질문&답변
클라우드/리눅스에 관한 질문과 답변을 주고 받는 곳입니다.
리눅스 분류

rootkit으로 점검한 결과입니다. 어떻게 치료해야하는지요?

작성자 정보

  • 이은재 작성
  • 작성일

컨텐츠 정보

본문

ls명령이 먹히지 않고 dir만 되어서 Rootkit로 서버를 점검하여본 결과 아래와 같이 출력되었습니다.

윗쪽은 감염이 된것과 관계된 것이고, 아래것은 전체를 올린것입니다.

그런데, 사용하다 보니까 ls명령이 먹히고, 물론 dir명령도 먹힙니다.

제가 서버에서 다른 계정으로 들어가서 그런것인가요?

그리고 클라이언트에서 ftp가 되지 않습니다. 물론 proftp가 열려있는데, 접속된후 바로 끊어지는것 같습니다.

어떻게 치료해야 하는지 가르쳐 주세요... 고수님들 부탁해요

----감염관련내용---
Checking `ifconfig'... INFECTED

Checking `login'... INFECTED
Checking `aliens'... /etc/ld.so.hash
Searching for t0rn's v8 defaults... Possible t0rn v8 (or variation) rootkit installed
Searching for Showtee... Warning: Possible Showtee Rootkit installed

Searching for Romanian rootkit ...  /usr/include/file.h /usr/include/proc.h

Searching for ShKit rootkit default files and dirs... Possible ShKit rootkit installed
Checking `lkm'... You have     1 process hidden for readdir command
You have     3 process hidden for ps command
Warning: Possible LKM Trojan installed

 

-------전체내용----

ROOTDIR is `/'

Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not infected
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not infected
Checking `gpm'... not infected
Checking `grep'... not infected
Checking `hdparm'... not infected
Checking `su'... not infected
Checking `ifconfig'... INFECTED
Checking `inetd'... not tested
Checking `inetdconf'... not found
Checking `identd'... not infected
Checking `init'... not infected
Checking `killall'... not infected
Checking `ldsopreload'... not infected
Checking `login'... INFECTED
Checking `ls'... not infected
Checking `lsof'... not infected
Checking `mail'... not infected
Checking `mingetty'... not infected
Checking `netstat'... not infected
Checking `named'... not infected
Checking `passwd'... not infected
Checking `pidof'... not infected
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... not infected
Checking `pstree'... INFECTED
Checking `rpcinfo'... not infected
Checking `rlogind'... not infected
Checking `rshd'... not infected
Checking `slogin'... not infected
Checking `sendmail'... not infected
Checking `sshd'... not infected
Checking `syslogd'... not infected
Checking `tar'... not infected
Checking `tcpd'... not infected
Checking `tcpdump'... not infected
Checking `top'... not infected
Checking `telnetd'... not infected
Checking `timed'... not found
Checking `traceroute'... not infected
Checking `vdir'... not infected
Checking `w'... not infected
Checking `write'... not infected
Checking `aliens'... /etc/ld.so.hash
Searching for sniffer's logs, it may take a while... nothing found
Searching for HiDrootkit's default dir... nothing found
Searching for t0rn's default files and dirs... nothing found
Searching for t0rn's v8 defaults... Possible t0rn v8 (or variation) rootkit installed
Searching for Lion Worm default files and dirs... nothing found
Searching for RSHA's default files and dir... nothing found
Searching for RH-Sharpe's default files... nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while...
/usr/lib/perl5/5.6.1/i386-linux/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gnome/Applet/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gnome/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gtk/GLArea/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gtk/Gdk/ImlibImage/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gtk/Gdk/Pixbuf/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gtk/GladeXML/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gtk/XmHTML/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/Gtk/base/.packlist /usr/lib/perl5/site_perl/5.6.1/i386-linux/auto/NKF/.packlist /usr/lib/qt-3.0.5/etc/settings/.qtrc.lock

Searching for LPD Worm files and dirs... nothing found
Searching for Ramen Worm files and dirs... nothing found
Searching for Maniac files and dirs... nothing found
Searching for RK17 files and dirs... nothing found
Searching for Ducoci rootkit... nothing found
Searching for Adore Worm... nothing found
Searching for ShitC Worm... nothing found
Searching for Omega Worm... nothing found
Searching for Sadmind/IIS Worm... nothing found
Searching for MonKit... nothing found
Searching for Showtee... Warning: Possible Showtee Rootkit installed
Searching for OpticKit... nothing found
Searching for T.R.K... nothing found
Searching for Mithra... nothing found
Searching for OBSD rk v1... nothing found
Searching for LOC rootkit ... nothing found
Searching for Romanian rootkit ...  /usr/include/file.h /usr/include/proc.h
Searching for HKRK rootkit ... nothing found
Searching for Suckit rootkit ... nothing found
Searching for Volc rootkit ... nothing found
Searching for Gold2 rootkit ... nothing found
Searching for TC2 Worm default files and dirs... nothing found
Searching for Anonoying rootkit default files and dirs... nothing found
Searching for ZK rootkit default files and dirs... nothing found
Searching for ShKit rootkit default files and dirs... Possible ShKit rootkit installed
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... not infected
Checking `lkm'... You have     1 process hidden for readdir command
You have     3 process hidden for ps command
Warning: Possible LKM Trojan installed
Checking `rexedcs'... not found
Checking `sniffer'... Checking `w55808'... not infected
Checking `wted'... nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... nothing deleted

 

관련자료

댓글 0
등록된 댓글이 없습니다.

공지사항


뉴스광장


  • 현재 회원수 :  60,034 명
  • 현재 강좌수 :  35,787 개
  • 현재 접속자 :  246 명