设为首页
收藏本站
用户名
Email
自动登录
找回密码
密码
登录
注册
快捷导航
平台
Portal
论坛
BBS
文库
项目
群组
Group
我的博客
Space
搜索
搜索
热搜:
shell
linux
mysql
本版
用户
LinuxSir.cn,穿越时空的Linuxsir!
»
论坛
›
运维技术 —— LinuxSir.cn
›
网络技术\网络安全讨论
›
被黑了吗?
返回列表
查看:
1700
|
回复:
0
被黑了吗?
[复制链接]
blackwhite
blackwhite
当前离线
积分
2506
IP卡
狗仔卡
发表于 2004-8-5 10:35:44
|
显示全部楼层
|
阅读模式
个人的desktop。一直在线。现在出现这个问题。
用chkrootkit检测,网卡是运行在混杂模式下。用lsattr -a /bin的目录,出现这个结果。
s-S-i-dAc---- ./.
suS-iadAcjI-- ./..
s-S-i-dAc---- ./dd
s-S-i-dAc---- ./cp
s-S-i-dAc---- ./df
s-S-i-dAc---- ./ed
s-S-i-dAc---- ./ex
s-S-i-dAc---- ./ln
s-S-i-dAc---- ./ls
s-S-i-dAc---- ./mt
s-S-i-dAc---- ./mv
s-S-i-dAc---- ./ps
s-S-i-dAc---- ./rm
s-S-i-dAc---- ./sh
s-S-i-dAc---- ./su
s-S-i-dAc---- ./vi
s-S-i-dAc---- ./ash
s-S-i-dAc---- ./awk
s-S-i-dAc---- ./cat
s-S-i-dAc---- ./bsh
s-S-i-dAc---- ./csh
s-S-i-dAc---- ./cut
s-S-i-dAc---- ./env
s-S-i-dAc---- ./pwd
s-S-i-dAc---- ./red
s-S-i-dAc---- ./sed
s-S-i-dAc---- ./rpm
s-S-i-dAc---- ./rvi
s-S-i-dAc---- ./tar
s-S-i-dAc---- ./bash
s-S-i-dAc---- ./arch
s-S-i-dAc---- ./date
s-S-i-dAc---- ./cpio
s-S-i-dAc---- ./echo
s-S-i-dAc---- ./gawk
s-S-i-dAc---- ./grep
s-S-i-dAc---- ./gtar
s-S-i-dAc---- ./gzip
s-S-i-dAc---- ./kill
s-S-i-dAc---- ./link
s-S-i-dAc---- ./mail
s-S-i-dAc---- ./more
s-S-i-dAc---- ./nice
s-S-i-dAc---- ./ping
s-S-i-dAc---- ./tcsh
s-S-i-dAc---- ./sort
s-S-i-dAc---- ./stty
s-S-i-dAc---- ./sync
s-S-i-dAc---- ./true
s-S-i-dAc---- ./view
s-S-i-dAc---- ./zcat
s-S-i-dAc---- ./unicode_stop
s-S-i-dAc---- ./bash2
s-S-i-dAc---- ./chgrp
s-S-i-dAc---- ./chmod
s-S-i-dAc---- ./chown
s-S-i-dAc---- ./dmesg
s-S-i-dAc---- ./egrep
s-S-i-dAc---- ./false
s-S-i-dAc---- ./fgrep
s-S-i-dAc---- ./igawk
s-S-i-dAc---- ./login
s-S-i-dAc---- ./mkdir
s-S-i-dAc---- ./mknod
s-S-i-dAc---- ./mount
s-S-i-dAc---- ./pgawk
s-S-i-dAc---- ./rmdir
s-S-i-dAc---- ./rview
s-S-i-dAc---- ./sleep
s-S-i-dAc---- ./touch
s-S-i-dAc---- ./uname
s-S-i-dAc---- ./kbd_mode
s-S-i-dAc---- ./setfont
s-S-i-dAc---- ./unicode_start
s-S-i-dAc---- ./domainname
s-S-i-dAc---- ./aumix-minimal
s-S-i-dAc---- ./doexec
s-S-i-dAc---- ./setserial
s-S-i-dAc---- ./gettext
s-S-i-dAc---- ./netstat
s-S-i-dAc---- ./gunzip
s-S-i-dAc---- ./ipcalc
s-S-i-dAc---- ./hostname
s-S-i-dAc---- ./nisdomainname
s-S-i-dAc---- ./mktemp
s-S-i-dAc---- ./dnsdomainname
s-S-i-dAc---- ./loadkeys
s-S-i-dAc---- ./ash.static
s-S-i-dAc---- ./umount
s-S-i-dAc---- ./unlink
s-S-i-dAc---- ./usleep
s-S-i-dAc---- ./ypdomainname
s-S-i-dAc---- ./basename
s-S-i-dAc---- ./dumpkeys
复制代码
另外一台机器上就不是这个样子的。
------------- ./.
------------- ./..
------------- ./dnsdomainname
------------- ./ping
------------- ./mktemp
------------- ./mount
------------- ./umount
------------- ./nisdomainname
------------- ./domainname
------------- ./hostname
------------- ./netstat
------------- ./cpio
------------- ./sh
------------- ./ypdomainname
------------- ./setserial
------------- ./bash
------------- ./bash2
------------- ./gawk
------------- ./ed
------------- ./red
------------- ./awk
------------- ./basename
------------- ./igawk
------------- ./pgawk
------------- ./egrep
------------- ./fgrep
------------- ./grep
------------- ./chgrp
------------- ./cat
------------- ./ash.static
------------- ./chmod
------------- ./chown
------------- ./cp
------------- ./cut
------------- ./date
------------- ./dd
------------- ./df
------------- ./echo
------------- ./env
------------- ./false
------------- ./link
------------- ./ln
------------- ./ls
------------- ./mkdir
------------- ./mknod
------------- ./mv
------------- ./nice
------------- ./pwd
------------- ./rm
------------- ./rmdir
------------- ./sleep
------------- ./sort
------------- ./stty
------------- ./su
------------- ./sync
------------- ./touch
------------- ./true
------------- ./uname
------------- ./unlink
------------- ./ash
------------- ./gunzip
------------- ./bsh
------------- ./dumpkeys
------------- ./gzip
------------- ./zcat
------------- ./ps
------------- ./rpm
------------- ./sed
复制代码
大家给点意见。自己认为是给黑了。这个机器基本上不开服务的,比较怪的事情。
回复
使用道具
举报
提升卡
置顶卡
沉默卡
喧嚣卡
变色卡
显身卡
返回列表
高级模式
B
Color
Image
Link
Quote
Code
Smilies
您需要登录后才可以回帖
登录
|
注册
本版积分规则
发表回复
回帖后跳转到最后一页
Copyright © 2002-2023
LinuxSir.cn
(http://www.linuxsir.cn/) 版权所有 All Rights Reserved.
Powered by
RedflagLinux!
技术支持:
中科红旗
|
京ICP备19024520号
快速回复
返回顶部
返回列表