chkrootkit
¤ÎÊÔ½¸
http://pocketstudio.jp/linux/?chkrootkit
[
¥È¥Ã¥×
] [
ÊÔ½¸
|
º¹Ê¬
|
¥Ð¥Ã¥¯¥¢¥Ã¥×
|
źÉÕ
|
¥ê¥í¡¼¥É
] [
¿·µ¬
|
°ìÍ÷
|
ñ¸ì¸¡º÷
|
ºÇ½ª¹¹¿·
|
¥Ø¥ë¥×
]
-- ¿÷·Á¤È¤¹¤ë¥Ú¡¼¥¸ --
Apache/Tips
Apache/Tips/Basic ǧ¾Ú
Apache/Tips/Digest ǧ¾Ú
Apache/Tips/Digest+ǧ¾Ú
Apache/Tips/mod_auth_digest.so¤Î¥»¥Ã¥È¥¢¥Ã¥×¡¦¥¤¥ó¥¹¥È¡¼¥ë
BBS
BBS/archive1
BitTorrent
BracketName
CentOS
CentOS 3 ¥Ñ¥Ã¥±¡¼¥¸¹¹¿·¡¦¥¨¥é¡¼¥¿¡¦¥»¥¥å¥ê¥Æ¥£¾ðÊó
CentOS 4 ¥Ñ¥Ã¥±¡¼¥¸¹¹¿·¡¦¥¨¥é¡¼¥¿¡¦¥»¥¥å¥ê¥Æ¥£¾ðÊó
CentOS ¤¬ÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë isos ¥Ç¥£¥ì¥¯¥È¥ê·²¤Ë¤¢¤ë¥Õ¥¡¥¤¥ë¤Ï²¿¤Ç¤¹¤«¡©
CentOS ¤Ë´óÉÕ¤·¤è¤¦¤¼¡ª
CentOS ¤Î¥í¥´¤ä²èÁü¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ·¤Æ¤â¹½¤¤¤Þ¤»¤ó¤«¡©
CentOS ÍÑ ¥»¥Ã¥È¥¢¥Ã¥× CD ¥Õ¥¡¥¤¥ë¤Î¥À¥¦¥ó¥í¡¼¥É¤È CD ¤ÎºîÀ®ÊýË¡¤ò¶µ¤¨¤Æ¤¯¤À¤µ¤¤¡£
CentOS/FAQ
CentOS/FAQ/CentOS 2¡¦CentOS 3¡¦CentOS 4 ¤Ï¤É¤Î¤è¤¦¤ËÈæ³Ó¤Ç¤¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS 3.3 ¤Ç¤Î MegaRaid STA 150-2 ¤Ë¤Ä¤¤¤Æ
CentOS/FAQ/CentOS 4 ¤È¤Ï²¿¤Ç¤¹¤«¡©
CentOS/FAQ/CentOS 4 ¤Î³«È¯¼Ô¤Ïï¤Ç¤·¤ç¤¦¡£¤É¤Î¤è¤¦¤ËÏ¢Íí¤ò¼è¤ì¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS 4.x ¤Ë¥¢¥Ã¥×¥°¥ì¡¼¥É¤¹¤ëÂåÂذƤϤ¢¤ê¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS Extras ¤È¤Ï²¿¤Ç¤¹¤«¡©
CentOS/FAQ/CentOS ¤Ç¤Ï¤É¤¦¤·¤Æ GPG ¥¡¼¤¬ yum ¤Ë¥»¥Ã¥È¤µ¤ì¤Æ¤¤¤Ê¤¤¤Î¤Ç¤¹¤«¡©
CentOS/FAQ/CentOS ¤Ç¤Ï¤É¤¦¤·¤Æ GPG ¥¡¼¤¬ yum ¤Ë¥»¥Ã¥È¤µ¤ì¤Æ¤¤¤Ê¤¤¤Î¤Ç¤¹¤«¡©(G)
CentOS/FAQ/CentOS ¤È Red Hat(R)¼Ò¤ä RHEL ¤È¤Ï¤É¤Î¤è¤¦¤Ê´Ø·¸¤Ç¤¹¤«¡©
CentOS/FAQ/CentOS ¤Ë´Ø¤¹¤ëÁ´¤Æ¤Î¥ì¥Ý¥¸¥È¥ê¡Ê¥Ç¥£¥ì¥¯¥È¥ê¡Ë¤Ë´Ø¤¹¤ëÀâÌÀ¤Ï¤¢¤ê¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS ¤Î 3.1¡¦3.2¡¦3.3 ¤È¤ÎÁê°ãÅÀ¤Ï²¿¤Ç¤·¤ç¤¦¡© ¤½¤ì¤é¤ÏÁ´¤Æ RedHat...
CentOS/FAQ/CentOS ¤Î¥Ð¡¼¥¸¥ç¥ó¤ä¥ê¥ê¡¼¥¹¤Ï¤É¤Î¤è¤¦¤Ê»ÅÁȤߤǤ¹¤«¡£¤Þ¤¿¡¢¾å°Ì¥Ù¥ó¥À¡¼¤ÎÄ󶡤¹¤ë¤â¤Î¤È...
CentOS/FAQ/CentOS ¤Ï°ì¼¡ÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë¥½¡¼¥¹ RPM ¥Õ¥¡¥¤¥ë¤òÊѹ¹¤·¤Æ¤¤¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS ¤ò MySQL (¤¢¤ë¤¤¤Ï PostgreSQL) ¤È°ì½ï¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤·¤¿¡£¤Ç¤¹¤¬...
CentOS/FAQ/CentOS ¥ê¥ê¡¼¥¹¤ò¥À¥¦¥ó¥í¡¼¥É¤¹¤ë°Ù¤Ë Bittorrent ¤ò¤É¤¦¤ä¤Ã¤Æ»È¤¨¤Ð¤¤¤¤¤Ç¤¹¤«¡©
CentOS/FAQ/CentOS-2 ¤Î¹¹¿·¤¬¥µ¥Ý¡¼¥È¤µ¤ì¤ë´ü´Ö¤Ï¤É¤ÎÄøÅ٤Ǥ¹¤«¡©
CentOS/FAQ/CentOS-3 ¤Ç RHGFS ¤È RHCS ¤Ï»È¤¨¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS-3 ¤Î¹¹¿·¤¬¥µ¥Ý¡¼¥È¤µ¤ì¤ë´ü´Ö¤Ï¤É¤ÎÄøÅ٤Ǥ¹¤«¡©
CentOS/FAQ/CentOS-4 ¤Ç RHGFS ¤È RHCS ¤Ï»È¤¨¤Þ¤¹¤«¡©
CentOS/FAQ/CentOS-4 ¤Î centosplus ¥ì¥Ý¥¸¥È¥ê¤È¤Ï²¿¤Ç¤¹¤«¡©
CentOS/FAQ/CentOS-4 ¤Î¹¹¿·¤¬¥µ¥Ý¡¼¥È¤µ¤ì¤ë´ü´Ö¤Ï¤É¤ÎÄøÅ٤Ǥ¹¤«¡©
CentOS/FAQ/Donavan »á ¤Ï WhiteBoxLinux ¤ÈƱ¤¸¤¯ CentOS ¤Ë¤â´Ø·¸¤·¤Æ¤¤¤ëÊý¤Ç¤¹¤«¡©
CentOS/FAQ/ISO ¥¤¥á¡¼¥¸¥Õ¥¡¥¤¥ë¤Ï¤É¤³¤Ë¤¢¤ê¤Þ¤¹¤«¡©
CentOS/FAQ/Red Hat ¼Ò¤¬½¤ÀµÈǤòȯɽ¤·¤¿¸å¡¢CentOS ¤Ë½¤Àµ¤¬È¿±Ç¤µ¤ì¤ë¤Î¤Ë¤Ï¤É¤Î¤¯¤é¤¤¤Î´ü´Ö¤òÍפ·¤Þ¤¹¤«¡©
CentOS/FAQ/Red Hat(R) ¼Ò¤Î Directory Server ¤Ï CentOS-4 ¤Ç¤â»È¤¨¤Þ¤¹¤«¡©
CentOS/FAQ/¤É¤³¤«¤é CentOS ÍѤΠRPM ¥Ñ¥Ã¥±¡¼¥¸¤òÆþ¼ê¤Ç¤¤Þ¤¹¤«¡©
CentOS/FAQ/¤É¤³¤Ç CentOS 4 ÍѤΥѥ屡¼¥¸½ð̾¸°¤òÆþ¼ê¤Ç¤¤Þ¤¹¤«¡©
CentOS/FAQ/¤É¤Î¤è¤¦¤Ê¥¢¡¼¥¥Æ¥¯¥Á¥ã¤¬¥µ¥Ý¡¼¥È¤µ¤ì¤Þ¤¹¤«¡©
CentOS/FAQ/¤É¤Î¤è¤¦¤Ë¤·¤Æ CentOS ¤Î¹¹¿·¾ðÊó¤òÆþ¼ê¤Ç¤¤Þ¤¹¤«¡©
CentOS/FAQ/¤É¤Î¤è¤¦¤Ë¤·¤Æ RedHat 9 ¤«¤é CentOS 3 ¤Ë¥·¥¹¥Æ¥à¤ò°Ü¹Ô¤Ç¤¤Þ¤¹¤«¡©
CentOS/FAQ/¤É¤Î¤è¤¦¤Ë¤·¤Æ WBEL-3 (White Box Exterprise Linux) ¤«¤é CentOS 3 ¤Ë¥·¥¹¥Æ¥à¤ò°Ü¹Ô¤Ç¤¤Þ¤¹¤«¡©
CentOS/FAQ/¤Ê¤¼ CentOS ¤¬Â¸ºß¤¹¤ë¤Î¤Ç¤¹¤«¡©
CentOS/FAQ/»ä¤¬¥À¥¦¥ó¥í¡¼¥É¤·¤¿ x86_64 ÍѤΠCentOS 3.3 ¤Ï¥Ð¡¼¥¸¥ç¥ó¤¬ RC1 ¤Èɽ¼¨¤µ¤ì¤Þ¤¹...
CentOS/FAQ/¾å°Ì¥Ù¥ó¥À¡¼¤Ï Enterprise Linux ¤È¤·¤Æ AS¡¦ES¡¦WS¡¦PWS ¤È¤¤¤Ã¤¿Ê£¿ô¤Î¥Ð¡¼¥¸¥ç¥ó¤òÄó¶¡...
CentOS/FAQ/¿¤¯¤Î RPM ¤Ë¤Ï redhat ¤ä rhel ¤ä rh ¤È¤¤¤¦Ê¸»ú¤¬´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤é¤ÏÊѹ¹¤·¤Ê¤¤¤Î¤Ç¤¹¤«¡©
CentOS/FAQ/郎 CentOS 2.0 ¤ò´ÉÍý¤·¤Æ¤¤¤ë¤Î¤Ç¤·¤ç¤¦¡£
CentOS/FAQ/郎 CentOS 3 ¤ò¥á¥ó¥Æ¥Ê¥ó¥¹¤·¤Æ¤¤¤ë¤Î¤Ç¤·¤ç¤¦¡©
CentOS/FAQ_ja
CentOS3/security/i386/CESA-2006 0710 Important CentOS 3 i386 kernel
CentOS3/security/i386/CESA-2006 0720 Critical CentOS 3 i386 kdelibs
CentOS3/security/i386/CESA-2006 0725 Moderate CentOS 3 i386 qt
CentOS3/security/i386/CESA-2006 0726 Moderate CentOS 3 i386 wireshark
CentOS3/security/i386/CESA-2006 0727 Moderate CentOS 3 i386 texinfo
CentOS3/security/i386/CESA-2006 0729 Moderate CentOS 3 i386 ruby
CentOS3/security/i386/CESA-2006 0730 Important CentOS 3 i386 php
CentOS3/security/i386/CESA-2006 0734 Critical CentOS 3 i386 seamonkey
CentOS3/security/i386/CESA-2006 0738 Low CentOS 3 i386 openssh
CentOS3/security/i386/CESA-2007 0015 Moderate CentOS 3 i386 ImageMagick
CentOS3/security/i386/CESA-2007 0044 Moderate CentOS 3 i386 bind
CentOS3/security/i386/CESA-2007 0060 Moderate CentOS 3 i386 samba
CentOS3/security/i386/CESA-2007 0064 Moderate CentOS 3 i386 postgresql
CentOS3/security/i386/CESA-2007 0076 Important CentOS 3 i386 php
CentOS3/security/i386/CESA-2007 0086 Critical CentOS 3 i386 gnomemeeting
CentOS3/update/Critical CentOS 3 i386 sendmail
CentOS4/security/i386/CESA-2006 0713 python
CentOS4/security/i386/CESA-2006 0719 Moderate CentOS 4 i386 nss_ldap
CentOS4/security/i386/CESA-2006 0720 Critical CentOS 4 i386 kdelibs
CentOS4/security/i386/CESA-2006 0725 Moderate CentOS 4 i386 qt
CentOS4/security/i386/CESA-2006 0726 Moderate CentOS 4 i386 wireshark
CentOS4/security/i386/CESA-2006 0727 Moderate CentOS 4 i386 texinfo
CentOS4/security/i386/CESA-2006 0729 Moderate CentOS 4 i386 ruby
CentOS4/security/i386/CESA-2006 0730 Important CentOS 4 i386 php
CentOS4/security/i386/CESA-2006 0733 Critical CentOS 4 i386 firefox
CentOS4/security/i386/CESA-2006 0734 Critical CentOS 4 i386 seamonkey
CentOS4/security/i386/CESA-2006 0735 Critical CentOS 4 i386 thunderbird
CentOS4/security/i386/CESA-2006 0738 Low CentOS 4 i386 openssh
CentOS4/security/i386/CESA-2006 0742 Critical CentOS 4 i386 elinks
CentOS4/security/i386/CESA-2007 0008 Moderate CentOS 4 i386 dbus
CentOS4/security/i386/CESA-2007 0014 Important CentOS 4 i386 kernel
CentOS4/security/i386/CESA-2007 0015 Moderate CentOS 4 i386 ImageMagick
CentOS4/security/i386/CESA-2007 0018 Moderate CentOS 4 i386 fetchmail
CentOS4/security/i386/CESA-2007 0019 Moderate CentOS 4 i386 gtk2
CentOS4/security/i386/CESA-2007 0022 Moderate CentOS 4 i386 squirrelmail
CentOS4/security/i386/CESA-2007 0044 Moderate CentOS 4 i386 bind
CentOS4/security/i386/CESA-2007 0060 Moderate CentOS 4 i386 samba
CentOS4/security/i386/CESA-2007 0064 Moderate CentOS 4 i386 postgresql
CentOS4/security/i386/CESA-2007 0076 Important CentOS 4 i386 php
CentOS4/security/i386/CESA-2007 0086 Critical CentOS 4 i386 gnomemeeting
CentOS4/security/x86_64/CESA-2006 0713 python
CentOS4/security/x86_64/CESA-2006 0719 Moderate CentOS 4 x86_64 nss_ldap
CentOS4/security/x86_64/CESA-2006 0720 Critical CentOS 4 x86_64 kdelibs
CentOS4/security/x86_64/CESA-2006 0725 Moderate CentOS 4 i386 qt
CentOS4/security/x86_64/CESA-2006 0726 Moderate CentOS 4 x86_64 wireshark
CentOS4/security/x86_64/CESA-2006 0727 Moderate CentOS 4 x86_64 texinfo
CentOS4/security/x86_64/CESA-2006 0729 Moderate CentOS 4 x86_64 ruby
CentOS4/security/x86_64/CESA-2006 0730 Important CentOS 4 x86_64 php
