LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
查看: 1700|回复: 0

被黑了吗?

[复制链接]
发表于 2004-8-5 10:35:44 | 显示全部楼层 |阅读模式
个人的desktop。一直在线。现在出现这个问题。
用chkrootkit检测,网卡是运行在混杂模式下。用lsattr -a /bin的目录,出现这个结果。

  1. s-S-i-dAc---- ./.
  2. suS-iadAcjI-- ./..
  3. s-S-i-dAc---- ./dd
  4. s-S-i-dAc---- ./cp
  5. s-S-i-dAc---- ./df
  6. s-S-i-dAc---- ./ed
  7. s-S-i-dAc---- ./ex
  8. s-S-i-dAc---- ./ln
  9. s-S-i-dAc---- ./ls
  10. s-S-i-dAc---- ./mt
  11. s-S-i-dAc---- ./mv
  12. s-S-i-dAc---- ./ps
  13. s-S-i-dAc---- ./rm
  14. s-S-i-dAc---- ./sh
  15. s-S-i-dAc---- ./su
  16. s-S-i-dAc---- ./vi
  17. s-S-i-dAc---- ./ash
  18. s-S-i-dAc---- ./awk
  19. s-S-i-dAc---- ./cat
  20. s-S-i-dAc---- ./bsh
  21. s-S-i-dAc---- ./csh
  22. s-S-i-dAc---- ./cut
  23. s-S-i-dAc---- ./env
  24. s-S-i-dAc---- ./pwd
  25. s-S-i-dAc---- ./red
  26. s-S-i-dAc---- ./sed
  27. s-S-i-dAc---- ./rpm
  28. s-S-i-dAc---- ./rvi
  29. s-S-i-dAc---- ./tar
  30. s-S-i-dAc---- ./bash
  31. s-S-i-dAc---- ./arch
  32. s-S-i-dAc---- ./date
  33. s-S-i-dAc---- ./cpio
  34. s-S-i-dAc---- ./echo
  35. s-S-i-dAc---- ./gawk
  36. s-S-i-dAc---- ./grep
  37. s-S-i-dAc---- ./gtar
  38. s-S-i-dAc---- ./gzip
  39. s-S-i-dAc---- ./kill
  40. s-S-i-dAc---- ./link
  41. s-S-i-dAc---- ./mail
  42. s-S-i-dAc---- ./more
  43. s-S-i-dAc---- ./nice
  44. s-S-i-dAc---- ./ping
  45. s-S-i-dAc---- ./tcsh
  46. s-S-i-dAc---- ./sort
  47. s-S-i-dAc---- ./stty
  48. s-S-i-dAc---- ./sync
  49. s-S-i-dAc---- ./true
  50. s-S-i-dAc---- ./view
  51. s-S-i-dAc---- ./zcat
  52. s-S-i-dAc---- ./unicode_stop
  53. s-S-i-dAc---- ./bash2
  54. s-S-i-dAc---- ./chgrp
  55. s-S-i-dAc---- ./chmod
  56. s-S-i-dAc---- ./chown
  57. s-S-i-dAc---- ./dmesg
  58. s-S-i-dAc---- ./egrep
  59. s-S-i-dAc---- ./false
  60. s-S-i-dAc---- ./fgrep
  61. s-S-i-dAc---- ./igawk
  62. s-S-i-dAc---- ./login
  63. s-S-i-dAc---- ./mkdir
  64. s-S-i-dAc---- ./mknod
  65. s-S-i-dAc---- ./mount
  66. s-S-i-dAc---- ./pgawk
  67. s-S-i-dAc---- ./rmdir
  68. s-S-i-dAc---- ./rview
  69. s-S-i-dAc---- ./sleep
  70. s-S-i-dAc---- ./touch
  71. s-S-i-dAc---- ./uname
  72. s-S-i-dAc---- ./kbd_mode
  73. s-S-i-dAc---- ./setfont
  74. s-S-i-dAc---- ./unicode_start
  75. s-S-i-dAc---- ./domainname
  76. s-S-i-dAc---- ./aumix-minimal
  77. s-S-i-dAc---- ./doexec
  78. s-S-i-dAc---- ./setserial
  79. s-S-i-dAc---- ./gettext
  80. s-S-i-dAc---- ./netstat
  81. s-S-i-dAc---- ./gunzip
  82. s-S-i-dAc---- ./ipcalc
  83. s-S-i-dAc---- ./hostname
  84. s-S-i-dAc---- ./nisdomainname
  85. s-S-i-dAc---- ./mktemp
  86. s-S-i-dAc---- ./dnsdomainname
  87. s-S-i-dAc---- ./loadkeys
  88. s-S-i-dAc---- ./ash.static
  89. s-S-i-dAc---- ./umount
  90. s-S-i-dAc---- ./unlink
  91. s-S-i-dAc---- ./usleep
  92. s-S-i-dAc---- ./ypdomainname
  93. s-S-i-dAc---- ./basename
  94. s-S-i-dAc---- ./dumpkeys
复制代码

另外一台机器上就不是这个样子的。

  1. ------------- ./.
  2. ------------- ./..
  3. ------------- ./dnsdomainname
  4. ------------- ./ping
  5. ------------- ./mktemp
  6. ------------- ./mount
  7. ------------- ./umount
  8. ------------- ./nisdomainname
  9. ------------- ./domainname
  10. ------------- ./hostname
  11. ------------- ./netstat
  12. ------------- ./cpio
  13. ------------- ./sh
  14. ------------- ./ypdomainname
  15. ------------- ./setserial
  16. ------------- ./bash
  17. ------------- ./bash2
  18. ------------- ./gawk
  19. ------------- ./ed
  20. ------------- ./red
  21. ------------- ./awk
  22. ------------- ./basename
  23. ------------- ./igawk
  24. ------------- ./pgawk
  25. ------------- ./egrep
  26. ------------- ./fgrep
  27. ------------- ./grep
  28. ------------- ./chgrp
  29. ------------- ./cat
  30. ------------- ./ash.static
  31. ------------- ./chmod
  32. ------------- ./chown
  33. ------------- ./cp
  34. ------------- ./cut
  35. ------------- ./date
  36. ------------- ./dd
  37. ------------- ./df
  38. ------------- ./echo
  39. ------------- ./env
  40. ------------- ./false
  41. ------------- ./link
  42. ------------- ./ln
  43. ------------- ./ls
  44. ------------- ./mkdir
  45. ------------- ./mknod
  46. ------------- ./mv
  47. ------------- ./nice
  48. ------------- ./pwd
  49. ------------- ./rm
  50. ------------- ./rmdir
  51. ------------- ./sleep
  52. ------------- ./sort
  53. ------------- ./stty
  54. ------------- ./su
  55. ------------- ./sync
  56. ------------- ./touch
  57. ------------- ./true
  58. ------------- ./uname
  59. ------------- ./unlink
  60. ------------- ./ash
  61. ------------- ./gunzip
  62. ------------- ./bsh
  63. ------------- ./dumpkeys
  64. ------------- ./gzip
  65. ------------- ./zcat
  66. ------------- ./ps
  67. ------------- ./rpm
  68. ------------- ./sed
复制代码

大家给点意见。自己认为是给黑了。这个机器基本上不开服务的,比较怪的事情。
您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表