etc/rc.local

sed -i 's/^\(\/mnt\/linsx\)/# \1/' /etc/rc.local

sed -i 's/^\(\/tmp\/\)/# \1/' /etc/rc.local

rm -fr /mnt/linsx

rm -fr /tmp/minerd

rm -fr /tmp/1.sh

 

ps -ef |grep "/usr/bin/acpid" |grep -v grep |awk -F" "  {'print $2'}|xargs -i kill -9 {}

ps -ef |grep "/usr/bin/bsd-port/agent" |grep -v grep |awk -F" "  {'print $2'}|xargs -i kill -9 {}

ps -ef |grep "/usr/bin/.sshd" |grep -v grep|awk -F" "  {'print $2'}|xargs -i kill -9 {}

ps -ef |grep "/root/.l" |grep -v grep|awk -F" "  {'print $2'}|xargs -i kill -9 {}

ps -ef |grep "/mnt/linsx" |grep -v grep|awk -F" "  {'print $2'}|xargs -i kill -9 {}

 

/root/.bash_profile 添加相同的代码

 

定时器执行的脚本:

#!/bin/sh
$grep_result
grep_result=`ps -ef |grep tomcat|grep "/home/whuang/software/apache/apache-tomcat-7.0.53"|grep -v "grep"`
if [ x"$grep_result" = x"" ];then

        catalina_home2=/home/whuang/software/apache/apache-tomcat-7.0.53
        CATALINA_HOME=$catalina_home2
        cd $catalina_home2/bin
        ./startup.sh
    else
        echo "tomcat is running..."  
    fi
rm -fr /usr/bin/acpid 2>/dev/null
rm -fr /usr/bin/bsd-port/agent
rm -fr /usr/bin/.sshd
rm -fr /mnt/linsx

rm -fr /tmp/minerd

rm -fr /tmp/1.sh


ps -ef |grep "/usr/bin/acpid" |grep -v grep |awk -F" "  {'print $2'}|xargs -i kill -9 {}
ps -ef |grep "/usr/bin/bsd-port/agent" |grep -v grep |awk -F" "  {'print $2'}|xargs -i kill -9 {}
ps -ef |grep "/usr/bin/.sshd" |grep -v grep|awk -F" "  {'print $2'}|xargs -i kill -9 {}
ps -ef |grep "/root/.l" |grep -v grep|awk -F" "  {'print $2'}|xargs -i kill -9 {}
ps -ef |grep "/mnt/linsx" |grep -v grep|awk -F" "  {'print $2'}|xargs -i kill -9 {}


sed -i 's/^\([^#].*scrypt\)/# \1/' /etc/rc.local
sed -i 's/^\(\/mnt\/linsx\)/# \1/' /etc/rc.local
sed -i 's/^\(\/tmp\/\)/# \1/' /etc/rc.local

 

 

 

 

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值