CentOS4/security/x86_64/CESA-2006 0733 Critical CentOS 4 x86_64 firefox
CentOS4/security/x86_64/CESA-2006 0734 Critical CentOS 4 x86_64 seamonkey
CentOS4/security/x86_64/CESA-2006 0735 Critical CentOS 4 x86_64 thunderbird
CentOS4/security/x86_64/CESA-2006 0738 Low CentOS 4 x86_64 openssh
CentOS4/security/x86_64/CESA-2006 0742 Critical CentOS 4 x86_64 elinks
CentOS4/security/x86_64/CESA-2007 0008 Moderate CentOS 4 x86_64 dbus
CentOS4/security/x86_64/CESA-2007 0014 Important CentOS 4 x86_64 kernel
CentOS4/security/x86_64/CESA-2007 0015 Moderate CentOS 4 x86_64 ImageMagick
CentOS4/security/x86_64/CESA-2007 0018 Moderate CentOS 4 x86_64 fetchmail
CentOS4/security/x86_64/CESA-2007 0019 Moderate CentOS 4 x86_64 gtk2
CentOS4/security/x86_64/CESA-2007 0022 Moderate CentOS 4 x86_64 squirrelmail
CentOS4/security/x86_64/CESA-2007 0044 Moderate CentOS 4 x86_64 bind
CentOS4/security/x86_64/CESA-2007 0060 Moderate CentOS 4 x86_64 samba
CentOS4/security/x86_64/CESA-2007 0064 Moderate CentOS 4 x86_64 postgresql
CentOS4/security/x86_64/CESA-2007 0076 Important CentOS 4 x86_64 php
CentOS4/security/x86_64/CESA-2007 0086 Critical CentOS 4 x86_64 gnomemeeting
CentOS4/update/CESA-2006 0689 kernel
CentOS4/update/Critical CentOS 4 i386 sendmail
C¸À¸ì
DRAC(Dynamic Relay Authorization)¤Ë¤Ä¤¤¤Æ¤ÎÆüËܸì¾ðÊó
DRAC/DRAC(Dynamic Relay Authorization Control)¥É¥¥å¥á¥ó¥ÈÏÂÌõ
DRAC/POP IMAP ¥µ¡¼¥Ð¤ÎÄ´À° (POP IMAP Server Modifications)
DRAC/doc/INSTALL
DRAC/doc/PORTING
DRAC/doc/README
DRAC/doc/dracd-setup.linux
DRAC/doc/dracd.allow-sample
DRAC/¥¤¥ó¥¹¥È¡¼¥ë (Instaling)
DRAC/¥³¥ó¥Ñ¥¤¥ë (Compiling)
DRAC/¥Æ¥¹¥È (Testing)
DRAC/¥á¡¼¥ë¥µ¡¼¥ÐÄ´À° (Mail Server Configuration)
DomainKey
DomainKeys
Dovecot/Dovecot¤Ã¤Æ²¿¡©
English
FC4/Apache/Apache¤Î¥»¥Ã¥È¥¢¥Ã¥×
FC4/Apache/°ìÈ̥桼¥¶¤Î¥¦¥§¥Öɽ¼¨
FC4/FAQ/TeraTerm ¤¬Ê¸»ú²½¤±¤·¤Æ¤Þ¤¹¤¬¡©
FC4/FAQ/man ¤¬Ê¸»ú²½¤±¤·¤Æ¤Þ¤¹¤¬¡©
FC4/FAQ/slocate ¤ä locate ¤¬»È¤¨¤Ê¤¤¡©
FC4/FAQ/¥·¥¹¥Æ¥à¤Îʸ»ú¥³¡¼¥É¤ò EUC_JP ¤Ë¤·¤¿¤¤¤ó¤Ç¤¹¤¬¡©
FC4/FAQ/¥·¥ó¥°¥ë¥â¡¼¥É¤ÇÆ°ºî¤µ¤»¤ë¤Ë¤Ï¡©
FC4/FAQ/¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤¬ Read-Only ¤Ë¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡Ä¡Ä
FC4/FAQ/¥é¥ó¥ì¥Ù¥ë¤ÎÊѹ¹¤ò¤·¤¿¤¤¤ó¤À¤±¤É¡©
FC4/FSElinx/¥á¥â/FC4 ¾å¤Ç SELinux ¤Î targeted ¥Ý¥ê¥·¡¼¤¬Å¬ÍѤµ¤ì¤ë¥Ç¡¼¥â¥ó
FC4/FSElinx/¥á¥â/SELinux ´Ä¶¤Ç¤Ï quota ¤Ï»È¤¨¤Ê¤¤
FC4/PHP/¥Þ¥ë¥Á¥Ð¥¤¥Èʸ»úÎó´Ø¿ô¤Ø¤ÎÂбþÊýË¡
FC4/SELinux/FC4 ¤Çɸ½à¤Î SELinux Æ°ºî¥â¡¼¥É
FC4/SELinux/FC4 ¾å¤Ç SELinux ¤Î¥í¥°¤ò³Îǧ¤¹¤ë¤Ë¤Ï¡©
FC4/SELinux/SELinux ¤ò̵¸ú¤Ë¤¹¤ë¤Ë¤Ï¡©
FC4/SELinux/struct¤ò»î¤·¤¿¡£¥Ï¥Þ¤Ã¤¿
FC4/SELinux/¥Ý¥ê¥·¡¼¤ò¼êÆ°¤ÇÀßÄꤹ¤ë¤Ë¤Ï
FC4/SELinux/Æ°ºî¥â¡¼¥É³Îǧ¡¦Êѹ¹¤Èµ¯Æ°»þ¤ÎÀßÄê
FC4/TIP/GRUB/¥«¡¼¥Í¥ëÁªÂò»þ´Ö¤ÎÊѹ¹
FC4/TIP/¥Ñ¥¹¥ï¡¼¥É¤Î´Ê°×ºîÀ®
FC4/TIP/´Êñ¤ËÅŸ»¤òÍî¤È¤¹ poweroff
FC4/TIP/ɸ½à¤Ç½àÈ÷¤µ¤ì¤Æ¤¤¤Ê¤¤¥×¥í¥°¥é¥à¤ÎRPM¤Ï¡©
FC4/VNC¤Ë¤è¤ë¥ê¥â¡¼¥È¤«¤é¤Î X Window Áàºî
FC4/dovecot/dovecot ¤Ë¤è¤ë APOPǧ¾Ú(DIGEST-MD5)¤ò»È¤Ã¤¿°ÂÁ´¤Ê¥í¥°¥¤¥ó
FC4/dovecot/dovecot ¤Ë¤è¤ë MRA(¥á¡¼¥ë¼õ¿®¥µ¡¼¥Ð)¤òÍѤ¤¤¿ pop3,pop3s,imap,imap4¹½ÃÛ
FC4/quota
FC4/quota/1.quota ¤È¤Ï¤Ê¤ó¤À¡©¿©¤¨¤ë¤Î¤«¡©
FC4/quota/2.quota ¤ò»È¤¦¤¿¤á¤ÎÀßÄê
FC4/quota/3.quota ¤Î±¿ÍѤˤè¤ë¥Ç¥£¥¹¥¯ÍÆÎÌÀ©¸Â
FC4/quota/4.quota ¤ÈSELinux
FC4/quota/5.quota ¤ÎÀßÄê¤òÇѻߤ¹¤ë
FC4/sendmail/FC4ÉÕ°¤Îsendmail¤ÇSMTPS¤ÈSMTP AUTH(SMTPǧ¾Ú)¤ËÂбþ¤µ¤»¤ëÊýË¡
FC4/sendmail/MTA ¤È¤·¤Æ¤Î sendmail ¤ÎÀßÄê(¥á¡¼¥ë¤òÁ÷¤ë¤¿¤á¤ËºÇÄã¸ÂÅÙ¤¹¤Ù¤»ö)
FC4/sendmail/SMTP¥Ý¡¼¥È25À©¸ÂÂкö¤Î¥µ¥Ö¥ß¥Ã¥·¥ç¥ó¡¦¥Ý¡¼¥È(Submission Port)ÍøÍÑ
FC4/sendmail/smrsh À©¸Â¤ò¼ê·Ú¤Ë¼è¤ê½ü¤¯ÊýË¡
FC4/ssh/ssh ¥µ¡¼¥Ð¤Î¥»¥¥å¥ê¥Æ¥£ÀßÄê
FC4/telnet/¥µ¡¼¥Ð¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ÈÀßÄê
FC4/vsftpd
FC4/vsftpd/1.FTP ¥µ¡¼¥Ð¤Î¥»¥Ã¥È¥¢¥Ã¥×
FC4/vsftpd/2.vsftpd ¤Î½é´ü¥»¥Ã¥È¥¢¥Ã¥×
FC4/vsftpd/3.vsftpd ¤ÎÀßÄêÊѹ¹ÊýË¡¤äÊØÍøµ»
FC4/vsftpd/4.vsftpd ¤Îºï½ü
FC4/xinetd
FC4/¥»¥Ã¥È¥¢¥Ã¥×CD¤ÎºîÀ®
FC4/¥»¥Ã¥È¥¢¥Ã¥×¥á¥â
FC4ÉÕ°¤Î sendmail ¤Ç APOP ǧ¾Ú¤È pop3s ¤Ø¤ÎÂбþ(qpopper)
FC4ÉÕ°¤Î sendmail ¤Ç POP before SMTP(qpopper+DRAC)¤Ø¤ÎÂбþ
FC5/update/Update¡§ beagle-0.2.3-4
FC5/update/Update¡§ curl-7.15.1-3
FC5/update/Update¡§ perl-Archive-Tar-1.29-1
FC5/update/Update¡§ samba-3.0.22-1.fc5
FC5/update/Update¡§ sendmail-8.13.6-0.FC5.1
FC5/¥»¥Ã¥È¥¢¥Ã¥× CD ¤ÎºîÀ®
FC5/¥À¥¦¥ó¥í¡¼¥É¾ðÊó¡ÊÆüËܹñÆâ¥ß¥é¡¼¤Î°ìÍ÷¡Ë
FC5/¥Ë¥å¡¼¥¹µ»ö
FC5/¥Ñ¥Ã¥±¡¼¥¸¹¹¿·¡¦¥¨¥é¡¼¥¿
FC5/¥ê¥ê¡¼¥¹¥Î¡¼¥È
FC6/Fedora Core 6 ¤Î¥À¥¦¥ó¥í¡¼¥É¾ðÊó
FC6/FedoraCore6
FC6/FedoraXenQuickstartFC6
FC6/ReleaseNotes
FC6/Schedule
FC6/¥»¥Ã¥È¥¢¥Ã¥×CD¤ÎºîÀ®
FC6/¥»¥Ã¥È¥¢¥Ã¥×¡¦¥¬¥¤¥É
FC6/¥»¥Ã¥È¥¢¥Ã¥×¡¦¥¬¥¤¥É/1.CD¤â¤·¤¯¤ÏDVD¤«¤é¥Ö¡¼¥È¤¹¤ë
FC6/¥»¥Ã¥È¥¢¥Ã¥×¡¦¥¬¥¤¥É/2.¥¢¥Ê¥³¥ó¥À¤Ç¤Î¥¤¥ó¥¹¥È¡¼¥ë
FHS
FHS/1. Introduction - ¤Ï¤¸¤á¤Ë
FHS/2. ¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à
FHS/3. root ¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à
FHS/4. /usr ³¬ÁØ
FHS/5. /var ³¬ÁØ
FHS/6. ¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¡¦¥·¥¹¥Æ¥àÆÃͤÎÊäÂÀâÌÀ
FHS/7. ÉÕÏ¿(Appendix)
Fedora
Fedora 7
Fedora 7/Schedule
Fedora Core 6 ¤Î¿·µ¡Ç½¤Þ¤È¤á
Fedora Core 6 ¥¤¥ó¥¹¥È¡¼¥ë¡¦¥¬¥¤¥É
Fedora Core 6 ¥µ¡¼¥Ð±¿ÍÑ¥¬¥¤¥É
Fedora Foundation
Fedora+Core+6+¥µ¡¼¥Ð±¿ÍÑ¥¬¥¤¥É
Fedora/F8
Fedora/Fedora Union Project
Fedora/¾ðÊó¤ò¼ê¤ËÆþ¤ì¤ë¤Ë¤Ï¡©
FedoraCore/Fedora Legacy shutting down
FedoraCore4/Fedora Core 4 Release Note Errata ¥ê¥ê¡¼¥¹¥Î¡¼¥ÈÏÂÌõ
FedoraCore4/Fedora Core 4 Release Note Extr ¥ê¥ê¡¼¥¹¥Î¡¼¥ÈÏÂÌõ
FedoraCore4/Fedora Core 4 Release Note ¥ê¥ê¡¼¥¹¥Î¡¼¥ÈÏÂÌõ
FedoraCore4/Fedora Core 4 ¾ðÊó¤Î¤Þ¤È¤á
FedoraXenQuickstart
FeodraCore4¤Î¥À¥¦¥ó¥í¡¼¥ÉÀè
FrontPage
GFDL
GFDL 1.2 ¤Ë´ð¤Å¤¯Åö¥µ¥¤¥ÈÃøºî¸¢É½µ(±Ñ¸ì¤Ç¤¹¡£¤¹¤ß¤Þ¤»¤ó)
InitNG ¤Ç¹â®¥Ö¡¼¥È
InitNG/Documentation
InterWiki
InterWikiName
InterWikiSandBox
InterWiki¥Æ¥¯¥Ë¥«¥ë
KTBBS
LVM2(ÏÀÍý¥Ü¥ê¥å¡¼¥à¥Þ¥Í¡¼¥¸¥ã)¤ò CentOS-4 ¤Ç»È¤¦¤Ë¤Ï¤É¤Î¤è¤¦¤Ë¤·¤¿¤é¤è¤¤¤Î¤Ç¤¹¤«¡©
Linux
LinuxSoft
Linux»¨µ
LinuxÆþÌç
Logcheck
Logcheck/README ÆüËܸìÌõ
MAIL
MAIL/RFC 2554 - SMTP Service Extentions for Authentication
MAIL/RFC2554 SMTP Service Extentions for Authentication
MTA/AntiSPAM/Domain Keys¤Ã¤Æ²¿¡©
MTA/AntiSPAM/Sender ID ¤òƳÆþ¤·¤Æ¤ß¤ë
MTA/AntiSPAM/Sender ID¤Ã¤Æ²¿¡©
MTA/AntiSPAM/Sendmail ¤Ø¤Î Domain Keys ¼ÂÁõ
MTA/AntiSPAM/Sendmail ¤Ø¤Î Sender ID ¼ÂÁõ
Mail
MenuBar
Notes
ONSE Telecom Co. (SHINBIRO)
PHP
PayPal
Perl
Pocketstudio.jp Linux Wiki
Pocketstudio.jp Linux Wiki FrontPage
Pocketstuido.jp Linux wiki in Chinese traditional
Pocketstuido.jp Linux wiki in English
PortSentry
PortSentry/README ÆüËܸìÌõ
PukiWiki
PukiWiki/1.4/Manual/Plugin
PukiWiki/1.4/Manual/Plugin/A-D
PukiWiki/1.4/Manual/Plugin/E-G
PukiWiki/1.4/Manual/Plugin/H-K
PukiWiki/1.4/Manual/Plugin/L-N
PukiWiki/1.4/Manual/Plugin/O-R
PukiWiki/1.4/Manual/Plugin/S-U
PukiWiki/1.4/Manual/Plugin/V-Z
PukiWiki/¥Ä¥¢¡¼
RecentDeleted
RedHat
Rookit Hunter/Fedora Core 4 ¤Ç»î¤¹
Rootkit Hunter
Rootkit Hunter/FAQ ÆüËܸìÈÇ
SELinux
SELinux Policy Editor ¤Ë¤Ä¤¤¤Æ
SELinux/FAQ
SELinux/SELinux¤È¤Ï²¿¤¾¤ä¡©
SELinux/SELinux´ØÏ¢½ñÀÒ
SPAMÂкö
SandBox
Selinux/SELinux¤È¤Ï²¿¤¾¤ä¡©
Selinux/SELinux´ØÏ¢½ñÀÒ
ServerName
SourceForge
Ubuntu
Unix ¤Ë´Ø¤¹¤ë¥á¥â
Unix/dev/null¤ÎÌò³ä
UserDir
VineLinux
WhiteBox
WhiteBoxLinux
WikiEngines
WikiName
WikiWikiWeb
X Windows ¥µ¡¼¥Ð¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤¤¤Þ¤»¤ó¡£¥¤¥ó¥¹¥È¡¼¥ë¸å¤Ë X Window ¥µ¡¼¥Ð¤òÄɲäǤ¤Þ¤¹¤«¡©
