用rkhunter後門檢測得到的結果 - Linux

Table of Contents

有幾個warning
281 [09:17:35] /usr/bin/unhide.rb [ Warning ]
282 [09:17:35] Warning: The command '/usr/bin/unhide.rb' has been replaced by a script: /usr/bin/unhide.rb: Ruby script, ASCII text


287 [09:17:35] /sbin/chkconfig [ Warning ]
288 [09:17:35] Warning: The command '/sbin/chkconfig' has been replaced by a sc ript: /sbin/chkconfig: a /usr/bin/perl script, ASCII text executable


1660 [09:22:28] Checking for enabled inetd services [ Warning ]
1661 [09:22:28] Warning: Found enabled inetd service: gds_db

1752 [09:23:22] Checking for hidden files and directories [ Warning ]
1753 [09:23:22] Warning: Hidden directory found: /dev/.udev
1754 [09:23:22] Warning: Hidden file found: /dev/.initramfs: symbolic link to `/ run/initramfs'


我中木馬了嗎?我的電腦現在只有53端口是開的,我還是感覺到我電腦上有木馬。

--
心情不好,做做瑜伽吧,伸伸懶腰,心情會變好的。

--

All Comments

Yedda avatarYedda2012-09-10
Mia avatarMia2012-09-11
那么說是沒問題了?
Kristin avatarKristin2012-09-12
只看懂部分內容
Susan avatarSusan2012-09-14
其實指令的部份不見得寫warning就一定有問題
Rae avatarRae2012-09-16
像我朋友的機器su的權限都會自己改過 然後每次rkhunt
-er去檢查su的時候都會寫warning 但是實際上su根本不
Victoria avatarVictoria2012-09-17
會被一般使用者啟動 所以其實是沒有問題的
推測rkhunter對指令有一個檢驗的機制 看是否warning
但就指令的這個部份就算測了結果是warning也不見得一
Damian avatarDamian2012-09-22
定有必要性的問題