哪位帮我分析一下rkhunter的日志,看看被入侵的程度
[12:09:24] Running Rootkit Hunter 1.1.8 on ADSLserver
[12:09:24]
Rootkit Hunter 1.1.8, Copyright 2003-2004, Michael Boelen
Rootkit Hunter comes with ABSOLUTELY NO WARRANTY. This is free software,
and you are welcome to redistribute it under the terms of the GNU General
Public License. See LICENSE for details.
[12:09:24] Info: Shell /bin/bash
[12:09:24] ------------------------ Configuration check --------------------------
[12:09:24] Parsing configuration file (/usr/local/etc/rkhunter.conf)
[12:09:24] Info: No mail-on-warning address configured
[12:09:24] Info: Using /usr/local/rkhunter/lib/rkhunter/tmp as temporary directory
[12:09:24] Info: Using /usr/local/rkhunter/lib/rkhunter/db as database directory
[12:09:24] Info: Using '/usr/sbin /usr/bin /usr/local/bin /usr/local/sbin /bin /sbin' as binary directory
[12:09:24] -------------------------- Application scan ---------------------------
[12:09:24] Found /usr/sbin/lsof
[12:09:24] Found /usr/bin/find
[12:09:24] Found /usr/bin/lynx
[12:09:24] Found /usr/bin/lsattr
[12:09:24] Found /usr/bin/md5sum
[12:09:24] Found /usr/bin/nmap
[12:09:24] Found /usr/bin/stat
[12:09:24] Found /usr/bin/strings
[12:09:24] Found /usr/bin/wget
[12:09:24] Found /usr/bin/perl (version 5.8.0)
[12:09:24] Found /bin/ls
[12:09:24] Found /bin/ps
[12:09:24] Found /sbin/ip
[12:09:24] Found /sbin/ifconfig
[12:09:25] Found /sbin/lsmod
[12:09:25] Info: WGET found
[12:09:25] Info: NMAP found
[12:09:25] Info: LSOF found
[12:09:25] Info: ip found
[12:09:25] Application scan ended
[12:09:25] ---------------------------- System checks ----------------------------
[12:09:25] Info: kernel is 2.4
[12:09:25] Info: Found /etc/redhat-release
[12:09:25] Info: Full OS name = Red Hat Linux release 9 (Shrike)
[12:09:25] Info: OS ID = 116
[12:09:25] Info: Using /usr/bin/md5sum to verify MD5 hashes
[12:09:25] Info: /usr/bin/md5sum found
[12:09:25] Info: /usr/local/rkhunter/lib/rkhunter/tmp
[12:09:25] Info: UID is zero (root)
[12:09:25] Info: Perl version 5.8.0 found
[12:09:25] Info: Digest::MD5 installed (version 2.20).
[12:09:25] Info: Using Perl Digest::MD5 module instead of /usr/bin/md5sum
[12:09:25] ---------------------------- File checks -----------------------------
[12:09:25] Checking /usr/local/rkhunter/lib/rkhunter/db/md5blacklist.dat... OK
[12:09:26] Checking /usr/local/rkhunter/lib/rkhunter/db/mirrors.dat... OK
[12:09:26] Checking /usr/local/rkhunter/lib/rkhunter/db/programs_bad.dat... OK
[12:09:26] Checking /usr/local/rkhunter/lib/rkhunter/db/programs_good.dat... OK
[12:09:26] ------------------------------ Selftests ------------------------------
[12:09:26] Strings selftest: scanning for string /usr/sbin/ntpsx... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../ls... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../netstat... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../lsof... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../bkit-ssh/bkit-shhk... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../bkit-ssh/bkit-pw... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../bkit-ssh/bkit-shrs... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../uconf.inv... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../psr... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../find... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../pstree... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../slocate... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../du... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../top... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/...... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.../bkit-ssh... OK
[12:09:26] Strings selftest: scanning for string /usr/lib/.bkit-... OK
[12:09:26] Strings selftest: scanning for string /tmp/.bkp... OK
[12:09:26] Strings selftest: scanning for string /tmp/.cinik... OK
[12:09:26] Strings selftest: scanning for string /tmp/.font-unix/.cinik... OK
[12:09:26] Strings selftest: scanning for string /lib/.sso... OK
[12:09:26] Strings selftest: scanning for string /lib/.so... OK
[12:09:26] Strings selftest: scanning for string /var/run/...dica/clean... OK
[12:09:26] Strings selftest: scanning for string /var/run/...dica/xl... OK
[12:09:26] Strings selftest: scanning for string /var/run/...dica/xdr... OK
[12:09:26] Strings selftest: scanning for string /var/run/...dica/psg... OK
[12:09:27] Strings selftest: scanning for string /var/run/...dica/secure... OK
[12:09:27] Strings selftest: scanning for string /var/run/...dica/rdx... OK
[12:09:27] Strings selftest: scanning for string /var/run/...dica/va... OK
[12:09:27] Strings selftest: scanning for string /var/run/...dica/cl.sh... OK
[12:09:27] Strings selftest: scanning for string /usr/bin/.etc... OK
[12:09:27] Strings selftest: scanning for string /usr/lib/.fx/sched_host.2... OK
[12:09:27] Strings selftest: scanning for string /usr/lib/.fx/random_d.2... OK
[12:09:27] Strings selftest: scanning for string /usr/lib/.fx/set_pid.2... OK
[12:09:27] Strings selftest: scanning for string /usr/lib/.fx/cons.saver... OK
[12:09:27] Strings selftest: scanning for string /usr/lib/.fx/adore/adore/adore.ko... OK
[12:09:27] Strings selftest: scanning for string /bin/sysback... OK
[12:09:27] Strings selftest: scanning for string /usr/local/bin/sysback... OK
[12:09:27] Strings selftest: scanning for string /usr/lib/.tbd... OK
[12:09:27] Strings selftest: scanning for string /dev/.lib/lib/lib/t0rns... OK
[12:09:27] Strings selftest: scanning for string /dev/.lib/lib/lib/du... OK
[12:09:27] Strings selftest: scanning for string /dev/.lib/lib/lib/ls... OK
[12:09:27] Strings selftest: scanning for string /dev/.lib/lib/lib/t0rnsb... OK
[12:09:27] Strings selftest: scanning for string /dev/.lib/lib/lib/ps... OK
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
太多了,看看附档吧。
难说。最好有更详细的日志