konto usunięte
Temat: Zabezpieczenie serwera przed trojanami szkodliwym...
Dostały sie do mnie na serwer jakieś szkodnikih1765292:~# chkrootkit -q
Checking `ls'... INFECTED
Checking `netstat'... INFECTED
Checking `ps'... INFECTED
Checking `top'... INFECTED
The following suspicious files and directories were found:
/usr/lib/jvm/.java-6-sun.jinfo /usr/lib/jvm/java-6-sun-1.6.0.22/lib/visualvm/profiler3/.lastModified /usr/lib/jvm/java-6-sun-1.6.0.22/lib/visualvm/visualvm/.lastModified /usr/lib/jvm/java-6-sun-1.6.0.22/lib/visualvm/platform11/.lastModified /usr/lib/jvm/java-6-sun-1.6.0.22/.systemPrefs /usr/lib/jvm/.java-gcj.jinfo /usr/lib/xulrunner-1.9/.autoreg /lib/init/rw/.mdadm /lib/init/rw/.ramfs
/lib/init/rw/.mdadm
You have 26 process hidden for readdir command
You have 26 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
h1765292:~#
oraz wynik:
rkhunter -c
System checks summary
=====================
File properties checks...
Required commands check failed
Files checked: 139
Suspect files: 3
Rootkit checks...
Rootkits checked : 243
Possible rootkits: 0
Applications checks...
Applications checked: 6
Suspect applications: 2
The system checks took: 3 minutes and 10 seconds
All results have been written to the log file (/var/log/rkhunter.log)
One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
Ostatnio dostałem, e-maila od firmy ze z mojego serwera dedykowanego są wychodzące ataki typu ddos, czy może to przez te zainfekowane pliki nie mogę się ich pozbyć.Krystian Hetmański edytował(a) ten post dnia 04.12.10 o godzinie 13:01