本来昨天就想写本问,因为昨天有点忙,整理这被人放了rootkit的系统,所以就暂时搁浅。现在写下发现的经过。
前天也就是2004年03月21日晚上10点左右,因为有事登陆到放在公司的pc上操作,在执行# netstat -nlp的时候,发现80和443的断口被一个叫xntps的进程所替换了,当时就发现不对,因为xntps自己也不是很清楚,所以马上打开google一查,傻了眼,原来是中了rootkit,所以根据google里查的,查找/etc/rc.d/rc.sysinit文件,发现在该问最后真的有/usr/sbin/xntps -q,所以确信是中了rootkit。
接下去就是先禁该进程,直接# killall -9 xntps发现没用,也许killall命令已经给替换了,所以赶紧# /etc/init.d/syslog restart 然后好歹把那xntps暂时从netstat -nlp中"杀了"。同时去/var/log/去查日志,却发现几乎所有的日志已经被清除,只剩下:/etc/secure,马上把该文件cp到本地,打开一看,下面是/etc/secure的内容:
Mar 21 21:31:06 www useradd[5424]: new user: name=admin, uid=0, gid=0, home=/usr/lib/.admin/, shell=/bin/bash
Mar 21 21:32:57 www sshd[5426]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:32:57 www sshd[5426]: Failed password for ROOT from 194.102.107.185 port 1697
Mar 21 21:33:02 www sshd[5426]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:33:02 www sshd[5426]: Failed password for ROOT from 194.102.107.185 port 1697
Mar 21 21:33:08 www sshd[5426]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:33:08 www sshd[5426]: Failed password for ROOT from 194.102.107.185 port 1697
Mar 21 21:33:30 www sshd[5426]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:33:30 www sshd[5426]: Failed password for ROOT from 194.102.107.185 port 1697
Mar 21 21:33:53 www sshd[5426]: Failed password for ROOT from 194.102.107.185 port 1697
Mar 21 21:34:10 www useradd[5428]: new user: name=ftpd, uid=0, gid=0, home=/usr/lib/.ftpd/, shell=/bin/bash
Mar 21 21:34:42 www sshd[5426]: Connection closed by 194.102.107.185
Mar 21 21:35:32 www sshd[5432]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:35:32 www sshd[5432]: Failed password for ROOT from 194.102.107.185 port 1698
Mar 21 21:35:40 www sshd[5432]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:35:40 www sshd[5432]: Failed password for ROOT from 194.102.107.185 port 1698
Mar 21 21:35:57 www sshd[5432]: ROOT LOGIN REFUSED FROM 194.102.107.185
Mar 21 21:35:57 www sshd[5432]: Failed password for ROOT from 194.102.107.185 port 1698
Mar 21 21:36:00 www sshd[5432]: Connection closed by 194.102.107.185
当时就立即修改admin和ftpd用户的密码,却发现不行,这时候犯了一个致命的错误,没能马上关机,而是重起了,重起后发现自己进不了系统。没办法,只好由他胡作非为了,第二天一到公司,马上拔网线,进系统,发现系统里的所以的东西已经被删干净了。5555,哭也没眼泪,只能怪自己没能做好安全工作。
写下这些只是告诫那些linuxfans不要认为linux就是非常安全的,在没有任何安全配置的情况下仍然是赤裸裸的,很容易被人骇掉的。[/color:4bb6bdebbe]