linux肉鸡检测,一台linux肉鸡的简单手工入侵检测过程

该篇内容涉及对Linux系统的网络连接状况进行检查,显示了监听中的服务,包括SSH、HTTP、FTP等,同时提到了疑似被替换的系统文件,并通过`rpm-qa`命令检查了系统中可能被篡改的其他关键程序。文章还涉及到系统安全配置,如iptables和ssh配置文件。
摘要由CSDN通过智能技术生成

[root@localhost ~]# netstat -lntp

Active Internet connections (only servers)

Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name

tcp        0      0 127.0.0.1:2208              0.0.0.0:*                   LISTEN      2298/hpiod

tcp        0      0 0.0.0.0:1000                0.0.0.0:*                   LISTEN      2090/rpc.statd

tcp        0      0 0.0.0.0:111                 0.0.0.0:*                   LISTEN      2056/portmap

tcp        0      0 0.0.0.0:21                  0.0.0.0:*                   LISTEN      2883/vsftpd

tcp        0      0 127.0.0.1:631               0.0.0.0:*                   LISTEN      2315/cupsd

tcp        0      0 127.0.0.1:25                0.0.0.0:*                   LISTEN      2361/sendmail: acce

tcp        0      0 127.0.0.1:2207              0.0.0.0:*                   LISTEN      2303/python

总感觉这系统怪怪的,连22端口都看不到,应该替换了netstat了,先看看有没有其他被替换掉的系统文件吧。

[root@localhost ~]# rpm -qaV

S.5..UG.   /bin/netstat

S.5..UG.   /sbin/ifconfig

S.5....T   /usr/bin/ssh-keygen

S.5....T c /etc/sysconfig/system-config-securitylevel

S.5..UG.   /usr/sbin/lsof

.M......   /var/tux

S.5....T c /etc/inittab

S.5....T   /usr/share/texmf-var/fonts/map/dvipdfm/updmap/dvipdfm_dl14.map

S.5....T   /usr/share/texmf-var/fonts/map/dvipdfm/updmap/dvipdfm_ndl14.map

S.5....T   /usr/share/texmf-var/fonts/map/pdftex/updmap/pdftex_dl14.map

S.5....T   /usr/share/texmf-var/fonts/map/pdftex/updmap/pdftex_ndl14.map

S.5....T   /usr/share/texmf-var/web2c/aleph.fmt

S.5....T   /usr/share/texmf-var/web2c/amstex.fmt

S.5....T   /usr/share/texmf-var/web2c/bamstex.fmt

S.5....T   /usr/share/texmf-var/web2c/bplain.fmt

S.5....T   /usr/share/texmf-var/web2c/cont-en.fmt

S.5....T   /usr/share/texmf-var/web2c/etex.fmt

..5....T   /usr/share/texmf-var/web2c/metafun.mem

S.5....T   /usr/share/texmf-var/web2c/mf.base

..5....T   /usr/share/texmf-var/web2c/mpost.mem

S.5....T   /usr/share/texmf-var/web2c/mptopdf.fmt

S.5....T   /usr/share/texmf-var/web2c/omega.fmt

S.5....T   /usr/share/texmf-var/web2c/pdfetex.fmt

S.5....T   /usr/share/texmf-var/web2c/pdftex.fmt

S.5....T   /usr/share/texmf-var/web2c/tex.fmt

.......T c /etc/kdump.conf

S.5....T c /etc/printcap

..5....T c /etc/pki/nssdb/secmod.db

....L... c /etc/pam.d/system-auth

.M...... c /etc/cups/classes.conf

.......T c /etc/audit/auditd.conf

missing     /usr/sbin/nscd

S.5....T c /etc/sysconfig/named

.M......   /var/named

SM5..UG.   /bin/ps

SM5..UG.   /usr/bin/top

SM5....T c /etc/sysconfig/iptables-config

S.5..UG.   /usr/bin/find

prelink: /usr/lib/libGL.so.1.2.#prelink#.crFdQJ Could not trace symbol resolving

S.?.....   /usr/lib/libGL.so.1.2

S.5....T c /etc/ppp/chap-secrets

S.5....T c /etc/ppp/pap-secrets

S.5....T c /etc/xml/catalog

S.5....T c /usr/share/sgml/docbook/xmlcatalog

S.5....T c /etc/ssh/ssh_config

S.5....T   /usr/bin/scp

S.5....T   /usr/bin/sftp

S.5....T   /usr/bin/ssh

S.5....T   /usr/bin/ssh-add

SM5...GT   /usr/bin/ssh-agent

S.5....T   /usr/bin/ssh-keyscan

S.5....T   /usr/share/texmf-var/fonts/map/dvips/updmap/builtin35.map

S.5....T   /usr/share/texmf-var/fonts/map/dvips/updmap/download35.map

S.5....T   /usr/share/texmf-var/fonts/map/dvips/updmap/ps2pk.map

S.5....T   /usr/share/texmf-var/fonts/map/dvips/updmap/psfonts_pk.map

S.5....T   /usr/share/texmf-var/fonts/map/dvips/updmap/psfonts_t1.map

S.5....T   /etc/sgml/docbook-slides.cat

S.5....T   /usr/share/icons/hicolor/icon-theme.cache

S.5..UG.   /bin/ls

S.5..UG.   /usr/bin/dir

S.5..UG.   /usr/bin/md5sum

S.5..UG.   /usr/bin/pstree

S.5....T c /etc/syslog.conf

S.5....T c /etc/ssh/sshd_config

S.5....T   /usr/sbin/sshd

missing     /var/lib/texmf/ls-R

S.5....T   /etc/sgml/docbook-simple.cat

S.5....T c /etc/vsftpd/vsftpd.conf

.M......   /var/ftp/pub

S.5....T c /etc/mailcap

......G.   /var/cache/samba/winbindd_privileged

.......T c /etc/mail/sendmail.cf

SM5....T c /etc/mail/submit.cf

S.5....T c /var/log/mail/statistics

..5....T c /usr/lib/security/classpath.security

S.5....T c /etc/sane.d/dll.conf

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值