Linux Server hacked

Source: Internet
Author: User
The linux server is hacked-Linux Enterprise Application-Linux server application information. The following is a detailed description. Original person: sery

Log on to a server today, install some software, run ps to view the process, days, a lot of scan-ssh processes. this is a machine that can only be launched. It seems that it is a trick. why? The password is not changed.

Let's see what he has done:

Cd/var/tmp // upload a file to this directory. A total of two files, a.jpg and z, and jpg, are tricky.
Ls
Ls
Tar xvfz a.jpg // decompress the file and run the program start
Cd
./Start
Cd ..
Ls
Ls
Tar xvfz z.jpg // decompress another file
Cd z
Screen
Clear
Ll
Cd/
Ll
Cd/usr/
Ls
Exit //

After carefully reading the process, we found that in addition to the scan-ssh process, there are also unknown processes such as psscan and sh, no matter how many processes are killed, and then change the system password, check the/etc/passwd file to see if a new user has been created. check the directory where the running level is located to see if any abnormal startup process has been created. Check/etc/rc again. local. finally, delete all the files and directories in the/var/tmp directory.

Restart the system and check the process several more times. Fortunately, no other signs of destruction were found. Generally, it is best to back up data and reinstall the system for a business system.

This is another example of setting a simple password to be hacked.
Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.