Xen
Xen/Docs/¥æ¡¼¥¶¡¼¥º¥Þ¥Ë¥å¥¢¥ëÆüËܸìÈÇ2.0
Xen/FedoraXenQuickStart
Xen/Xen Faq - Xen ¸ø¼° Wiki ÆüËܸìÌõ 2.0
Xen/Xen ¤Ë¤è¤ë Linux ¾å¤Ç¤Î²¾ÁÛ²½´Ä¶¹½ÃÛ
Xen/XenFaq - Xen ¸ø¼° Wiki ÆüËܸìÌõ
Xen/XenFaq+-+Xen+¸ø¼°+Wiki+ÆüËܸìÌõ
YukiWiki
analog
analog/6.0/doc/analog ¥É¥¥å¥á¥ó¥ÈÏÂÌõ¥×¥í¥¸¥§¥¯¥È
analog/6.0/doc/analog/Macintosh
analog/6.0/doc/analog/Windows 95 °Ê¹ß
analog/6.0/doc/analog/analog ¤Î¥«¥¹¥¿¥Þ¥¤¥º
analog/6.0/doc/analog/analog ¤ò»È¤¤»Ï¤á¤ë
analog/6.0/doc/analog/¤½¤Î¾¤¹¤Ù¤Æ
analog/6.0/doc/analog/¥³¥Þ¥ó¥ÉÁḫɽ
analog/6.0/doc/analog/¥í¥°¥Õ¥¡¥¤¥ë¤ÎÁªÂò
analog/6.0/doc/analog/¥í¥°¥Õ¥©¡¼¥Þ¥Ã¥È¤Î»ØÄê
analog/6.0/doc/analog/²òÀÏ·ë²Ì¤Ë¤Ä¤¤¤Æ
analog/6.0/doc/analog/´ðËÜŪ¤Ê¥³¥Þ¥ó¥É
analog/6.0/doc/analog/¸¡º÷¸ì¶ç
analog/6.0/doc/analog/½ÐÎϤÎÄ´À°
analog/6.0/doc/analog/½ÐÎÏ·Á¼°
analog/6.0/doc/analog/ÀßÄꥳ¥Þ¥ó¥É¤Î¹½Ê¸
analog/log2jp
bbs
bootchart
bootchart¤Çµ¯Æ°»þ¤Î¥×¥í¥»¥¹¿ä°Ü¤äÉé²Ù¤ò¥°¥é¥Õ²½
centos4/security/x86_64/cesa-2007 0064 moderate centos 4 x86_64 postgresql
chkrootkit
chkrootkit FAQ ÆüËܸìÌõ
chkrootkit README ÆüËܸìÌõ
chkrootkit ¸ø¼°¥µ¥¤¥ÈÆüËܸ첽
command/pwd - ¸½ºß°ÌÃ֤γÎǧ
linux/ML/¥Í¥Ã¥È¥ï¡¼¥¯
linux/ML/Á´ÈÌ
linux/xinetd.conf
mta/antispam/sender id ¤òƳÆþ¤·¤Æ¤ß¤ë
perl/module/Net-Telnet¥â¥¸¥å¡¼¥ë
pocketstudio.jp linux wiki
qmail/FAQ
rkdat README ÏÂÌõ
rkdet
rkdet ¥É¥¥å¥á¥ó¥ÈÏÂÌõ
rkdit ¥É¥¥å¥á¥ó¥ÈÏÂÌõ
whereis
yum
¤´°ÆÆâ
¥·¥§¥ë(shell)¤È¤Ï¡©
¥·¥¹¥Æ¥à¹½À®(Æ°ºî´Ä¶)¤Ë¤Ä¤¤¤Æ¶µ¤¨¤Æ¤¯¤À¤µ¤¤
¥½¥Õ¥È¥¦¥§¥¢ RAID ¤Ï CentOS-4 ¤Ç¤É¤Î¤è¤¦¤Ë¹½ÃۤǤ¤Þ¤¹¤«¡©
¥Ñ¥¹(PATH)¤Î³Îǧ¤ÈÀßÄêÊýË¡¤Ï¡©
¥×¥í¥Ð¥¤¥À¤Ë¤³¤Î¤è¤¦¤ÊÄ̹ð
¥×¥í¥ó¥×¥È¤Î³Îǧ¤äÀßÄê
¥Ø¥ë¥×
¥â¥¸¥å¡¼¥ë¤Î´ðËÜ - CPAN ¤«¤é Perl ¤Î¥â¥¸¥å¡¼¥ë¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë
¶µ¤¨¤Æ
»²¾È¿ô
À°·Á¥ë¡¼¥ë
Á°ÐÇ
Ä̤ꤹ¤¬¤ê¤Î³ØÀ¸¤µ¤ó
ÆÃÄê¥Õ¥¡¥¤¥ë¤Î¥Ñ¥¹¤òõ¤¹¤Ë¤Ï¡©
ÆüËܸì
Ìîµå¥Ö¥í¥°¤Ø¤è¤¦¤³¤½¡ª
1
[[LinuxSoft]] #contents ---- * News [#n601e887] - 2006ǯ10·î10Æü chkrootkit [[ºÇ¿·ÈÇ Version 0.47 ¤¬¥ê¥ê¡¼¥¹>http://www.chkrootkit.org/download/]]¤µ¤ì¤Þ¤·¤¿¡£chkrootkit ¤È¤·¤Æ¤Ïµ×¡¹¤Î¥ê¥ê¡¼¥¹¤Ë¤Ê¤ê¤Þ¤¹¡£ - 2006ǯ10·î11Æü chkrootkit [[¸ø¼°¥µ¥¤¥È>http://www.chkrootkit.org/]] ÆüËܸ첽¥×¥í¥¸¥§¥¯¥È¤òÀµ¼°¤Ë¥¹¥¿¡¼¥È¤·¤Þ¤¹¡£ * ¸ø¼°¥µ¥¤¥ÈÆüËܸ첽¥×¥í¥¸¥§¥¯¥È [#nd428bbb] ¡¡[[chkrootkit ¸ø¼°¥µ¥¤¥ÈÆüËܸ첽]]¥×¥í¥¸¥§¥¯¥È¤ò³«»Ï¤·¤Þ¤¹(2006ǯ10·î11Æü)¡£&br; - ¸ø¼°¥µ¥¤¥È http://www.chkrootkit.org/ ¡¡¾ÜºÙ¤Ê·Ð°Þ¤Ï¸ø¼°¥á¡¼¥ê¥ó¥°¥ê¥¹¥È users@chkrootkit.it.org ¤Î "Subject: [crt-users] May I make a translation site? (in Japanese)"¤Ë³¤¯¥¹¥ì¥Ã¥É¤ò¤´Í÷²¼¤µ¤¤¡£¥¢¡¼¥«¥¤¥Ö¤Î±ÜÍ÷¤Ï¤Ç¤¤Ê¤¤¤è¤¦¤Ç¤¹¡£¼õ¿®¤µ¤ì¤Æ¤¤¤ë¿Í¤·¤«Æɤá¤Þ¤»¤ó¡£¤´¤á¤ó¤Ê¤µ¤¤¡£ ¡¡³«È¯¼Ô¤Ç¤¢¤ë Nelson »á¤è¤êµöÂú¤òĺ¤¤Þ¤·¤¿¡£jp1.chkrootkit.org ¤¬³ä¤êÅö¤ÆͽÄê¤Ç¤¹¡£ ¡¡¤³¤Î¥×¥í¥¸¥§¥¯¥È¤ÎÌÜŪ¤Ï¸ø¼°¥µ¥¤¥È¤ÎÃé¼Â¤Ê¤ëÆüËܸ첽¤Ë¤¢¤ê¤Þ¤¹¡£&br; ¡¡ºÇ½ªÅª¤Ë¤Ï chkrootkit ¤òÆüËܸì(UTF-8)Âбþ¤µ¤»¤ë¥Ñ¥Ã¥Á¤ò½Ð¤·¤¿¤¤¤Ç¤¹¡Ê´õ˾Ū´Ñ¬¡Ë&br; ¡¡»²²Ã¼Ô¡õ¶¨Îϼԡõ¥Æ¥¹¥¿¡¼Ê罸Ãæ¤Ç¤¹¡£ ¡¡µöÂúʸ¾Ï°Ê²¼È´¿è¡Ê±Ñ¸ì¤Ç¤¹¡¢¡¢¤´¤á¤ó¤Ê¤µ¤¤¡Ë¡£ > My proposal is simple. That is in editing of pure > www.chkrootkit.org. In other words, I translate English of HTML > of the site into Japanese. A display style there doesn't take > its place. > > It is inferior to ability in reading and writing because the > Japanese most part doesn't make English a main language in being > disappointing. Even if you think "Is though it such easy English?" > > It is rather another problem that I am anxious. The person who > can't discuss English in the Japanese technician of linux is the > fact to exist in many, too. (This comes off the main subject. I > think that it can have it know as your reference.) > > In addition, I will sometimes appear at the site if the one for > the Japanese has renewal information. I want to provide a > localization patch if it is possible, too. Don't you care though you think that I will proceed with the work with the above contents? ¡¡³«È¯¼Ô¤Î Nelson »á¤«¤é¤Ï "No problem. You're welcome. Please, go ahead."¡ÊÌäÂê¤Ê¤¤¤è¡¢´¿·Þ¤·¤Þ¤¹¡£¤É¤¦¤¾¡ª¡Ë¤È²÷Âú¤òĺ¤¤Þ¤·¤¿¡£ * chkrootkit ¤ò»È¤Ã¤¿ÉÔÀµ¿¯Æþ¸¡ÃÎ [#q2f0d073] ** chkrootkit ¤Ã¤Æ²¿¡© [#v4ca30f1] ¡¡ÉÔÀµ¿¯Æþ¸¡ÃΡ¢¤È¤¤¤¦¤È¤³¤í¤Î chkrootkit (¥Á¥§¥Ã¥¯¡¦¥ë¡¼¥È¥¥Ã¥È)¤¬»ä¤Î¼þ¤ê¤Ç¤Ï°ìÈÖÍ̾½ê¤ß¤¿¤¤¤Ç¤¹¡£rootkit (¥ë¡¼¥È¤¤Ã¤È) ¤È¤¤¤¦¤Î¤ÏÉÔÀµ¥¢¥¯¥»¥¹»þ¤ËÉÔÀµ¿¯Æþ¼Ô¤¬¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤ò²þã⤷¤¿¤êÀßÄê¤òÊѹ¹¤·¤¿¤ê¡¢¥Ð¥Ã¥¯¥É¥¢¡ÊÉÔÀµ¥¢¥¯¥»¥¹¤Î¤¿¤á¤Î΢¸ý¡¢¤¿¤È¤¨¤Ðɸ½à¤Ç¤Ï¤Ê¤¤Ê̥ݡ¼¥È¤Çµ¯Æ°¤µ¤»¤ësshd¥µ¡¼¥Ð¤Ç¤¹¤È¤«¡Ë¤ÎÉßÀß¡¢¥×¥í¥»¥¹¤Î±£Êáʾ¤Î¥µ¡¼¥Ð·²¤ò¥Ý¡¼¥È¥¹¥¥ã¥ó¤·¤¿¤ê¡¢Sniffer ¤È¤¤¤¦¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Î¥Ñ¥±¥Ã¥È¤ò²òÀϤ¹¤ë¤³¤È¤Ç¡¢¥æ¡¼¥¶Ì¾¤ä¥Ñ¥¹¥ï¡¼¥É¤Î¾ðÊó¤ò¼èÆÀ¤¹¤ë¤è¤¦¤Ê¥×¥í¥°¥é¥à¤¬°ìÈÌŪ¤Ë±£¤µ¤ì¤ä¤¹¤¤¤Ç¤¹¡Ë¤ò¹Ô¤¦¤è¤¦¤ÊÉÔÀµ¿¯Æþ¥Ä¡¼¥ë·²¤È¸Æ¤Ð¤ì¤ë¤â¤Î¤Ç¤¹¡£ ¡¡chkrootkit ¤Ï¡¢¤³¤ì¤é rootkit ¤ò¿×®¤Ë¸¡ºº¤·¤Æ¡¢¥·¥¹¥Æ¥à¤Ë°±Æ¶Á¤¬¤¢¤ë²ÄǽÀ¤¬¤¢¤ì¤Ð·Ù¹ð¤ò¤·¤Æ¤¯¤ì¤ë¥Ä¡¼¥ë¤Ç¤¹¡£¥Ä¡¼¥ë¼«ÂΤˤϥ·¥¹¥Æ¥à²þãâ»þ¤Ë¥Õ¥¡¥¤¥ë¤ò½¤Éü¤¹¤ë¤è¤¦¤Êµ¡Ç½¤Ï¤¢¤ê¤Þ¤»¤ó¡£¤¢¤¯¤Þ¤Ç¸¡½Ð¤¬ÌÜŪ¤Ç¤¹¡£¥·¥¹¥Æ¥à¤¬¸¶°øÉÔÌÀ¤Î¹âÉé²Ù¤Ë´Ù¤Ã¤¿¤ê¡¢ËÜÍè»È¤¨¤ë¤Ï¤º¤Î ps ¤ä ls ¤È¤¤¤Ã¤¿°ìÈÌŪ¤Ê¥³¥Þ¥ó¥É¤¬µÞ¤Ë»È¤¨¤Ê¤¯¤Ê¤Ã¤¿¤ê¤·¤¿¤é¡¢¤È¤ê¤¢¤¨¤ºÉÔÀµ¥¢¥¯¥»¥¹¤òµ¿¤Ã¤Æ¤ß¤ë¤Î¤â£±¤Ä¤ÎÊýË¡¤Ç¤¹¡£ ¡¡ÉÔÀµ¥¢¥¯¥»¥¹¤Ê¤ó¤Æ´Ø·¸¤Ê¤¤¤è¡©¤È¤Ï»×¤Ã¤Æ¤¤¤Þ¤»¤ó¤«¡£¤¿¤È¤¨ iptables ¤Ç¥¬¥Á¥¬¥Á¤Ë SSH ¤ä FTP ¤È¤¤¤Ã¤¿°ìÈÌŪ¤Ê¥Ý¡¼¥È¤ò¼é¤Ã¤Æ¤¤¤Æ¤â¡¢¸ø³«¤µ¤ì¤Æ¤¤¤ë°ìÈÌŪ¤Ê¥µ¡¼¥Ó¥¹¤ËÀȼåÀ¤¬¸«¤Ä¤«¤Ã¤¿¾ì¹ç¡¢¤½¤³¤«¤éÉÔÀµ¤Ê¥¢¥¯¥»¥¹¤ò¼õ¤±¤ë¤³¤È¤¬¤¢¤êÆÀ¤ë¤Î¤Ç¤¹¡£Í̾¤Ê¤È¤³¤í¤Ç¤Ï¿ôǯÁ°¤Ë BIND ¤ÎÀȼåÀ¤òÍøÍѤ·¤¿ ri0n ¤¢¤ë¤¤¤Ï¥é¡¼¥á¥ó¤È¸Æ¤Ð¤ì¤ë¥ï¡¼¥à¡¢¤½¤·¤Æ¡¢OpenSSL ¤ÎÀȼåÀ¤òÍøÍѤ·¤¿ÉÔÀµ¥¢¥¯¥»¥¹¤¬¤¢¤²¤é¤ì¤ë¤Ç¤·¤ç¤¦¡£ ¡¡¾Ü¤·¤¤·Ð°Þ¤ò¤Þ¤È¤á¤Þ¤¹¤È¡¢BIND ¤Ï DNS ¥µ¡¼¥Ó¥¹¤È¤·¤Æ°ìÈÌŪ¤Ê DNS ¥µ¡¼¥Ð¤Ç¤¢¤ì¤Ð¥Ý¡¼¥È 53 ¤ò¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£BIND 8 ¤ÎÀȼåÀ¤¬È¯¸«¤µ¤ì¤Æ¤Þ¤â¤Ê¤¯¡¢¤³¤ÎÀȼåÀ¤òÍøÍѤ·¤Æ¼¡¡¹¤È¥µ¡¼¥Ð¤ËÉÔÀµ¥¢¥¯¥»¥¹¡¦Áý¿£¤ò·«¤êÊÖ¤¹ ri0n ¤È¤¤¤¦¥ï¡¼¥à¤¬½Ð²ó¤Ã¤¿¤³¤È¤¬¤¢¤ê¤Þ¤¹¡£named ¤ÏÅö»þ root ¥æ¡¼¥¶¸¢¸Â¤Ç¼Â¹Ô¤¹¤ë¤³¤È¤¬¤¢¤ê¤Þ¤·¤¿¤Î¤Ç¡Êº£Æü¤Ç¤Ï named ¤È¤¤¤¦ÀìÍѥ桼¥¶¤¬Æ°ºî¤Ë¤¢¤¿¤Ã¤Æ¤¤¤ë¤È»×¤¤¤Þ¤¹¤¬¡Ë¡¢¥·¥¹¥Æ¥à¤ËÉÔÀµ¤Ê¥Õ¥¡¥¤¥ë¤òÉßÀߤµ¤ì¤ë¤È¤¤¤¦¤³¤È¤¬¤¢¤ê¤Þ¤·¤¿¡£ ¡¡OpenSSL ¤ÎÀȼåÀ¤Ç¤Ï OpenSSL ¤Î¥é¥¤¥Ö¥é¥ê¤òÍѤ¤¤¿ mod_ssl¡¢¤Ä¤Þ¤ê https ÄÌ¿®¤Ë¤Ä¤«¤¦¥Ý¡¼¥È 443 ÈÖ¤ËÂФ¹¤ë¹¶·â¤¬¹Ô¤ï¤ì¤¿¤³¤È¤¬¤¢¤ê¤Þ¤¹((¥í¥°¤ò¸«¤ë¤È¡¢º£Æü¤Ç¤â¹¶·â¤È¤ª¤Ü¤·¤¥¢¥¯¥»¥¹¤Ï¸«¼õ¤±¤é¤ì¤Þ¤¹¤¬¡Ä¡Ä))¡£¤¢¤ëÊýË¡¤ò»È¤Ã¤Æ¥Ý¡¼¥È 443 ¤ò¤¿¤¿¤¯¤È¡¢apache ¤Î¼Â¹Ô¥æ¡¼¥¶¸¢¸Â¤Ç¥µ¡¼¥Ð¤Ø¤Î¥í¥°¥¤¥ó¤òµö¤·¤Æ¤·¤Þ¤¦¤³¤È¤¬¤¢¤ê¤Þ¤¹¡£°ìÅÙ¥í¥°¥¤¥ó¤òµö¤¹¤È¡¢¿¯Æþ¼Ô¤Ï exploit(¥¨¥¯¥¹¥×¥í¥¤¥É)¤È¸Æ¤Ð¤ì¤ë root ¸¢¸Â¤òÃ¥¼è¤¹¤ë¤¿¤á¤Î¥×¥í¥°¥é¥à¤òÍѤ¤¤Æ root ¸¢¸Â¤òÃ¥¼è¤·¡¢¥·¥¹¥Æ¥à¤ò²þã⤷¤¿¤ê¡¢MP3 ÃÖ¤¾ì¤Ë¤·¤ÆÍ·¤ó¤À¤ê¡¢Â¾¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤ò¹¶·â¤·¤¿¤ê¡¢¤¢¤È¤Ï¹¥¤ÊüÂê¤ä¤êÊüÂê¡¢¤È¤¤¤¦»öÎã¤â¤¢¤ê¤Þ¤·¤¿¡£ ¡¡¤³¤Î¤è¤¦¤Ë¡¢¤¿¤È¤¨ iptables ¤Ç¸Ç¤á¤Æ¤¤¤è¤¦¤¬ÀìÍÑ¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤Ë¤è¤Ã¤Æ¶¯¸Ç¤Ê¥Í¥Ã¥È¥ï¡¼¥¯¤ò¹½ÃÛ¤·¤Æ¤¤¤Æ¤â¡¢¾ï¤Ë¸ø³«¤µ¤ì¤Æ¤¤¤ë¥Ý¡¼¥È¤Ë±÷¤¤¤Æ¤ÏÉÔÀµ¥¢¥¯¥»¥¹¤ä¹¶·â¤ò¼õ¤±¤ë¤ª¤½¤ì¤¬¤¢¤ê¤Þ¤¹¡£ ¡¡µÞ¤Ë¥Í¥Ã¥È¥ï¡¼¥¯¤¬¥À¥¦¥ó¤·¤¿¤ê¡¢µÞ¤Ë¥³¥Þ¥ó¥É¤¬»È¤¨¤Ê¤¯¤Ê¤Ã¤Æ½é¤á¤Æ¹²¤Æ¤Æ¤â¡¢¤â¤¦¥Í¥Ã¥È¥ï¡¼¥¯¤«¤éÀÚ¤êÎ¥¤¹¤·¤«¼êÃʤϻĤµ¤ì¤Æ¤¤¤Þ¤»¤ó¡£°ìÈÖ¥¿¥Á¤¬°¤¤¤Î¤Ï¥µ¡¼¥ÐÆâ¤ËÀøÉú¤¹¤ë¥¿¥¤¥×¤Î¿¯Æþ¼Ô¤Ç¤¹¡£°ì¸«¸«¤«¤±¾å¤Ï¤Õ¤Ä¤¦¤Î¥·¥¹¥Æ¥à¤Ê¤Î¤Ç¤¹¤¬¡¢¥«¡¼¥Í¥ë¤ËÆüì¤Ê¥â¥¸¥å¡¼¥ë¤òÁȤ߹þ¤Þ¤»¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¿¯Æþ¼Ô¤Î¼Â¹Ô¤¹¤ë¥×¥í¥»¥¹¤ä¥Í¥Ã¥È¥ï¡¼¥¯¾ðÊó¤ò±£¤¹¤è¤¦¤Ê¤³¤È¤¬¤Ç¤¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¡¢¤â¤·¥Í¥Ã¥È¥ï¡¼¥¯¾ðÊó¤ò¥¥ã¥×¥Á¥ã¡¦²òÀϤ¹¤ë¥×¥í¥°¥é¥à¤¬»Å¹þ¤Þ¤ì¤Æ¤¤¤¿¤é¡¢¤¤¤Ä¤Î¤Þ¤Ë¤«¥æ¡¼¥¶Ì¾¤È¥Ñ¥¹¥ï¡¼¥É¤ä¾ðÊó¤ä¡¢³°Éô¤ËÌç³°ÉԽФʥǡ¼¥¿¥Ù¡¼¥¹¤Î½ÅÍ×¾ðÊó¤¬Åð¤Þ¤ì¤ë²ÄǽÀ¤À¤Ã¤Æ¤¢¤ë¤Î¤Ç¤¹¡£ ¡¡¤Ç¤¹¤«¤é¡¢Êݸ±¤È¤¤¤¦°ÕÌ£¤Ç¤â¡¢ÉáÃʤ«¤éÉÔÀµ¿¯Æþ¥Ä¡¼¥ë·²¤ò¼Â¹Ô¤¹¤ë¥Æ¥¹¥È¤ò¤·¤Æ¤ß¤ë¤³¤È¤ò¤ª¤¹¤¹¤á¤·¤Þ¤¹¡£¾ÃËÉ¡¦²ÐºÒ·±Îý¤Î¤è¤¦¤Ê¤â¤Î¤À¤È¹Í¤¨¤Æ¤¯¤À¤µ¤¤¡£¤À¤ì¤âËÜÅö¤Ë²Ð»ö¤¬µ¯¤³¤ë¤Ê¤ó¤Æ»×¤Ã¤Æ¤¤¤Þ¤»¤ó¡¢¤¬¡¢µ¯¤¤ë¤È¤¤Ë¤Ïµ¯¤¤ë¤â¤Î¤Ç¤¹¡£ÉÔÀµ¥¢¥¯¥»¥¹¤È»×¤ï¤ì¤ëÃû¸õ¤¬¸«¤¨¤Æ¤â¡¢°ì¸«¥·¥¹¥Æ¥à¤ÏÊ¿ÀŤòÊݤ俤ޤޤ«¤â¤·¤ì¤Þ¤»¤ó¡£¤½¤ì¤³¤½¡¢¿¯Æþ¼Ô¤Î»×¤¦¤Ä¤Ü¡£¤³¤³¤Ç¾Ò²ð¤¹¤ë chkrootkit ¤ò»È¤Ã¤Æ¡¢Äê´üŪ¤Ë¥·¥¹¥Æ¥à¤Ë°Û¾ï¤¬È¯À¸¤·¤Æ¤¤¤Ê¤¤¤«³Îǧ¤ò¤¹¤ë¤è¤¦¤Ê½¬´·¤Å¤±¤ò¤·¤Æ¤ª¤¯¤³¤È¤ò¶¯¤¯¤ª¤¹¤¹¤á¤·¤Þ¤¹¡£µ¤¤¬¤Ä¤¤¤Æ¤«¤é¤Ç¤ÏÃÙ¤¤¤Î¤Ç¤¹¡£ ¡¡chkrootkit ¤ÏȽÌÀ¤·¤Æ¤¤¤ë((¸ºß¤¬ÃΤé¤ì¤Æ¤¤¤ëÍ̾¤Ê¤â¤Î)) rootkit ¤ä¥ï¡¼¥à¡¢LKM(Lodable Kernel Module) ¤È¤¤¤Ã¤¿¥·¥¹¥Æ¥àÁȹþ·¿¤ÎÉÔÀµ¥Ä¡¼¥ë·²¤ò¸¡ÃΤ¹¤ë¤¿¤á¤Î¥½¥Õ¥È¤Ç¤¹¡£º£Æü¸½ºß(2006-10) version 0.47 ¤¬ºÇ¿·¤Î¤â¤Î¤Ç¤¹¡£ ¡ÊƱÍÍ¤Ê rootkit ¸¡½Ð¥Ä¡¼¥ë¤È¤·¤Æ [[Rootkit Hunter:http://pocketstudio.jp/linux/?Rootkit%20Hunter]] ¤È¤¤¤¦¥½¥Õ¥È¤â¾Ò²ð¤·¤Æ¤ª¤¤Þ¤¹¡£¤³¤Á¤é¤Ï chkrootkit °Ê¾å¤ËºÙ¤«¤Ê¥ì¥Ý¡¼¥È¤ò½Ð¤·¤Æ¤¯¤ì¤Þ¤¹¡Ë ** ¤Ç¡¢chkrootkit ¤Î¾ðÊó¤Ï¤É¤³¤«¤é¡© [#u47b1e2d] ¡¡chkrootkit ¤Î¸ø¼°¥Ú¡¼¥¸¤Ï¤³¤Á¤é¤Ç¤¹ ¡¡http://www.chkrootkit.org/ - Ãøºî¸¢ COPYRIGHT 1.2 (Pangeia Informatica) 2/21/97 Copyright 1996-2003 - Pangeia Informatica, All rights reserved. ** Âбþ OS [#f08791bf] >Linux 2.0.x, 2.2.x, 2.4.x and 2.6.x, >FreeBSD 2.2.x, 3.x, 4.x and 5.x, OpenBSD 2.x and 3.x., NetBSD 1.6.x, >Solaris 2.5.1, 2.6, 8.0 and 9.0, HP-UX 11, Tru64 and BSDI. >(README ¤è¤ê) ** chkrootkit ¤Î¥¤¥ó¥¹¥È¡¼¥ë [#te964bd5] ¡¡¥¤¥ó¥¹¥È¡¼¥ëÊýË¡¤Ï»ê¤Ã¤Æ´Êñ¤Ç¤¹¡£ $ wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz ¡¡¸ø³«¤µ¤ì¤Æ¤¤¤ë [[MD5 ¥Á¥§¥Ã¥¯¥µ¥à:ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.md5]]¤òÈæ³Ó¤·¤Æ¡¢Àµµ¬¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë¤³¤È¤òÇ°¤Î¤¿¤á¤Ë³Îǧ¤·¤Æ¤ª¤¤Þ¤¹¡£ $ md5sum chkrootkit.tar.gz 4c6455d202cef35395a673386e4bf01a8 chkrootkit.tar.gz ¡¡¼¡¤Ë¥Õ¥¡¥¤¥ë¤òŸ³«¤·¤Æ¥Ç¥£¥ì¥¯¥È¥ê¤ò°ÜÆ°¤·¤Þ¤¹¡£ $ tar xfz chkrootkit.tar.gz $ cd chkrootkit-0.47 ¡¡¼¡¤Ë make ¤·¤Þ¤¹¡£ $ make sense ¡¡¤³¤ì¤Ç¥Ð¥¤¥Ê¥ê¤ÎºîÀ®¤Ï½ª¤ï¤ê¤Þ¤·¤¿¡£¼Â¹Ô¤Ï¤½¤Î¥Ç¥£¥ì¥¯¥È¥êÆâ¤Ç¹Ô¤¤¤Þ¤¹¡£chkrootkit ¤ÏËÜÂΤǤ¹¤¬¡¢¤½¤Î¤Û¤«¤Î¥×¥í¥°¥é¥à¤ÈϢư¤·¤ÆÆ°ºî¤¹¤ëɬÍפ¬¤¢¤ë¤¿¤á¤Ç¤¹¡£°ì±þ chkrootkit ñÂΤǤâÆ°ºî¤Ï¹Ô¤ï¤ì¤Þ¤¹¡£ ** chkrootkit ¤Î¼Â¹Ô [#l93b6bdd] ¡¡¥½¡¼¥¹¤ò make ¤·¤¿¥Ç¥£¥ì¥¯¥È¥ê¤Ç chkrootkit ¤ò¼Â¹Ô¤·¤Þ¤¹¡£ ¡¡Ãí°ÕÅÀ¤È¤·¤Æ¤Ï¼Â¹Ô»þ¤Ë¤Ï root ¥æ¡¼¥¶¸¢¸Â¤¬É¬ÍפȤʤê¤Þ¤¹¡£°ìÈ̥桼¥¶¤Ç¤Ï¤¹¤Ù¤Æ¤Î¸¡ºº¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤¤Þ¤»¤ó¡£ # ./chkrootkit ¡¡¤Á¤Ê¤ß¤Ë°Ê²¼¤¬ Fedora Core 4 ¤Ç¼Â¹Ô¤·¤Æ¤ß¤¿·ë²Ì¤Ç¤¹¡£ ROOTDIR is `/' Checking `amd'... not found Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected Checking `cron'... not infected Checking `date'... not infected Checking `du'... not infected Checking `dirname'... not infected Checking `echo'... not infected Checking `egrep'... not infected Checking `env'... not infected Checking `find'... not infected Checking `fingerd'... not found Checking `gpm'... not infected Checking `grep'... not infected Checking `hdparm'... not infected Checking `su'... not infected Checking `ifconfig'... not infected Checking `inetd'... not tested Checking `inetdconf'... not found Checking `identd'... not found Checking `init'... not infected Checking `killall'... not infected Checking `ldsopreload'... not infected Checking `login'... not infected Checking `ls'... not infected Checking `lsof'... not infected Checking `mail'... not infected Checking `mingetty'... not infected Checking `netstat'... not infected Checking `named'... not infected Checking `passwd'... not infected Checking `pidof'... not infected Checking `pop2'... not found Checking `pop3'... not found Checking `ps'... not infected Checking `pstree'... not infected Checking `rpcinfo'... not infected Checking `rlogind'... not found Checking `rshd'... not found Checking `slogin'... not infected Checking `sendmail'... not infected Checking `sshd'... not infected Checking `syslogd'... not infected Checking `tar'... not infected Checking `tcpd'... not infected Checking `tcpdump'... not infected Checking `top'... not infected Checking `telnetd'... not infected Checking `timed'... not found Checking `traceroute'... not infected Checking `vdir'... not infected Checking `w'... not infected Checking `write'... not infected Checking `aliens'... no suspect files Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found Searching for Lion Worm default files and dirs... nothing found Searching for RSHA's default files and dir... nothing found Searching for RH-Sharpe's default files... nothing found Searching for Ambient's rootkit (ark) default files and dirs... nothing found Searching for suspicious files and dirs, it may take a while... /usr/lib/perl5/5.8.6/i386-linux-thread-multi/.packlist /usr/lib/perl5/vendor_perl/5.8.6/ i386-linux-thread-multi/auto/NKF/.packlist Searching for LPD Worm files and dirs... nothing found Searching for Ramen Worm files and dirs... nothing found Searching for Maniac files and dirs... nothing found Searching for RK17 files and dirs... nothing found Searching for Ducoci rootkit... nothing found Searching for Adore Worm... nothing found Searching for ShitC Worm... nothing found Searching for Omega Worm... nothing found Searching for Sadmind/IIS Worm... nothing found Searching for MonKit... nothing found Searching for Showtee... nothing found Searching for OpticKit... nothing founde Searching for T.R.K... nothing found Searching for Mithra... nothing found Searching for LOC rootkit... nothing found Searching for Romanian rootkit... nothing found Searching for HKRK rootkit... nothing found Searching for Suckit rootkit... nothing found Searching for Volc rootkit... nothing found Searching for Gold2 rootkit... nothing found Searching for TC2 Worm default files and dirs... nothing found Searching for Anonoying rootkit default files and dirs... nothing found Searching for ZK rootkit default files and dirs... nothing found Searching for ShKit rootkit default files and dirs... nothing found Searching for AjaKit rootkit default files and dirs... nothing found Searching for zaRwT rootkit default files and dirs... nothing found Searching for Madalin rootkit default files... nothing found Searching for Fu rootkit default files... nothing found Searching for ESRK rootkit default files... nothing found Searching for anomalies in shell history files... nothing found Checking `asp'... not infected Checking `bindshell'... INFECTED (PORTS: 465) Checking `lkm'... chkproc: nothing detected Checking `rexedcs'... not found Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets eth1: not promisc and no PF_PACKET sockets Checking `w55808'... not infected Checking `wted'... chkwtmp: nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... chklastlog: nothing deleted Checking `chkutmp'... chkutmp: nothing