日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當(dāng)前位置: 首頁 > 编程资源 > 编程问答 >内容正文

编程问答

centerOS安装chkrootkit

發(fā)布時(shí)間:2023/12/13 编程问答 34 豆豆
生活随笔 收集整理的這篇文章主要介紹了 centerOS安装chkrootkit 小編覺得挺不錯(cuò)的,現(xiàn)在分享給大家,幫大家做個(gè)參考.

Chkrootkit是一個(gè)在本地系統(tǒng)檢查rootkit痕跡的工具,它是檢查系統(tǒng)二進(jìn)制文件是否被rootkit病毒修改的一個(gè)shell腳本。

(1)centerOS安裝chkrootkit

安裝gcc編譯環(huán)境yum install gcc gcc-c++ make -y

安裝chkrootkit.tar.gz

解壓后執(zhí)行

#make sense

?

安裝過程中常見報(bào)錯(cuò)

#make sense

cc -DHAVE_LASTLOG_H -o chklastlog chklastlog.c

cc -DHAVE_LASTLOG_H -o chkwtmp chkwtmp.c

cc -DHAVE_LASTLOG_H?? -D_FILE_OFFSET_BITS=64 -o ifpromisc ifpromisc.c

cc? -o chkproc chkproc.c

cc? -o chkdirs chkdirs.c

cc? -o check_wtmpx check_wtmpx.c

cc -static? -o strings-static strings.c

/usr/bin/ld: cannot find -lc

collect2: ld returned 1 exit status

make: *** [strings-static] Error 1

?

?

# yum install glibc-static

# make clean

?

# ./chkrootkit -V

直接執(zhí)行chkrootkit命令

# ./chkrootkit

Chkrootkit會(huì)對(duì)系統(tǒng)中的重要文件進(jìn)行掃描。

?

一下是官方文檔:

1. What's chkrootkit?
?---------------------

?chkrootkit is a tool to locally check for signs of a rootkit.? It
?contains:

?* chkrootkit: a shell script that checks system binaries for
?? rootkit modification.

?* ifpromisc.c: checks if the network interface is in promiscuous
?? mode.

?* chklastlog.c: checks for lastlog deletions.

?* chkwtmp.c: checks for wtmp deletions.

?* check_wtmpx.c: checks for wtmpx deletions.? (Solaris only)

?* chkproc.c: checks for signs of LKM trojans.

?* chkdirs.c: checks for signs of LKM trojans.

?* strings.c: quick and dirty strings replacement.

?* chkutmp.c: checks for utmp deletions.

?chkwtmp and chklastlog *try* to check for deleted entries in the wtmp
?and lastlog files, but it is *not* guaranteed that any modification
?will be detected.

?Aliens tries to find sniffer logs and rootkit config files.? It looks
?for some default file locations -- so it is also not guaranteed it
?will succeed in all cases.

?chkproc checks if /proc entries are hidden from ps and the readdir
?system call.? This could be the indication of a LKM trojan.? You can
?also run this command with the -v option (verbose).


?2. Rootkits, Worms and LKMs detected
?------------------------------------

?For an updated list of rootkits, worms and LKMs detected by
?chkrootkit please visit: http://www.chkrootkit.org/


?3. Supported Systems
?--------------------

?chkrootkit has been tested on: Linux 2.0.x, 2.2.x, 2.4.x and 2.6.x,
?FreeBSD 2.2.x, 3.x, 4.x and 5.x, OpenBSD 2.x, 3.x and 4.x., NetBSD
?1.6.x, Solaris 2.5.1, 2.6, 8.0 and 9.0, HP-UX 11, Tru64, BSDI and Mac
?OS X.


?4. Package Contents
?-------------------

?README
?README.chklastlog
?README.chkwtmp
?COPYRIGHT
?chkrootkit.lsm

?Makefile
?chklastlog.c
?chkproc.c
?chkdirs.c
?chkwtmp.c
?check_wtmpx.c
?ifpromisc.c
?strings.c
?chkutmp.c

?chkrootkit


?5. Installation
?---------------

?To compile the C programs type:

?# make sense

?After that it is ready to use and you can simply type:

?# ./chkrootkit


?6. Usage
?--------

?chkrootkit must run as root.? The simplest way is:

?# ./chkrootkit

?This will perform all tests.? You can also specify only the tests you
?want, as shown below:

?Usage: ./chkrootkit [options] [testname ...]
?Options:
???????? -h??????????????? show this help and exit
???????? -V??????????????? show version information and exit
???????? -l??????????????? show available tests
???????? -d??????????????? debug
???????? -q??????????????? quiet mode
???????? -x??????????????? expert mode
???????? -r dir??????????? use dir as the root directory
???????? -p dir1:dir2:dirN path for the external commands used by chkrootkit
???????? -n??????????????? skip NFS mounted dirs

?Where testname stands for one or more from the following list:

?aliens asp bindshell lkm rexedcs sniffer w55808 wted scalper slapper
?z2 chkutmp amd basename biff chfn chsh cron crontab date du dirname
?echo egrep env find fingerd gpm grep hdparm su ifconfig inetd
?inetdconf identd init killall ldsopreload login ls lsof mail mingetty
?netstat named passwd pidof pop2 pop3 ps pstree rpcinfo rlogind rshd
?slogin sendmail sshd syslogd tar tcpd tcpdump top telnetd timed
?traceroute vdir w write

?For example, the following command checks for trojaned ps and ls
?binaries and also checks if the network interface is in promiscuous
?mode.

?? # ./chkrootkit ps ls sniffer

?The `-q' option can be used to put chkrootkit in quiet mode -- in
?this mode only output messages with `infected' status are shown.

?With the `-x' option the user can examine suspicious strings in the
?binary programs that may indicate a trojan -- all the analysis is
?left to the user.

