Redian新闻
>
紧急求助---机器被侵入.
avatar
紧急求助---机器被侵入.# Security - 系统安全
s*e
1
以下是相关信息. 请高手指点怎么才能干净彻底的解决这个被侵入的机器.
The attack discovered yesterday, Jan. 30.
login: co
System: IRIX 6.5
Connected from: ACA44A79.ipt.aol.com
I logged in as root and used su co to log in as co. I did whoami to find
that co is root.
co has entry in /etc/passwd .
This file was modified on Jan. 30, about one minute after login.
No entry or modification in /etc/shadow .
The system manager application on IRIX gave the following information on
the user:
login: co
real name: PR
home directory: /tmp
g
avatar
d*z
2
my only suggestion is to backup all the useful data and
format and reinstall the machine. it is possible that the
intruder has installed multiple backdoors to your system and
it will be very hard or impossible to detect all of them.

【在 s***e 的大作中提到】
: 以下是相关信息. 请高手指点怎么才能干净彻底的解决这个被侵入的机器.
: The attack discovered yesterday, Jan. 30.
: login: co
: System: IRIX 6.5
: Connected from: ACA44A79.ipt.aol.com
: I logged in as root and used su co to log in as co. I did whoami to find
: that co is root.
: co has entry in /etc/passwd .
: This file was modified on Jan. 30, about one minute after login.
: No entry or modification in /etc/shadow .

avatar
m*t
3
maybe do a tcp/ip dump or use some kind of network sniffer
to find suspicious activities....monitor all processes...search for virus
usually it can be very time consuming. better put some protection before your
network, such as firewall.

【在 d*****z 的大作中提到】
: my only suggestion is to backup all the useful data and
: format and reinstall the machine. it is possible that the
: intruder has installed multiple backdoors to your system and
: it will be very hard or impossible to detect all of them.

相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。