deleted ¡¡ÆâÌõ¤òºÙ¤«¤¯¸«¤Æ¤¤¤¯¤È ROOTDIR is `/' ¡¡£±¹ÔÌܤΠROOTDIR ¤Ï / ÇÛ²¼¤¹¤Ù¤Æ¤ò¸¡º÷ÂоݤȤ·¤Æ¤¤¤ë¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£ Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected ¡¡£²¹ÔÌܰʹߤΠChecking ¤Ï¼ç¤Ê¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤Ç¤¹¡£"not found"¤È¤¤¤¦¤Î¤Ï¥Õ¥¡¥¤¥ë¤¬¤¢¤ê¤Þ¤»¤ó¤·¡¢"not infected" ¤È¤Ç¤Æ¤¤¤ì¤Ð²þã⤵¤ì¤Æ¤¤¤ë²ÄǽÀ¤Ï¤Ê¤¤¤È¤¤¤¨¤Þ¤¹¡£ ¡¡¤Á¤Ê¤ß¤Ë²þã⤵¤ì¤Æ¤¤¤ë¤È¡¢¤½¤Î¥Õ¥¡¥¤¥ë¤ËÂФ·¤Æ¤Ï "INFECTED" ¤Èɽ¼¨¤µ¤ì¤Þ¤¹¡£ Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found ¡¡°ú¤Â³¤ Searching ¤È³¤¤¤Æ¤¤¤ë¤Î¤Ï¥ï¡¼¥à¤ä¥ë¡¼¥È¥¥Ã¥È¤¬ÁȤ߹þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¤«¤Î¸¡½Ð¤Ç¤¹¡£"nothing found" ¤È¤Ç¤Æ¤¤¤ë¤Î¤¬Åö¤¿¤êÁ°¤Ç¤¹¡£FOUND ¤È¤Ê¤Ã¤¿¤é¡¢²¿¤«»Å¹þ¤Þ¤ì¤Æ¤¤¤ë²ÄǽÀ¤¬Èó¾ï¤Ë¹â¤¤¤Ç¤¹¡£ Searching for suspicious files and dirs, it may take a while... ¡¡¤³¤³¤Ç¤Ï¥Õ¥¡¥¤¥ë̾¤ÎÀèƬ¤Ë . ¤¬¤Ä¤¤¤Æ¤¤¤Æ¡¢²ø¤·¤¤¤È»×¤ï¤ì¤ë¥Õ¥¡¥¤¥ë¤Î°ìÍ÷¤òɽ¼¨¤·¤Þ¤¹¡£¥·¥¹¥Æ¥à¤¬ÍѤ¤¤ë¤â¤Î¤Ç¤¢¤ì¤ÐÌäÂê¤Ï¤¢¤ê¤Þ¤»¤ó¡£¸«´·¤ì¤Ê¤¤¥Õ¥¡¥¤¥ë¤¬±÷¤«¤ì¤Æ¤¤¤¿¤éÍ×Ãí°Õ¤Ç¤¹¡£ Checking `asp'... not infected Checking `bindshell'... INFECTED (PORTS: 465) ¡¡¤ª¤Ã¤È¡¢¤³¤³¤Ç bindshell ¤¬ INFECTED ¤È¤Ç¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡£¾Ü¤·¤¤¾ðÊó¤Ï¤ï¤«¤é¤Ê¤¤¤Î¤Ç¤¹¤¬¡¢°ìÀÎÁ°¤Ë bindshell ¤È¤¤¤¦¥Ä¡¼¥ë¤ÎÃæ¤Ë¥Ý¡¼¥È 465 ¤ò»È¤¦¤è¤¦¤Ê¤â¤Î¤¬¤¢¤Ã¤¿¤ß¤¿¤¤¤Ç¤¹¤Í¡£¤Þ¡¢Íî¤ÁÃ夤¤Æ¥Ý¡¼¥È 465 ¤ò³Îǧ¤·¤Þ¤·¤ç¤¦¡£ # /usr/sbin/lsof -i tcp:465 COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME sendmail 1996 root 6u IPv4 5783 TCP *:smtps (LISTEN) ¡¡¥Ý¡¼¥È¤Î³Îǧ¤Ï lsof ¥³¥Þ¥ó¥É¤Ç¤¹¡£¤³¤Á¤é¤Ï¤ß¤Æ¤ÎÄ̤ê sendmail ¤¬ Submission Port(¥á¡¼¥ëÁ÷¿®ÍѤΥµ¥Ö¥ß¥Ã¥·¥ç¥ó¡¦¥Ý¡¼¥È)¤È¤·¤Æ smtps ÄÌ¿®ÍѤËÍѤ¤¤Æ¤¤¤ë¤â¤Î¤Ç¤¹¤«¤é¡¢Á´¤¯ÌäÂꤢ¤ê¤Þ¤»¤ó¡£ Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets eth1: not promisc and no PF_PACKET sockets Checking `w55808'... not infected Checking `wted'... chkwtmp: nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... chklastlog: nothing deleted Checking `chkutmp'... chkutmp: nothing deleted ¡¡ºÇ¸å¤ÎÊý¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¤¬¥¹¥¥ã¥ó²Äǽ¤Ê¾õÂ֤ǤϤʤ¤¤«(PROMICUS ¥â¡¼¥É¤«¤É¤¦¤«¡Ë¤Î³Îǧ¤ä utmp ¤È¤¤¤Ã¤¿¥í¥°¥¤¥ó¾ðÊó¤ä¥í¥°¤Î²þã⤬¤ß¤é¤ì¤Ê¤¤¤«¥Á¥§¥Ã¥¯¤·¤Æ¤¤¤Þ¤¹¡£ ¡¡¤Á¤Ê¤ß¤Ë¡¢»ä¤Ï Vine 2.1.5(·ë¹½¸Å¤¤¤Ç¤¹¤¬¸½Ìò¥µ¡¼¥Ð¤Ç¤¹) ´Ä¶¤Ç³Îǧ¤·¤Æ¤¤¤Þ¤¹¤¬¡¢ps ¥³¥Þ¥ó¥É¤Î°ú¿ô¤«²¿¤«¤Î¥Ð¥°¤Ç¼¡¤Î¤è¤¦¤Ê·Ù¹ð¤¬¤Ç¤Æ¤·¤Þ¤¦¤è¤¦¤Ç¤¹¡£ OooPS! chkproc: Warning: Possible LKM Trojan installed ¡¡¤È¤ê¤¢¤¨¤º¼Â¹Ô¤·¤Æ¤ß¤Æ¡¢¥·¥¹¥Æ¥à¤Ë°Û¾ï¤¬¸«¼õ¤±¤é¤ì¤Ê¤¤¤è¤¦¤Ê¤é°Â¿´¤Ç¤¹¡£¤â¤· INFECTED ¤ä ¡Á installed ¤È¤Ç¤¿¤é¡¢¤¢¤ï¤Æ¤º¤Ë¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤ÎÆüÉÕ¤ä md5sum ¥³¥Þ¥ó¥É¤Ë¤è¤ë¥Á¥§¥Ã¥¯¥µ¥à¤òÈæ³Ó¤·¤¿¤ê¤·¡¢ÉÔÀµ¥¢¥¯¥»¥¹¤¬Ç§¤á¤é¤ì¤ë¤Ê¤é®¤ä¤«¤Ë¥Í¥Ã¥È¥ï¡¼¥¯¤«¤éÀÚ¤êÎ¥¤·¤ÆÂн褹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£ ** chkrootkit ¤Î¼Â¹Ô¥ª¥×¥·¥ç¥ó [#ufd37b25] - "-h" ¥Ø¥ë¥×¤òɽ¼¨¤·¤Þ¤¹ # ./chkrootkit -h Usage: ./chkrootkit [options] [test ...] Options: -h show this help and exit -V show version information and exit -l show available tests and exit -d debug -q quiet mode -x expert mode -r dir use dir as the root directory -p dir1:dir2:dirN path for the external commands used by chkrootkit -n skip NFS mounted dirs - "-V" ¥Ð¡¼¥¸¥ç¥óÈÖ¹æ¤òɽ¼¨¤·¤Þ¤¹ # ./chkrootkit -V chkrootkit version 0.45 - "-l" chkktootkit ¤Î¸¡ººÂоݤȤʤë¥Õ¥¡¥¤¥ë°ìÍ÷¤òɽ¼¨¤·¤Þ¤¹¡£ # ./chkrootkit -l ./chkrootkit: tests: aliens asp bindshell lkm rexedcs sniffer w55808 wted scalper slapper z2 chkutmp amd basename biff chfn chsh cron date du dirname echo egrep env find fingerd gpm grep hdparm su ifconfig inetd inetdconf identd init killall ldsopreload login ls lsof mail mingetty netstat named passwd pidof pop2 pop3 ps pstree rpcinfo rlogind rshd slogin sendmail sshd syslogd tar tcpd tcpdump top telnetd timed traceroute vdir w write - "-q" ÀŤ«¤Ê¥â¡¼¥É¡£ÌäÂê¤È¤Ê¤Ã¤¿¹àÌܤ·¤«É½¼¨¤·¤Þ¤»¤ó¡£ # ./chkrootkit -q /usr/lib/perl5/5.8.6/i386-linux-thread-multi/.packlist /usr/lib/perl5/vendor_perl/5.8.6/i386-linux-thread-multi/auto/NKF/.packlist INFECTED (PORTS: 465) - "-x" ¥¨¥¥¹¥Ñ¡¼¥È¡Ê¾åµé¼Ô¸þ¤±¡Ë¥â¡¼¥É¤Ç¤¹¡£Èó¾ï¤ËËÄÂç¤Ê¸¡ººµÏ¿¤¬É½¼¨¤µ¤ì¤Þ¤¹¤Î¤Ç¡¢¼ÂÍÑŪ¤ÊÊýË¡¤È¤·¤Æ¤Ï°Ê²¼¤Î¤è¤¦¤Ë¥í¥°¤ò½Ð¤¹¤è¤¦¤Ë¤·¤¿¤Û¤¦¤¬Îɤ¤¤Ç¤¹¡£ # ./chkrootkit -x > check.log - "-r" ¸¡ººÂоݤȤʤë¥Ç¥£¥ì¥¯¥È¥ê¤Î»ØÄê¤Ç¤¹¡£¤¿¤È¤¨¤Ð¡¢ÉÔÀµ¥¢¥¯¥»¥¹¤Ë¤è¤ê¥·¥¹¥Æ¥à¤¬²þã⤵¤ì¤¿¥É¥é¥¤¥Ö¤¬ /mnt ¤Ë¥Þ¥¦¥ó¥È¤·¤Æ¤¢¤ë¾ì¹ç¡¢Ä´ºº¤Î¤¿¤á¤Ë»È¤¦¾ì¹ç¤â¤¢¤ê¤Þ¤¹¡Ê·Ù¹ð¡§ÉÔÀµ¤Ê¥Ä¡¼¥ë·²¤ÎÃæ¤Ë¤Ï chkrootkit ¥Õ¥¡¥¤¥ë¤ò¼Â¹Ô¤¹¤ë¤À¤±¤Ç¤â¸½¹Ô¤Î¥·¥¹¥Æ¥à¤òºÆ±øÀ÷¤¹¤ë¤è¤¦¤Ê¤â¤Î¤â¸ºß¤·¤Æ¤¤¤Þ¤¹¡£¤¯¤ì¤°¤ì¤â¡¢¼Â²ÔƯÃæ¤Î½ÅÍפʥµ¡¼¥Ð¤Ç¤Ï¸¡ºº¤ò¹Ô¤ï¤Ê¤¤¤Ç¤¯¤À¤µ¤¤¡£¡Ë¡£ # ./chkrootkit -r /mnt - "-p" ¤Ï¥ª¥ê¥¸¥Ê¥ë¤Î /bin ¤ä /usr/bin ÇÛ²¼¤Î¥Õ¥¡¥¤¥ë¤¬±øÀ÷¤µ¤ì¤Æ¤¤¤ë²ÄǽÀ¤¬¤¢¤ë¤È¤¡Ê chkrootkit ¼«¿È¤¬¤À¤Þ¤µ¤ì¤ë²ÄǽÀ¤¬¤¢¤ë¤È¤¡Ë¡¢¼Â¹Ô¥Õ¥¡¥¤¥ë¤Î¥Ç¥£¥ì¥¯¥È¥ê¤ò»ØÄꤹ¤ë»þ¤Î¥ª¥×¥·¥ç¥ó¤Ç¤¹¡£¤¿¤È¤¨¤Ð¡¢¥ª¥ê¥¸¥Ê¥ë¤Î¥Õ¥¡¥¤¥ë¤¬ /media/cdrom/bin ¤Ë¤¢¤ë»þ¤Ï¼¡¤Î¤è¤¦¤Ë¤·¤Þ¤¹¡£ # ./chkrootkit -p /media/cdrom/bin > ¡¡"-r"¤È"-p"¤Î°ã¤¤¤Ï¡¢"-r" ¤¬»ØÄꤷ¤¿¥Ç¥£¥ì¥¯¥È¥êÇÛ²¼¤ò°ì³ç¤·¤Æ¸¡ºº¤¹¤ë¤Î¤ËÂФ·¤Æ¡¢"-p" ¤Ç¤ÏÊ£¿ô¤Î¥Ç¥£¥ì¥¯¥È¥ê¤Î¤ß¥Á¥§¥Ã¥¯¤Ç¤¤Þ¤¹¡£¤¿¤È¤¨¤Ð /bin ¤È /sbin ¤Î¤ß¥Á¥§¥Ã¥¯¤ò¤µ¤»¤¿¤¤»þ¤Ï # ./chkrootkit -p /bin:/sbin ¡¡¤³¤Î¤è¤¦¤Ë¡¢¥Ñ¥¹¤ò ":" µ¹æ¤Ç¶èÀڤäƻØÄꤷ¤Þ¤¹¡£ < - "-n" NFS ¥Þ¥¦¥ó¥È¤µ¤ì¤¿¥Ç¥£¥ì¥¯¥È¥ê¤Ï¸¡ººÂоݳ°¤È¤·¤Þ¤¹¡£ ¡¡¤Þ¤¿¡¢ÆÃÄê¤Î¥×¥í¥»¥¹¤ä¥Õ¥¡¥¤¥ë¤Î¤ß¥Á¥§¥Ã¥¯¤µ¤»¤ë¤³¤È¤â¤Ç¤¤Þ¤¹¡£¤¿¤È¤¨¤Ð ps ¤È ls ¤À¤±¸¡ºº¤·¤¿¤¤¤È¤¤Ï¡¢¼¡¤Î¤è¤¦¤Ë°ú¿ô¤È¤·¤Æ¥Õ¥¡¥¤¥ë̾¤òµ½Ò¤·¤Þ¤¹¡£ # ./chkrootkit ps ls ROOTDIR is `/' Checking `ps'... not infected Checking `ls'... not infected ¡¡É½¼¨·ë²Ì¤Î¾ÜºÙ¤Ï[[README ÆüËܸìÌõ>chkrootkit README ÆüËܸìÌõ]]¤ò¡¢¤¢¤ë¤¤¤Ï[[FAQ ÆüËܸìÈÇ:http://pocketstudio.jp/linux/?chkrootkit%20FAQ%20%C6%FC%CB%DC%B8%EC%CC%F5]]¤ò¤´Í÷¤¯¤À¤µ¤¤¡£ ** chkrootkit ¤ÎÄê´üŪ¤Ê¼Â¹Ô¤Ç´Æ»ëÂÎÀ©¤òÀ°¤¨¤ë [#f13a0315] ¡¡¤»¤Ã¤«¤¯ÊØÍø¤Ê¥Ä¡¼¥ë¤Ê¤Î¤Ç¡¢ËèÆü¼«Æ°¼Â¹Ô¤µ¤»¤ë¤è¤¦¤ÊÂÎÀ©¤ò¤È¤È¤Î¤¨¤Þ¤·¤ç¤¦¡£cron ¤Ç¼Â¹Ô¤¹¤ë¤¿¤á¤Î¥¹¥¯¥ê¥×¥È¤òºî¤ê¤Þ¤¹¡£Ãí°ÕÅÀ¤È¤·¤Æ¤Ï chkrootkit ¤¬¥³¥ó¥Ñ¥¤¥ë¤µ¤ì¤¿´Ä¶¤ò¥«¥ì¥ó¥È¤Î¥Ç¥£¥ì¥¯¥È¥ê¤È¼Â¹Ô¤µ¤ì¤Ê¤¯¤Æ¤Ï¤¤¤±¤Ê¤¤¡¢¤È¤¤¤¦¤³¤È¤Ç¤¹¡£Í×¤Ï make ¤·¤¿¤È¤³¤í¤Ç¼Â¹Ô¡¢¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£ ¡¡¤³¤³¤Ç¤Ï /usr/local ¤Ë chkrootkit ¤Î¥³¥Ô¡¼¤òÃÖ¤¯¤è¤¦¤Ë¤¹¤ëÎã¤òµ½Ò¤·¤Þ¤¹¡£ ¡¡¤Ê¤ª¡¢¥½¡¼¥¹¤Ï /usr/local/chkrootkit-0.45 ¤ËŸ³«¤·¤¿¤â¤Î¤È¤·¤Þ¤¹¡£ ¡¡¤Þ¤º¡¢¥½¡¼¥¹¤Î¥·¥ó¥Ü¥ê¥Ã¥¯¥ê¥ó¥¯¤ò /usr/local/chkrootkit ¤Ë¤Ï¤ê¤Þ¤¹¡£¥ê¥ó¥¯¤·¤Æ¤ª¤¯¤Î¤Ï¡¢¾Íè chkrootkit ¤Î¥Ð¡¼¥¸¥ç¥ó¤¬ÊѤï¤ë¤³¤È¤¬¤¢¤Ã¤Æ¤â¡¢¥ê¥ó¥¯Àè¤òÊѹ¹¤¹¤ë¤À¤±¤Ç¾¤Î¥¹¥¯¥ê¥×¥È·²¤Ë¤Ï¼ê¤ò²Ã¤¨¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ç¤¹¡£ # ln -s /usr/local/src/chkrootkit-0.45 /usr/local/chkrootkit ¡¡¼¡¤Ë¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¤Þ¤¹¡£ # vi /usr/local/bin/chkrootkit.sh ¡¡¥Õ¥¡¥¤¥ë¤ÎÃæ¿È¤Ï¼¡¤Î¤è¤¦¤Ê¤â¤Î¤Ç¤¹¡£ #!/bin/sh cd /usr/local/chkrootkit ./chkrootkit | mail -s "[chkrootkit] HOSTNAME `date +%Y-%m-%d`" admin@example.jp ¡¡¤³¤Î¤è¤¦¤Ëµ½Ò¤·¤Æ¤¯¤À¤µ¤¤¡£HOSTNAME ¤Ï¼«Ê¬¤Î¥Û¥¹¥È̾¤ò¡¢ËöÈø¤Î admin@example.jp ¤Ï¼«Ê¬¡Ê¤¢¤ë¤¤¤Ï¥µ¡¼¥Ð´ÉÍý¼Ô¡Ë¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤òµ½Ò¤·¤Þ¤¹¡£ ¡¡°Û¾ï¤¬¤Ç¤¿¤È¤¤À¤±¥á¥Ã¥»¡¼¥¸¤ò½Ð¤µ¤»¤¿¤¤¤È¤¤Ï°Ê²¼¤Î¤è¤¦¤Ê¥ª¥×¥·¥ç¥ó¤ò¤Ä¤±¤ë¤Û¤¦¤¬Îɤ¤¤Ç¤·¤ç¤¦¡£ ./chkrootkit -q | mail -s "[chkrootkit] HOSTNAME `date +%Y-%m-%d`" admin@example.jp ¡¡¼¡¤Ë¼Â¹Ô¸¢¸Â¤òÍ¿¤¨¤Þ¤¹¡£ # chmod +x /usr/local/bin/chkrootkit.sh ¡¡¼¡¤Ï cron ¤Ø¤ÎÅÐÏ¿¤Ç¤¹¡£ # crontab -e ¤È¼Â¹Ô¤·¤Þ¤¹¡£vi ¤Î cron ÊÔ½¸²èÌ̤ˤʤê¤Þ¤¹¤Î¤Ç¡¢ 00 01 * * * /usr/local/bin/chkrootkit.sh > /dev/null 2>&1 ¡¡¤³¤Îµ½ÒÎã¤Ç¤Ï¡¢ËèÆü¸áÁ°£±»þ¤Ë chkrootkit.sh (Àè¤Û¤Éµ½Ò¤·¤¿¥¹¥¯¥ê¥×¥È) ¤ò¼Â¹Ô¤·¤Æ¡¢¥á¡¼¥ë¤ò admin@example.jp °¸¤ËÂê̾¡Ø[chkrootkit] HOSTNAME 2005-07-20¡Ù¡ÊºÇ´ü¤Ïǯ·îÆü¡Ë¤È¤·¤ÆÁ÷¿®¤µ¤»¤ë¤â¤Î¤Ç¤¹¡£Âê̾¤ÎÉôʬ¤ÏɬÍפ˱þ¤¸¤ÆŬÅö¤Ë½ñ¤´¹¤¨¤Æ»È¤Ã¤Æ¤ß¤Æ¤¯¤À¤µ¤¤¡£ ¡¡¤³¤ÎÃʳ¬¤Ç»î¤·¤Ë¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ¤ß¤ë¤È¡¢¥á¡¼¥ë¤¬ÆϤ¯¤Ï¤º¤Ç¤¹¡£ # /usr/local/bin/chkrootkit.sh ¡¡¤¢¤È¤Ï¡¢ËèÆü·Ú¤¯¥Á¥§¥Ã¥¯¤·¤Æ¡¢°Û¾ï¤¬¸«¼õ¤±¤é¤ì¤Ê¤¤¤«³Îǧ¤¹¤ë¤è¤¦¤Ë½¬´·¤Å¤±¤Æ¤ª¤¯¤³¤È¤¬Îɤ¤¤Ç¤·¤ç¤¦¡£ * chkrootkit ´ØÏ¢¤ÎÆüËܸì¥É¥¥å¥á¥ó¥È [#j14afb16] - [[README ÆüËܸìÌõ>chkrootkit README ÆüËܸìÌõ]] - [[FAQ ÆüËܸìÈÇ>chkrootkit FAQ ÆüËܸìÌõ]]