?Lots of data can be seen with:

?? # ./chkrootkit -x | more

?Pathnames inside system commands:

?? # ./chkrootkit -x | egrep '^/'

?chkrootkit uses the following commands to make its tests: awk, cut,
?egrep, find, head, id, ls, netstat, ps, strings, sed, uname.? It is
?possible, with the `-p' option, to supply an alternate path to
?chkrootkit so it won't use the system's (possibly) compromised
?binaries to make its tests.

?To use, for example, binaries in /cdrom/bin:

?? # ./chkrootkit -p /cdrom/bin

?It is possible to add more paths with a `:'

?? # ./chkrootkit -p /cdrom/bin:/floppy/mybin

?Sometimes is a good idea to mount the disk from a compromised machine
?on a machine you trust.? Just mount the disk and specify a new
?rootdir with the `-r' option.

?For example, suppose the disk you want to check is mounted under
?/mnt, then:

?? # ./chkrootkit -r /mnt


?7. Output Messages
?------------------

?The following messages are printed by chkrootkit (except with the -x
?and -q command options) during its tests:

?? "INFECTED": the test has identified a command probably modified by
?? a known rootkit;

?? "not infected": the test didn't find any known rootkit signature.

?? "not tested": the test was not performed -- this could happen in
?? the following situations:
???? a) the test is OS specific;
???? b) the test depends on an external program that is not available;
???? c) some specific command line options are given. (e.g. -r ).

?? "not found": the command to be tested is not available;

?? "Vulnerable but disabled": the command is infected but not in use.
?? (not running or commented in inetd.conf)


?8. A trojaned command has been found.? What should I do now?
?------------------------------------------------------------

?Your biggest problem is that your machine has been compromised and
?this bad guy has root privileges.

?Maybe you can solve the problem by just replacing the trojaned
?command -- the best way is to reinstall the machine from a safe media
?and to follow your vendor's security recommendations.


?9. Reports and questions
?------------------------

?Please send comments, questions and bug reports to
?nelson@pangeia.com.br and jessen@cert.br.

?A simple FAQ and Related information about rootkits and security can
?be found at chkrootkit's homepage, http://www.chkrootkit.org.


?10. ACKNOWLEDGMENTS
?-------------------

?See the ACKNOWLEDGMENTS file.

?11. ChangeLog
?-------------

轉(zhuǎn)載于:https://www.cnblogs.com/jjzd/p/6220427.html

總結(jié)

以上是生活随笔為你收集整理的centerOS安装chkrootkit的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網(wǎng)站內(nèi)容還不錯(cuò),歡迎將生活随笔推薦給好友。

主站蜘蛛池模板: 精品无码一区二区三区的天堂 | 欧美日韩国产大片 | 三级av免费| 亚洲四虎av | 久草网视频在线观看 | www.久久艹 | 三上悠亚影音先锋 | 国产成人无码www免费视频播放 | 护士人妻hd中文字幕 | 爱露出 | 亚洲精品天堂成人片av在线播放 | 少妇又色又爽又高潮极品 | aaa日韩 | 国产网红女主播精品视频 | 西方裸体在线观看 | 欧美xxxx日本和非洲 | 欧美激情二区三区 | 精品深夜av无码一区二区老年 | 少妇粉嫩小泬喷水视频www | 国产伦理在线观看 | 麻豆视频一区二区 | 亚洲无人禁区 | 日本成人午夜视频 | 国产精品视频www | 91av国产视频 | 毛片免 | 你懂的在线视频网站 | 国产高清精品一区二区三区 | 永久免费av| 欧美做受69 | 在线播放一级片 | 天天艹夜夜艹 | 色综合久久久久综合体桃花网 | 九九热视频在线观看 | 三级黄色网 | 日韩在线播放av | 国产欧美日韩专区 | 四季av一区二区凹凸精品 | 国产av无码专区亚洲av麻豆 | 久久精品久久久精品美女 | 国产精品亚洲天堂 | 日本三级片在线观看 | 伊人丁香| 日批视频在线 | 大乳村妇的性需求 | 国产无遮挡裸体免费视频 | 欧美午夜精品理论片 | 9久9久9久女女女九九九一九 | 男生女生搞鸡视频 | 在线不卡av电影 | 日韩私人影院 | 久久综合加勒比 | 熟妇熟女乱妇乱女网站 | 国产一区二区视频在线免费观看 | 欧美人性生活视频 | av白浆 | xxxxwww一片 | 夜夜久久 | 少妇太爽了 | 操操操网站 | 国产精品99久久久久久人 | 日本大尺度吃奶做爰视频 | 少妇毛片一区二区三区 | 国产绳艺sm调教室论坛 | 欧美日韩高清一区二区 国产亚洲免费看 | 国产成人精品一区二区三区视频 | 久久久婷 | 天天视频污 | 日韩性欧美 | aaa午夜| 亚洲24p | 男女扒开双腿猛进入爽爽免费 | 亚洲国产经典 | 国产黄色自拍 | 91蜜桃| 91视频网页 | 欧美一区二区免费在线观看 | 国产日本欧美一区二区 | 涩涩视屏 | 久久精品在这里 | 精品久久久久久亚洲精品 | 一本之道久久 | 国产九九久久 | 五月激情五月婷婷 | 在线看的免费网站 | 98国产精品| 秋霞福利| 青在线视频 | 美女脱裤子让男人捅 | 奇米97| 黄色小说网站在线观看 | 精品99在线观看 | 日本熟女毛茸茸 | 岳奶大又白下面又肥又黑水多 | 99久久精品国产成人一区二区 | 男人午夜剧场 | 国产女女调教女同 | 国产精品无码一本二本三本色 | 日韩伦理一区二区 |