¥¿¥¤¥à¥¹¥¿¥ó¥×¤òÊѹ¹¤·¤Ê¤¤
[[LinuxSoft]] #contents ---- * News [#n601e887] - 2006ǯ10·î10Æü chkrootkit [[ºÇ¿·ÈÇ Version 0.47 ¤¬¥ê¥ê¡¼¥¹>http://www.chkrootkit.org/download/]]¤µ¤ì¤Þ¤·¤¿¡£chkrootkit ¤È¤·¤Æ¤Ïµ×¡¹¤Î¥ê¥ê¡¼¥¹¤Ë¤Ê¤ê¤Þ¤¹¡£ - 2006ǯ10·î11Æü chkrootkit [[¸ø¼°¥µ¥¤¥È>http://www.chkrootkit.org/]] ÆüËܸ첽¥×¥í¥¸¥§¥¯¥È¤òÀµ¼°¤Ë¥¹¥¿¡¼¥È¤·¤Þ¤¹¡£ * ¸ø¼°¥µ¥¤¥ÈÆüËܸ첽¥×¥í¥¸¥§¥¯¥È [#nd428bbb] ¡¡[[chkrootkit ¸ø¼°¥µ¥¤¥ÈÆüËܸ첽]]¥×¥í¥¸¥§¥¯¥È¤ò³«»Ï¤·¤Þ¤¹(2006ǯ10·î11Æü)¡£&br; - ¸ø¼°¥µ¥¤¥È http://www.chkrootkit.org/ ¡¡¾ÜºÙ¤Ê·Ð°Þ¤Ï¸ø¼°¥á¡¼¥ê¥ó¥°¥ê¥¹¥È users@chkrootkit.it.org ¤Î "Subject: [crt-users] May I make a translation site? (in Japanese)"¤Ë³¤¯¥¹¥ì¥Ã¥É¤ò¤´Í÷²¼¤µ¤¤¡£¥¢¡¼¥«¥¤¥Ö¤Î±ÜÍ÷¤Ï¤Ç¤¤Ê¤¤¤è¤¦¤Ç¤¹¡£¼õ¿®¤µ¤ì¤Æ¤¤¤ë¿Í¤·¤«Æɤá¤Þ¤»¤ó¡£¤´¤á¤ó¤Ê¤µ¤¤¡£ ¡¡³«È¯¼Ô¤Ç¤¢¤ë Nelson »á¤è¤êµöÂú¤òĺ¤¤Þ¤·¤¿¡£jp1.chkrootkit.org ¤¬³ä¤êÅö¤ÆͽÄê¤Ç¤¹¡£ ¡¡¤³¤Î¥×¥í¥¸¥§¥¯¥È¤ÎÌÜŪ¤Ï¸ø¼°¥µ¥¤¥È¤ÎÃé¼Â¤Ê¤ëÆüËܸ첽¤Ë¤¢¤ê¤Þ¤¹¡£&br; ¡¡ºÇ½ªÅª¤Ë¤Ï chkrootkit ¤òÆüËܸì(UTF-8)Âбþ¤µ¤»¤ë¥Ñ¥Ã¥Á¤ò½Ð¤·¤¿¤¤¤Ç¤¹¡Ê´õ˾Ū´Ñ¬¡Ë&br; ¡¡»²²Ã¼Ô¡õ¶¨Îϼԡõ¥Æ¥¹¥¿¡¼Ê罸Ãæ¤Ç¤¹¡£ ¡¡µöÂúʸ¾Ï°Ê²¼È´¿è¡Ê±Ñ¸ì¤Ç¤¹¡¢¡¢¤´¤á¤ó¤Ê¤µ¤¤¡Ë¡£ > My proposal is simple. That is in editing of pure > www.chkrootkit.org. In other words, I translate English of HTML > of the site into Japanese. A display style there doesn't take > its place. > > It is inferior to ability in reading and writing because the > Japanese most part doesn't make English a main language in being > disappointing. Even if you think "Is though it such easy English?" > > It is rather another problem that I am anxious. The person who > can't discuss English in the Japanese technician of linux is the > fact to exist in many, too. (This comes off the main subject. I > think that it can have it know as your reference.) > > In addition, I will sometimes appear at the site if the one for > the Japanese has renewal information. I want to provide a > localization patch if it is possible, too. Don't you care though you think that I will proceed with the work with the above contents? ¡¡³«È¯¼Ô¤Î Nelson »á¤«¤é¤Ï "No problem. You're welcome. Please, go ahead."¡ÊÌäÂê¤Ê¤¤¤è¡¢´¿·Þ¤·¤Þ¤¹¡£¤É¤¦¤¾¡ª¡Ë¤È²÷Âú¤òĺ¤¤Þ¤·¤¿¡£ * chkrootkit ¤ò»È¤Ã¤¿ÉÔÀµ¿¯Æþ¸¡ÃÎ [#q2f0d073] ** chkrootkit ¤Ã¤Æ²¿¡© [#v4ca30f1] ¡¡ÉÔÀµ¿¯Æþ¸¡ÃΡ¢¤È¤¤¤¦¤È¤³¤í¤Î chkrootkit (¥Á¥§¥Ã¥¯¡¦¥ë¡¼¥È¥¥Ã¥È)¤¬»ä¤Î¼þ¤ê¤Ç¤Ï°ìÈÖÍ̾½ê¤ß¤¿¤¤¤Ç¤¹¡£rootkit (¥ë¡¼¥È¤¤Ã¤È) ¤È¤¤¤¦¤Î¤ÏÉÔÀµ¥¢¥¯¥»¥¹»þ¤ËÉÔÀµ¿¯Æþ¼Ô¤¬¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤ò²þã⤷¤¿¤êÀßÄê¤òÊѹ¹¤·¤¿¤ê¡¢¥Ð¥Ã¥¯¥É¥¢¡ÊÉÔÀµ¥¢¥¯¥»¥¹¤Î¤¿¤á¤Î΢¸ý¡¢¤¿¤È¤¨¤Ðɸ½à¤Ç¤Ï¤Ê¤¤Ê̥ݡ¼¥È¤Çµ¯Æ°¤µ¤»¤ësshd¥µ¡¼¥Ð¤Ç¤¹¤È¤«¡Ë¤ÎÉßÀß¡¢¥×¥í¥»¥¹¤Î±£Êáʾ¤Î¥µ¡¼¥Ð·²¤ò¥Ý¡¼¥È¥¹¥¥ã¥ó¤·¤¿¤ê¡¢Sniffer ¤È¤¤¤¦¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Î¥Ñ¥±¥Ã¥È¤ò²òÀϤ¹¤ë¤³¤È¤Ç¡¢¥æ¡¼¥¶Ì¾¤ä¥Ñ¥¹¥ï¡¼¥É¤Î¾ðÊó¤ò¼èÆÀ¤¹¤ë¤è¤¦¤Ê¥×¥í¥°¥é¥à¤¬°ìÈÌŪ¤Ë±£¤µ¤ì¤ä¤¹¤¤¤Ç¤¹¡Ë¤ò¹Ô¤¦¤è¤¦¤ÊÉÔÀµ¿¯Æþ¥Ä¡¼¥ë·²¤È¸Æ¤Ð¤ì¤ë¤â¤Î¤Ç¤¹¡£ ¡¡chkrootkit ¤Ï¡¢¤³¤ì¤é rootkit ¤ò¿×®¤Ë¸¡ºº¤·¤Æ¡¢¥·¥¹¥Æ¥à¤Ë°±Æ¶Á¤¬¤¢¤ë²ÄǽÀ¤¬¤¢¤ì¤Ð·Ù¹ð¤ò¤·¤Æ¤¯¤ì¤ë¥Ä¡¼¥ë¤Ç¤¹¡£¥Ä¡¼¥ë¼«ÂΤˤϥ·¥¹¥Æ¥à²þãâ»þ¤Ë¥Õ¥¡¥¤¥ë¤ò½¤Éü¤¹¤ë¤è¤¦¤Êµ¡Ç½¤Ï¤¢¤ê¤Þ¤»¤ó¡£¤¢¤¯¤Þ¤Ç¸¡½Ð¤¬ÌÜŪ¤Ç¤¹¡£¥·¥¹¥Æ¥à¤¬¸¶°øÉÔÌÀ¤Î¹âÉé²Ù¤Ë´Ù¤Ã¤¿¤ê¡¢ËÜÍè»È¤¨¤ë¤Ï¤º¤Î ps ¤ä ls ¤È¤¤¤Ã¤¿°ìÈÌŪ¤Ê¥³¥Þ¥ó¥É¤¬µÞ¤Ë»È¤¨¤Ê¤¯¤Ê¤Ã¤¿¤ê¤·¤¿¤é¡¢¤È¤ê¤¢¤¨¤ºÉÔÀµ¥¢¥¯¥»¥¹¤òµ¿¤Ã¤Æ¤ß¤ë¤Î¤â£±¤Ä¤ÎÊýË¡¤Ç¤¹¡£ ¡¡ÉÔÀµ¥¢¥¯¥»¥¹¤Ê¤ó¤Æ´Ø·¸¤Ê¤¤¤è¡©¤È¤Ï»×¤Ã¤Æ¤¤¤Þ¤»¤ó¤«¡£¤¿¤È¤¨ iptables ¤Ç¥¬¥Á¥¬¥Á¤Ë SSH ¤ä FTP ¤È¤¤¤Ã¤¿°ìÈÌŪ¤Ê¥Ý¡¼¥È¤ò¼é¤Ã¤Æ¤¤¤Æ¤â¡¢¸ø³«¤µ¤ì¤Æ¤¤¤ë°ìÈÌŪ¤Ê¥µ¡¼¥Ó¥¹¤ËÀȼåÀ¤¬¸«¤Ä¤«¤Ã¤¿¾ì¹ç¡¢¤½¤³¤«¤éÉÔÀµ¤Ê¥¢¥¯¥»¥¹¤ò¼õ¤±¤ë¤³¤È¤¬¤¢¤êÆÀ¤ë¤Î¤Ç¤¹¡£Í̾¤Ê¤È¤³¤í¤Ç¤Ï¿ôǯÁ°¤Ë BIND ¤ÎÀȼåÀ¤òÍøÍѤ·¤¿ ri0n ¤¢¤ë¤¤¤Ï¥é¡¼¥á¥ó¤È¸Æ¤Ð¤ì¤ë¥ï¡¼¥à¡¢¤½¤·¤Æ¡¢OpenSSL ¤ÎÀȼåÀ¤òÍøÍѤ·¤¿ÉÔÀµ¥¢¥¯¥»¥¹¤¬¤¢¤²¤é¤ì¤ë¤Ç¤·¤ç¤¦¡£ ¡¡¾Ü¤·¤¤·Ð°Þ¤ò¤Þ¤È¤á¤Þ¤¹¤È¡¢BIND ¤Ï DNS ¥µ¡¼¥Ó¥¹¤È¤·¤Æ°ìÈÌŪ¤Ê DNS ¥µ¡¼¥Ð¤Ç¤¢¤ì¤Ð¥Ý¡¼¥È 53 ¤ò¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£BIND 8 ¤ÎÀȼåÀ¤¬È¯¸«¤µ¤ì¤Æ¤Þ¤â¤Ê¤¯¡¢¤³¤ÎÀȼåÀ¤òÍøÍѤ·¤Æ¼¡¡¹¤È¥µ¡¼¥Ð¤ËÉÔÀµ¥¢¥¯¥»¥¹¡¦Áý¿£¤ò·«¤êÊÖ¤¹ ri0n ¤È¤¤¤¦¥ï¡¼¥à¤¬½Ð²ó¤Ã¤¿¤³¤È¤¬¤¢¤ê¤Þ¤¹¡£named ¤ÏÅö»þ root ¥æ¡¼¥¶¸¢¸Â¤Ç¼Â¹Ô¤¹¤ë¤³¤È¤¬¤¢¤ê¤Þ¤·¤¿¤Î¤Ç¡Êº£Æü¤Ç¤Ï named ¤È¤¤¤¦ÀìÍѥ桼¥¶¤¬Æ°ºî¤Ë¤¢¤¿¤Ã¤Æ¤¤¤ë¤È»×¤¤¤Þ¤¹¤¬¡Ë¡¢¥·¥¹¥Æ¥à¤ËÉÔÀµ¤Ê¥Õ¥¡¥¤¥ë¤òÉßÀߤµ¤ì¤ë¤È¤¤¤¦¤³¤È¤¬¤¢¤ê¤Þ¤·¤¿¡£ ¡¡OpenSSL ¤ÎÀȼåÀ¤Ç¤Ï OpenSSL ¤Î¥é¥¤¥Ö¥é¥ê¤òÍѤ¤¤¿ mod_ssl¡¢¤Ä¤Þ¤ê https ÄÌ¿®¤Ë¤Ä¤«¤¦¥Ý¡¼¥È 443 ÈÖ¤ËÂФ¹¤ë¹¶·â¤¬¹Ô¤ï¤ì¤¿¤³¤È¤¬¤¢¤ê¤Þ¤¹((¥í¥°¤ò¸«¤ë¤È¡¢º£Æü¤Ç¤â¹¶·â¤È¤ª¤Ü¤·¤¥¢¥¯¥»¥¹¤Ï¸«¼õ¤±¤é¤ì¤Þ¤¹¤¬¡Ä¡Ä))¡£¤¢¤ëÊýË¡¤ò»È¤Ã¤Æ¥Ý¡¼¥È 443 ¤ò¤¿¤¿¤¯¤È¡¢apache ¤Î¼Â¹Ô¥æ¡¼¥¶¸¢¸Â¤Ç¥µ¡¼¥Ð¤Ø¤Î¥í¥°¥¤¥ó¤òµö¤·¤Æ¤·¤Þ¤¦¤³¤È¤¬¤¢¤ê¤Þ¤¹¡£°ìÅÙ¥í¥°¥¤¥ó¤òµö¤¹¤È¡¢¿¯Æþ¼Ô¤Ï exploit(¥¨¥¯¥¹¥×¥í¥¤¥É)¤È¸Æ¤Ð¤ì¤ë root ¸¢¸Â¤òÃ¥¼è¤¹¤ë¤¿¤á¤Î¥×¥í¥°¥é¥à¤òÍѤ¤¤Æ root ¸¢¸Â¤òÃ¥¼è¤·¡¢¥·¥¹¥Æ¥à¤ò²þã⤷¤¿¤ê¡¢MP3 ÃÖ¤¾ì¤Ë¤·¤ÆÍ·¤ó¤À¤ê¡¢Â¾¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤ò¹¶·â¤·¤¿¤ê¡¢¤¢¤È¤Ï¹¥¤ÊüÂê¤ä¤êÊüÂê¡¢¤È¤¤¤¦»öÎã¤â¤¢¤ê¤Þ¤·¤¿¡£ ¡¡¤³¤Î¤è¤¦¤Ë¡¢¤¿¤È¤¨ iptables ¤Ç¸Ç¤á¤Æ¤¤¤è¤¦¤¬ÀìÍÑ¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤Ë¤è¤Ã¤Æ¶¯¸Ç¤Ê¥Í¥Ã¥È¥ï¡¼¥¯¤ò¹½ÃÛ¤·¤Æ¤¤¤Æ¤â¡¢¾ï¤Ë¸ø³«¤µ¤ì¤Æ¤¤¤ë¥Ý¡¼¥È¤Ë±÷¤¤¤Æ¤ÏÉÔÀµ¥¢¥¯¥»¥¹¤ä¹¶·â¤ò¼õ¤±¤ë¤ª¤½¤ì¤¬¤¢¤ê¤Þ¤¹¡£ ¡¡µÞ¤Ë¥Í¥Ã¥È¥ï¡¼¥¯¤¬¥À¥¦¥ó¤·¤¿¤ê¡¢µÞ¤Ë¥³¥Þ¥ó¥É¤¬»È¤¨¤Ê¤¯¤Ê¤Ã¤Æ½é¤á¤Æ¹²¤Æ¤Æ¤â¡¢¤â¤¦¥Í¥Ã¥È¥ï¡¼¥¯¤«¤éÀÚ¤êÎ¥¤¹¤·¤«¼êÃʤϻĤµ¤ì¤Æ¤¤¤Þ¤»¤ó¡£°ìÈÖ¥¿¥Á¤¬°¤¤¤Î¤Ï¥µ¡¼¥ÐÆâ¤ËÀøÉú¤¹¤ë¥¿¥¤¥×¤Î¿¯Æþ¼Ô¤Ç¤¹¡£°ì¸«¸«¤«¤±¾å¤Ï¤Õ¤Ä¤¦¤Î¥·¥¹¥Æ¥à¤Ê¤Î¤Ç¤¹¤¬¡¢¥«¡¼¥Í¥ë¤ËÆüì¤Ê¥â¥¸¥å¡¼¥ë¤òÁȤ߹þ¤Þ¤»¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¿¯Æþ¼Ô¤Î¼Â¹Ô¤¹¤ë¥×¥í¥»¥¹¤ä¥Í¥Ã¥È¥ï¡¼¥¯¾ðÊó¤ò±£¤¹¤è¤¦¤Ê¤³¤È¤¬¤Ç¤¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¡¢¤â¤·¥Í¥Ã¥È¥ï¡¼¥¯¾ðÊó¤ò¥¥ã¥×¥Á¥ã¡¦²òÀϤ¹¤ë¥×¥í¥°¥é¥à¤¬»Å¹þ¤Þ¤ì¤Æ¤¤¤¿¤é¡¢¤¤¤Ä¤Î¤Þ¤Ë¤«¥æ¡¼¥¶Ì¾¤È¥Ñ¥¹¥ï¡¼¥É¤ä¾ðÊó¤ä¡¢³°Éô¤ËÌç³°ÉԽФʥǡ¼¥¿¥Ù¡¼¥¹¤Î½ÅÍ×¾ðÊó¤¬Åð¤Þ¤ì¤ë²ÄǽÀ¤À¤Ã¤Æ¤¢¤ë¤Î¤Ç¤¹¡£ ¡¡¤Ç¤¹¤«¤é¡¢Êݸ±¤È¤¤¤¦°ÕÌ£¤Ç¤â¡¢ÉáÃʤ«¤éÉÔÀµ¿¯Æþ¥Ä¡¼¥ë·²¤ò¼Â¹Ô¤¹¤ë¥Æ¥¹¥È¤ò¤·¤Æ¤ß¤ë¤³¤È¤ò¤ª¤¹¤¹¤á¤·¤Þ¤¹¡£¾ÃËÉ¡¦²ÐºÒ·±Îý¤Î¤è¤¦¤Ê¤â¤Î¤À¤È¹Í¤¨¤Æ¤¯¤À¤µ¤¤¡£¤À¤ì¤âËÜÅö¤Ë²Ð»ö¤¬µ¯¤³¤ë¤Ê¤ó¤Æ»×¤Ã¤Æ¤¤¤Þ¤»¤ó¡¢¤¬¡¢µ¯¤¤ë¤È¤¤Ë¤Ïµ¯¤¤ë¤â¤Î¤Ç¤¹¡£ÉÔÀµ¥¢¥¯¥»¥¹¤È»×¤ï¤ì¤ëÃû¸õ¤¬¸«¤¨¤Æ¤â¡¢°ì¸«¥·¥¹¥Æ¥à¤ÏÊ¿ÀŤòÊݤ俤ޤޤ«¤â¤·¤ì¤Þ¤»¤ó¡£¤½¤ì¤³¤½¡¢¿¯Æþ¼Ô¤Î»×¤¦¤Ä¤Ü¡£¤³¤³¤Ç¾Ò²ð¤¹¤ë chkrootkit ¤ò»È¤Ã¤Æ¡¢Äê´üŪ¤Ë¥·¥¹¥Æ¥à¤Ë°Û¾ï¤¬È¯À¸¤·¤Æ¤¤¤Ê¤¤¤«³Îǧ¤ò¤¹¤ë¤è¤¦¤Ê½¬´·¤Å¤±¤ò¤·¤Æ¤ª¤¯¤³¤È¤ò¶¯¤¯¤ª¤¹¤¹¤á¤·¤Þ¤¹¡£µ¤¤¬¤Ä¤¤¤Æ¤«¤é¤Ç¤ÏÃÙ¤¤¤Î¤Ç¤¹¡£ ¡¡chkrootkit ¤ÏȽÌÀ¤·¤Æ¤¤¤ë((¸ºß¤¬ÃΤé¤ì¤Æ¤¤¤ëÍ̾¤Ê¤â¤Î)) rootkit ¤ä¥ï¡¼¥à¡¢LKM(Lodable Kernel Module) ¤È¤¤¤Ã¤¿¥·¥¹¥Æ¥àÁȹþ·¿¤ÎÉÔÀµ¥Ä¡¼¥ë·²¤ò¸¡ÃΤ¹¤ë¤¿¤á¤Î¥½¥Õ¥È¤Ç¤¹¡£º£Æü¸½ºß(2006-10) version 0.47 ¤¬ºÇ¿·¤Î¤â¤Î¤Ç¤¹¡£ ¡ÊƱÍÍ¤Ê rootkit ¸¡½Ð¥Ä¡¼¥ë¤È¤·¤Æ [[Rootkit Hunter:http://pocketstudio.jp/linux/?Rootkit%20Hunter]] ¤È¤¤¤¦¥½¥Õ¥È¤â¾Ò²ð¤·¤Æ¤ª¤¤Þ¤¹¡£¤³¤Á¤é¤Ï chkrootkit °Ê¾å¤ËºÙ¤«¤Ê¥ì¥Ý¡¼¥È¤ò½Ð¤·¤Æ¤¯¤ì¤Þ¤¹¡Ë ** ¤Ç¡¢chkrootkit ¤Î¾ðÊó¤Ï¤É¤³¤«¤é¡© [#u47b1e2d] ¡¡chkrootkit ¤Î¸ø¼°¥Ú¡¼¥¸¤Ï¤³¤Á¤é¤Ç¤¹ ¡¡http://www.chkrootkit.org/ - Ãøºî¸¢ COPYRIGHT 1.2 (Pangeia Informatica) 2/21/97 Copyright 1996-2003 - Pangeia Informatica, All rights reserved. ** Âбþ OS [#f08791bf] >Linux 2.0.x, 2.2.x, 2.4.x and 2.6.x, >FreeBSD 2.2.x, 3.x, 4.x and 5.x, OpenBSD 2.x and 3.x., NetBSD 1.6.x, >Solaris 2.5.1, 2.6, 8.0 and 9.0, HP-UX 11, Tru64 and BSDI. >(README ¤è¤ê) ** chkrootkit ¤Î¥¤¥ó¥¹¥È¡¼¥ë [#te964bd5] ¡¡¥¤¥ó¥¹¥È¡¼¥ëÊýË¡¤Ï»ê¤Ã¤Æ´Êñ¤Ç¤¹¡£ $ wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz ¡¡¸ø³«¤µ¤ì¤Æ¤¤¤ë [[MD5 ¥Á¥§¥Ã¥¯¥µ¥à:ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.md5]]¤òÈæ³Ó¤·¤Æ¡¢Àµµ¬¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë¤³¤È¤òÇ°¤Î¤¿¤á¤Ë³Îǧ¤·¤Æ¤ª¤¤Þ¤¹¡£ $ md5sum chkrootkit.tar.gz 4c6455d202cef35395a673386e4bf01a8 chkrootkit.tar.gz ¡¡¼¡¤Ë¥Õ¥¡¥¤¥ë¤òŸ³«¤·¤Æ¥Ç¥£¥ì¥¯¥È¥ê¤ò°ÜÆ°¤·¤Þ¤¹¡£ $ tar xfz chkrootkit.tar.gz $ cd chkrootkit-0.47 ¡¡¼¡¤Ë make ¤·¤Þ¤¹¡£ $ make sense ¡¡¤³¤ì¤Ç¥Ð¥¤¥Ê¥ê¤ÎºîÀ®¤Ï½ª¤ï¤ê¤Þ¤·¤¿¡£¼Â¹Ô¤Ï¤½¤Î¥Ç¥£¥ì¥¯¥È¥êÆâ¤Ç¹Ô¤¤¤Þ¤¹¡£chkrootkit ¤ÏËÜÂΤǤ¹¤¬¡¢¤½¤Î¤Û¤«¤Î¥×¥í¥°¥é¥à¤ÈϢư¤·¤ÆÆ°ºî¤¹¤ëɬÍפ¬¤¢¤ë¤¿¤á¤Ç¤¹¡£°ì±þ chkrootkit ñÂΤǤâÆ°ºî¤Ï¹Ô¤ï¤ì¤Þ¤¹¡£ ** chkrootkit ¤Î¼Â¹Ô [#l93b6bdd] ¡¡¥½¡¼¥¹¤ò make ¤·¤¿¥Ç¥£¥ì¥¯¥È¥ê¤Ç chkrootkit ¤ò¼Â¹Ô¤·¤Þ¤¹¡£ ¡¡Ãí°ÕÅÀ¤È¤·¤Æ¤Ï¼Â¹Ô»þ¤Ë¤Ï root ¥æ¡¼¥¶¸¢¸Â¤¬É¬ÍפȤʤê¤Þ¤¹¡£°ìÈ̥桼¥¶¤Ç¤Ï¤¹¤Ù¤Æ¤Î¸¡ºº¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤¤Þ¤»¤ó¡£ # ./chkrootkit ¡¡¤Á¤Ê¤ß¤Ë°Ê²¼¤¬ Fedora Core 4 ¤Ç¼Â¹Ô¤·¤Æ¤ß¤¿·ë²Ì¤Ç¤¹¡£ ROOTDIR is `/' Checking `amd'... not found Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected Checking `cron'... not infected Checking `date'... not infected Checking `du'... not infected Checking `dirname'... not infected Checking `echo'... not infected Checking `egrep'... not infected Checking `env'... not infected Checking `find'... not infected Checking `fingerd'... not found Checking `gpm'... not infected Checking `grep'... not infected Checking `hdparm'... not infected Checking `su'... not infected Checking `ifconfig'... not infected Checking `inetd'... not tested Checking `inetdconf'... not found Checking `identd'... not found Checking `init'... not infected Checking `killall'... not infected Checking `ldsopreload'... not infected Checking `login'... not infected Checking `ls'... not infected Checking `lsof'... not infected Checking `mail'... not infected Checking `mingetty'... not infected Checking `netstat'... not infected Checking `named'... not infected Checking `passwd'... not infected Checking `pidof'... not infected Checking `pop2'... not found Checking `pop3'... not found Checking `ps'... not infected Checking `pstree'... not infected Checking `rpcinfo'... not infected Checking `rlogind'... not found Checking `rshd'... not found Checking `slogin'... not infected Checking `sendmail'... not infected Checking `sshd'... not infected Checking `syslogd'... not infected Checking `tar'... not infected Checking `tcpd'... not infected Checking `tcpdump'... not infected Checking `top'... not infected Checking `telnetd'... not infected Checking `timed'... not found Checking `traceroute'... not infected Checking `vdir'... not infected Checking `w'... not infected Checking `write'... not infected Checking `aliens'... no suspect files Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found Searching for Lion Worm default files and dirs... nothing found Searching for RSHA's default files and dir... nothing found Searching for RH-Sharpe's default files... nothing found Searching for Ambient's rootkit (ark) default files and dirs... nothing found Searching for suspicious files and dirs, it may take a while... /usr/lib/perl5/5.8.6/i386-linux-thread-multi/.packlist /usr/lib/perl5/vendor_perl/5.8.6/ i386-linux-thread-multi/auto/NKF/.packlist Searching for LPD Worm files and dirs... nothing found Searching for Ramen Worm files and dirs... nothing found Searching for Maniac files and dirs... nothing found Searching for RK17 files and dirs... nothing found Searching for Ducoci rootkit... nothing found Searching for Adore Worm... nothing found Searching for ShitC Worm... nothing found Searching for Omega Worm... nothing found Searching for Sadmind/IIS Worm... nothing found Searching for MonKit... nothing found Searching for Showtee... nothing found Searching for OpticKit... nothing founde Searching for T.R.K... nothing found Searching for Mithra... nothing found Searching for LOC rootkit... nothing found Searching for Romanian rootkit... nothing found Searching for HKRK rootkit... nothing found Searching for Suckit rootkit... nothing found Searching for Volc rootkit... nothing found Searching for Gold2 rootkit... nothing found Searching for TC2 Worm default files and dirs... nothing found Searching for Anonoying rootkit default files and dirs... nothing found Searching for ZK rootkit default files and dirs... nothing found Searching for ShKit rootkit default files and dirs... nothing found Searching for AjaKit rootkit default files and dirs... nothing found Searching for zaRwT rootkit default files and dirs... nothing found Searching for Madalin rootkit default files... nothing found Searching for Fu rootkit default files... nothing found Searching for ESRK rootkit default files... nothing found Searching for anomalies in shell history files... nothing found Checking `asp'... not infected Checking `bindshell'... INFECTED (PORTS: 465) Checking `lkm'... chkproc: nothing detected Checking `rexedcs'... not found Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets eth1: not promisc and no PF_PACKET sockets Checking `w55808'... not infected Checking `wted'... chkwtmp: nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... chklastlog: nothing deleted Checking `chkutmp'... chkutmp: nothing deleted ¡¡ÆâÌõ¤òºÙ¤«¤¯¸«¤Æ¤¤¤¯¤È ROOTDIR is `/' ¡¡£±¹ÔÌܤΠROOTDIR ¤Ï / ÇÛ²¼¤¹¤Ù¤Æ¤ò¸¡º÷ÂоݤȤ·¤Æ¤¤¤ë¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£ Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected ¡¡£²¹ÔÌܰʹߤΠChecking ¤Ï¼ç¤Ê¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤Ç¤¹¡£"not found"¤È¤¤¤¦¤Î¤Ï¥Õ¥¡¥¤¥ë¤¬¤¢¤ê¤Þ¤»¤ó¤·¡¢"not infected" ¤È¤Ç¤Æ¤¤¤ì¤Ð²þã⤵¤ì¤Æ¤¤¤ë²ÄǽÀ¤Ï¤Ê¤¤¤È¤¤¤¨¤Þ¤¹¡£ ¡¡¤Á¤Ê¤ß¤Ë²þã⤵¤ì¤Æ¤¤¤ë¤È¡¢¤½¤Î¥Õ¥¡¥¤¥ë¤ËÂФ·¤Æ¤Ï "INFECTED" ¤Èɽ¼¨¤µ¤ì¤Þ¤¹¡£ Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found ¡¡°ú¤Â³¤ Searching ¤È³¤¤¤Æ¤¤¤ë¤Î¤Ï¥ï¡¼¥à¤ä¥ë¡¼¥È¥¥Ã¥È¤¬ÁȤ߹þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¤«¤Î¸¡½Ð¤Ç¤¹¡£"nothing found" ¤È¤Ç¤Æ¤¤¤ë¤Î¤¬Åö¤¿¤êÁ°¤Ç¤¹¡£FOUND ¤È¤Ê¤Ã¤¿¤é¡¢²¿¤«»Å¹þ¤Þ¤ì¤Æ¤¤¤ë²ÄǽÀ¤¬Èó¾ï¤Ë¹â¤¤¤Ç¤¹¡£ Searching for suspicious files and dirs, it may take a while... ¡¡¤³¤³¤Ç¤Ï¥Õ¥¡¥¤¥ë̾¤ÎÀèƬ¤Ë . ¤¬¤Ä¤¤¤Æ¤¤¤Æ¡¢²ø¤·¤¤¤È»×¤ï¤ì¤ë¥Õ¥¡¥¤¥ë¤Î°ìÍ÷¤òɽ¼¨¤·¤Þ¤¹¡£¥·¥¹¥Æ¥à¤¬ÍѤ¤¤ë¤â¤Î¤Ç¤¢¤ì¤ÐÌäÂê¤Ï¤¢¤ê¤Þ¤»¤ó¡£¸«´·¤ì¤Ê¤¤¥Õ¥¡¥¤¥ë¤¬±÷¤«¤ì¤Æ¤¤¤¿¤éÍ×Ãí°Õ¤Ç¤¹¡£ Checking `asp'... not infected Checking `bindshell'... INFECTED (PORTS: 465) ¡¡¤ª¤Ã¤È¡¢¤³¤³¤Ç bindshell ¤¬ INFECTED ¤È¤Ç¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡£¾Ü¤·¤¤¾ðÊó¤Ï¤ï¤«¤é¤Ê¤¤¤Î¤Ç¤¹¤¬¡¢°ìÀÎÁ°¤Ë bindshell ¤È¤¤¤¦¥Ä¡¼¥ë¤ÎÃæ¤Ë¥Ý¡¼¥È 465 ¤ò»È¤¦¤è¤¦¤Ê¤â¤Î¤¬¤¢¤Ã¤¿¤ß¤¿¤¤¤Ç¤¹¤Í¡£¤Þ¡¢Íî¤ÁÃ夤¤Æ¥Ý¡¼¥È 465 ¤ò³Îǧ¤·¤Þ¤·¤ç¤¦¡£ # /usr/sbin/lsof -i tcp:465 COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME sendmail 1996 root 6u IPv4 5783 TCP *:smtps (LISTEN) ¡¡¥Ý¡¼¥È¤Î³Îǧ¤Ï lsof ¥³¥Þ¥ó¥É¤Ç¤¹¡£¤³¤Á¤é¤Ï¤ß¤Æ¤ÎÄ̤ê sendmail ¤¬ Submission Port(¥á¡¼¥ëÁ÷¿®ÍѤΥµ¥Ö¥ß¥Ã¥·¥ç¥ó¡¦¥Ý¡¼¥È)¤È¤·¤Æ smtps ÄÌ¿®ÍѤËÍѤ¤¤Æ¤¤¤ë¤â¤Î¤Ç¤¹¤«¤é¡¢Á´¤¯ÌäÂꤢ¤ê¤Þ¤»¤ó¡£ Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets eth1: not promisc and no PF_PACKET sockets Checking `w55808'... not infected Checking `wted'... chkwtmp: nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... chklastlog: nothing deleted Checking `chkutmp'... chkutmp: nothing deleted ¡¡ºÇ¸å¤ÎÊý¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¤¬¥¹¥¥ã¥ó²Äǽ¤Ê¾õÂ֤ǤϤʤ¤¤«(PROMICUS ¥â¡¼¥É¤«¤É¤¦¤«¡Ë¤Î³Îǧ¤ä utmp ¤È¤¤¤Ã¤¿¥í¥°¥¤¥ó¾ðÊó¤ä¥í¥°¤Î²þã⤬¤ß¤é¤ì¤Ê¤¤¤«¥Á¥§¥Ã¥¯¤·¤Æ¤¤¤Þ¤¹¡£ ¡¡¤Á¤Ê¤ß¤Ë¡¢»ä¤Ï Vine 2.1.5(·ë¹½¸Å¤¤¤Ç¤¹¤¬¸½Ìò¥µ¡¼¥Ð¤Ç¤¹) ´Ä¶¤Ç³Îǧ¤·¤Æ¤¤¤Þ¤¹¤¬¡¢ps ¥³¥Þ¥ó¥É¤Î°ú¿ô¤«²¿¤«¤Î¥Ð¥°¤Ç¼¡¤Î¤è¤¦¤Ê·Ù¹ð¤¬¤Ç¤Æ¤·¤Þ¤¦¤è¤¦¤Ç¤¹¡£ OooPS! chkproc: Warning: Possible LKM Trojan installed ¡¡¤È¤ê¤¢¤¨¤º¼Â¹Ô¤·¤Æ¤ß¤Æ¡¢¥·¥¹¥Æ¥à¤Ë°Û¾ï¤¬¸«¼õ¤±¤é¤ì¤Ê¤¤¤è¤¦¤Ê¤é°Â¿´¤Ç¤¹¡£¤â¤· INFECTED ¤ä ¡Á installed ¤È¤Ç¤¿¤é¡¢¤¢¤ï¤Æ¤º¤Ë¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤ÎÆüÉÕ¤ä md5sum ¥³¥Þ¥ó¥É¤Ë¤è¤ë¥Á¥§¥Ã¥¯¥µ¥à¤òÈæ³Ó¤·¤¿¤ê¤·¡¢ÉÔÀµ¥¢¥¯¥»¥¹¤¬Ç§¤á¤é¤ì¤ë¤Ê¤é®¤ä¤«¤Ë¥Í¥Ã¥È¥ï¡¼¥¯¤«¤éÀÚ¤êÎ¥¤·¤ÆÂн褹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£ ** chkrootkit ¤Î¼Â¹Ô¥ª¥×¥·¥ç¥ó [#ufd37b25] - "-h" ¥Ø¥ë¥×¤òɽ¼¨¤·¤Þ¤¹ # ./chkrootkit -h Usage: ./chkrootkit [options] [test ...] Options: -h show this help and exit -V show version information and exit -l show available tests and exit -d debug -q quiet mode -x expert mode -r dir use dir as the root directory -p dir1:dir2:dirN path for the external commands used by chkrootkit -n skip NFS mounted dirs - "-V" ¥Ð¡¼¥¸¥ç¥óÈÖ¹æ¤òɽ¼¨¤·¤Þ¤¹ # ./chkrootkit -V chkrootkit version 0.45 - "-l" chkktootkit ¤Î¸¡ººÂоݤȤʤë¥Õ¥¡¥¤¥ë°ìÍ÷¤òɽ¼¨¤·¤Þ¤¹¡£ # ./chkrootkit -l ./chkrootkit: tests: aliens asp bindshell lkm rexedcs sniffer w55808 wted scalper slapper z2 chkutmp amd basename biff chfn chsh cron date du dirname echo egrep env find fingerd gpm grep hdparm su ifconfig inetd inetdconf identd init killall ldsopreload login ls lsof mail mingetty netstat named passwd pidof pop2 pop3 ps pstree rpcinfo rlogind rshd slogin sendmail sshd syslogd tar tcpd tcpdump top telnetd timed traceroute vdir w write - "-q" ÀŤ«¤Ê¥â¡¼¥É¡£ÌäÂê¤È¤Ê¤Ã¤¿¹àÌܤ·¤«É½¼¨¤·¤Þ¤»¤ó¡£ # ./chkrootkit -q /usr/lib/perl5/5.8.6/i386-linux-thread-multi/.packlist /usr/lib/perl5/vendor_perl/5.8.6/i386-linux-thread-multi/auto/NKF/.packlist INFECTED (PORTS: 465) - "-x" ¥¨¥¥¹¥Ñ¡¼¥È¡Ê¾åµé¼Ô¸þ¤±¡Ë¥â¡¼¥É¤Ç¤¹¡£Èó¾ï¤ËËÄÂç¤Ê¸¡ººµÏ¿¤¬É½¼¨¤µ¤ì¤Þ¤¹¤Î¤Ç¡¢¼ÂÍÑŪ¤ÊÊýË¡¤È¤·¤Æ¤Ï°Ê²¼¤Î¤è¤¦¤Ë¥í¥°¤ò½Ð¤¹¤è¤¦¤Ë¤·¤¿¤Û¤¦¤¬Îɤ¤¤Ç¤¹¡£ # ./chkrootkit -x > check.log - "-r" ¸¡ººÂоݤȤʤë¥Ç¥£¥ì¥¯¥È¥ê¤Î»ØÄê¤Ç¤¹¡£¤¿¤È¤¨¤Ð¡¢ÉÔÀµ¥¢¥¯¥»¥¹¤Ë¤è¤ê¥·¥¹¥Æ¥à¤¬²þã⤵¤ì¤¿¥É¥é¥¤¥Ö¤¬ /mnt ¤Ë¥Þ¥¦¥ó¥È¤·¤Æ¤¢¤ë¾ì¹ç¡¢Ä´ºº¤Î¤¿¤á¤Ë»È¤¦¾ì¹ç¤â¤¢¤ê¤Þ¤¹¡Ê·Ù¹ð¡§ÉÔÀµ¤Ê¥Ä¡¼¥ë·²¤ÎÃæ¤Ë¤Ï chkrootkit ¥Õ¥¡¥¤¥ë¤ò¼Â¹Ô¤¹¤ë¤À¤±¤Ç¤â¸½¹Ô¤Î¥·¥¹¥Æ¥à¤òºÆ±øÀ÷¤¹¤ë¤è¤¦¤Ê¤â¤Î¤â¸ºß¤·¤Æ¤¤¤Þ¤¹¡£¤¯¤ì¤°¤ì¤â¡¢¼Â²ÔƯÃæ¤Î½ÅÍפʥµ¡¼¥Ð¤Ç¤Ï¸¡ºº¤ò¹Ô¤ï¤Ê¤¤¤Ç¤¯¤À¤µ¤¤¡£¡Ë¡£ # ./chkrootkit -r /mnt - "-p" ¤Ï¥ª¥ê¥¸¥Ê¥ë¤Î /bin ¤ä /usr/bin ÇÛ²¼¤Î¥Õ¥¡¥¤¥ë¤¬±øÀ÷¤µ¤ì¤Æ¤¤¤ë²ÄǽÀ¤¬¤¢¤ë¤È¤¡Ê chkrootkit ¼«¿È¤¬¤À¤Þ¤µ¤ì¤ë²ÄǽÀ¤¬¤¢¤ë¤È¤¡Ë¡¢¼Â¹Ô¥Õ¥¡¥¤¥ë¤Î¥Ç¥£¥ì¥¯¥È¥ê¤ò»ØÄꤹ¤ë»þ¤Î¥ª¥×¥·¥ç¥ó¤Ç¤¹¡£¤¿¤È¤¨¤Ð¡¢¥ª¥ê¥¸¥Ê¥ë¤Î¥Õ¥¡¥¤¥ë¤¬ /media/cdrom/bin ¤Ë¤¢¤ë»þ¤Ï¼¡¤Î¤è¤¦¤Ë¤·¤Þ¤¹¡£ # ./chkrootkit -p /media/cdrom/bin > ¡¡"-r"¤È"-p"¤Î°ã¤¤¤Ï¡¢"-r" ¤¬»ØÄꤷ¤¿¥Ç¥£¥ì¥¯¥È¥êÇÛ²¼¤ò°ì³ç¤·¤Æ¸¡ºº¤¹¤ë¤Î¤ËÂФ·¤Æ¡¢"-p" ¤Ç¤ÏÊ£¿ô¤Î¥Ç¥£¥ì¥¯¥È¥ê¤Î¤ß¥Á¥§¥Ã¥¯¤Ç¤¤Þ¤¹¡£¤¿¤È¤¨¤Ð /bin ¤È /sbin ¤Î¤ß¥Á¥§¥Ã¥¯¤ò¤µ¤»¤¿¤¤»þ¤Ï # ./chkrootkit -p /bin:/sbin ¡¡¤³¤Î¤è¤¦¤Ë¡¢¥Ñ¥¹¤ò ":" µ¹æ¤Ç¶èÀڤäƻØÄꤷ¤Þ¤¹¡£ < - "-n" NFS ¥Þ¥¦¥ó¥È¤µ¤ì¤¿¥Ç¥£¥ì¥¯¥È¥ê¤Ï¸¡ººÂоݳ°¤È¤·¤Þ¤¹¡£ ¡¡¤Þ¤¿¡¢ÆÃÄê¤Î¥×¥í¥»¥¹¤ä¥Õ¥¡¥¤¥ë¤Î¤ß¥Á¥§¥Ã¥¯¤µ¤»¤ë¤³¤È¤â¤Ç¤¤Þ¤¹¡£¤¿¤È¤¨¤Ð ps ¤È ls ¤À¤±¸¡ºº¤·¤¿¤¤¤È¤¤Ï¡¢¼¡¤Î¤è¤¦¤Ë°ú¿ô¤È¤·¤Æ¥Õ¥¡¥¤¥ë̾¤òµ½Ò¤·¤Þ¤¹¡£ # ./chkrootkit ps ls ROOTDIR is `/' Checking `ps'... not infected Checking `ls'... not infected ¡¡É½¼¨·ë²Ì¤Î¾ÜºÙ¤Ï[[README ÆüËܸìÌõ>chkrootkit README ÆüËܸìÌõ]]¤ò¡¢¤¢¤ë¤¤¤Ï[[FAQ ÆüËܸìÈÇ:http://pocketstudio.jp/linux/?chkrootkit%20FAQ%20%C6%FC%CB%DC%B8%EC%CC%F5]]¤ò¤´Í÷¤¯¤À¤µ¤¤¡£ ** chkrootkit ¤ÎÄê´üŪ¤Ê¼Â¹Ô¤Ç´Æ»ëÂÎÀ©¤òÀ°¤¨¤ë [#f13a0315] ¡¡¤»¤Ã¤«¤¯ÊØÍø¤Ê¥Ä¡¼¥ë¤Ê¤Î¤Ç¡¢ËèÆü¼«Æ°¼Â¹Ô¤µ¤»¤ë¤è¤¦¤ÊÂÎÀ©¤ò¤È¤È¤Î¤¨¤Þ¤·¤ç¤¦¡£cron ¤Ç¼Â¹Ô¤¹¤ë¤¿¤á¤Î¥¹¥¯¥ê¥×¥È¤òºî¤ê¤Þ¤¹¡£Ãí°ÕÅÀ¤È¤·¤Æ¤Ï chkrootkit ¤¬¥³¥ó¥Ñ¥¤¥ë¤µ¤ì¤¿´Ä¶¤ò¥«¥ì¥ó¥È¤Î¥Ç¥£¥ì¥¯¥È¥ê¤È¼Â¹Ô¤µ¤ì¤Ê¤¯¤Æ¤Ï¤¤¤±¤Ê¤¤¡¢¤È¤¤¤¦¤³¤È¤Ç¤¹¡£Í×¤Ï make ¤·¤¿¤È¤³¤í¤Ç¼Â¹Ô¡¢¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£ ¡¡¤³¤³¤Ç¤Ï /usr/local ¤Ë chkrootkit ¤Î¥³¥Ô¡¼¤òÃÖ¤¯¤è¤¦¤Ë¤¹¤ëÎã¤òµ½Ò¤·¤Þ¤¹¡£ ¡¡¤Ê¤ª¡¢¥½¡¼¥¹¤Ï /usr/local/chkrootkit-0.45 ¤ËŸ³«¤·¤¿¤â¤Î¤È¤·¤Þ¤¹¡£ ¡¡¤Þ¤º¡¢¥½¡¼¥¹¤Î¥·¥ó¥Ü¥ê¥Ã¥¯¥ê¥ó¥¯¤ò /usr/local/chkrootkit ¤Ë¤Ï¤ê¤Þ¤¹¡£¥ê¥ó¥¯¤·¤Æ¤ª¤¯¤Î¤Ï¡¢¾Íè chkrootkit ¤Î¥Ð¡¼¥¸¥ç¥ó¤¬ÊѤï¤ë¤³¤È¤¬¤¢¤Ã¤Æ¤â¡¢¥ê¥ó¥¯Àè¤òÊѹ¹¤¹¤ë¤À¤±¤Ç¾¤Î¥¹¥¯¥ê¥×¥È·²¤Ë¤Ï¼ê¤ò²Ã¤¨¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ç¤¹¡£ # ln -s /usr/local/src/chkrootkit-0.45 /usr/local/chkrootkit ¡¡¼¡¤Ë¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¤Þ¤¹¡£ # vi /usr/local/bin/chkrootkit.sh ¡¡¥Õ¥¡¥¤¥ë¤ÎÃæ¿È¤Ï¼¡¤Î¤è¤¦¤Ê¤â¤Î¤Ç¤¹¡£ #!/bin/sh cd /usr/local/chkrootkit ./chkrootkit | mail -s "[chkrootkit] HOSTNAME `date +%Y-%m-%d`" admin@example.jp ¡¡¤³¤Î¤è¤¦¤Ëµ½Ò¤·¤Æ¤¯¤À¤µ¤¤¡£HOSTNAME ¤Ï¼«Ê¬¤Î¥Û¥¹¥È̾¤ò¡¢ËöÈø¤Î admin@example.jp ¤Ï¼«Ê¬¡Ê¤¢¤ë¤¤¤Ï¥µ¡¼¥Ð´ÉÍý¼Ô¡Ë¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤òµ½Ò¤·¤Þ¤¹¡£ ¡¡°Û¾ï¤¬¤Ç¤¿¤È¤¤À¤±¥á¥Ã¥»¡¼¥¸¤ò½Ð¤µ¤»¤¿¤¤¤È¤¤Ï°Ê²¼¤Î¤è¤¦¤Ê¥ª¥×¥·¥ç¥ó¤ò¤Ä¤±¤ë¤Û¤¦¤¬Îɤ¤¤Ç¤·¤ç¤¦¡£ ./chkrootkit -q | mail -s "[chkrootkit] HOSTNAME `date +%Y-%m-%d`" admin@example.jp ¡¡¼¡¤Ë¼Â¹Ô¸¢¸Â¤òÍ¿¤¨¤Þ¤¹¡£ # chmod +x /usr/local/bin/chkrootkit.sh ¡¡¼¡¤Ï cron ¤Ø¤ÎÅÐÏ¿¤Ç¤¹¡£ # crontab -e ¤È¼Â¹Ô¤·¤Þ¤¹¡£vi ¤Î cron ÊÔ½¸²èÌ̤ˤʤê¤Þ¤¹¤Î¤Ç¡¢ 00 01 * * * /usr/local/bin/chkrootkit.sh > /dev/null 2>&1 ¡¡¤³¤Îµ½ÒÎã¤Ç¤Ï¡¢ËèÆü¸áÁ°£±»þ¤Ë chkrootkit.sh (Àè¤Û¤Éµ½Ò¤·¤¿¥¹¥¯¥ê¥×¥È) ¤ò¼Â¹Ô¤·¤Æ¡¢¥á¡¼¥ë¤ò admin@example.jp °¸¤ËÂê̾¡Ø[chkrootkit] HOSTNAME 2005-07-20¡Ù¡ÊºÇ´ü¤Ïǯ·îÆü¡Ë¤È¤·¤ÆÁ÷¿®¤µ¤»¤ë¤â¤Î¤Ç¤¹¡£Âê̾¤ÎÉôʬ¤ÏɬÍפ˱þ¤¸¤ÆŬÅö¤Ë½ñ¤´¹¤¨¤Æ»È¤Ã¤Æ¤ß¤Æ¤¯¤À¤µ¤¤¡£ ¡¡¤³¤ÎÃʳ¬¤Ç»î¤·¤Ë¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ¤ß¤ë¤È¡¢¥á¡¼¥ë¤¬ÆϤ¯¤Ï¤º¤Ç¤¹¡£ # /usr/local/bin/chkrootkit.sh ¡¡¤¢¤È¤Ï¡¢ËèÆü·Ú¤¯¥Á¥§¥Ã¥¯¤·¤Æ¡¢°Û¾ï¤¬¸«¼õ¤±¤é¤ì¤Ê¤¤¤«³Îǧ¤¹¤ë¤è¤¦¤Ë½¬´·¤Å¤±¤Æ¤ª¤¯¤³¤È¤¬Îɤ¤¤Ç¤·¤ç¤¦¡£ * chkrootkit ´ØÏ¢¤ÎÆüËܸì¥É¥¥å¥á¥ó¥È [#j14afb16] - [[README ÆüËܸìÌõ>chkrootkit README ÆüËܸìÌõ]] - [[FAQ ÆüËܸìÈÇ>chkrootkit FAQ ÆüËܸìÌõ]]
¥Æ¥¥¹¥ÈÀ°·Á¤Î¥ë¡¼¥ë¤òɽ¼¨¤¹¤ë