News †
ܸ첽ץ †chkrootkit ܸ첽ץȤϤޤ(2006ǯ1011) ܺ٤ʷаޤϸꥹ users@chkrootkit.it.org "Subject: [crt-users] May I make a translation site? (in Japanese)"³åɤ֤αϤǤʤ褦ǤƤͤɤޤʤ ȯԤǤ Nelson ĺޤjp1.chkrootkit.org ͽǤ ΥץȤŪϸȤ¤ʤܸ첽ˤޤ ʸϰʲȴʱѸǤʤˡ > My proposal is simple. That is in editing of pure > www.chkrootkit.org. In other words, I translate English of HTML > of the site into Japanese. A display style there doesn't take > its place. > > It is inferior to ability in reading and writing because the > Japanese most part doesn't make English a main language in being > disappointing. Even if you think "Is though it such easy English?" > > It is rather another problem that I am anxious. The person who > can't discuss English in the Japanese technician of linux is the > fact to exist in many, too. (This comes off the main subject. I > think that it can have it know as your reference.) > > In addition, I will sometimes appear at the site if the one for > the Japanese has renewal information. I want to provide a > localization patch if it is possible, too. Don't you care though you think that I will proceed with the work with the above contents? ȯԤ Nelson ᤫ "No problem. You're welcome. Please, go ahead."ʤ衢ޤޤɤˤȲĺޤ chkrootkit Ȥä †chkrootkit äƲ †ΡȤȤ chkrootkit (å롼ȥå)μǤϰͭ̾ߤǤrootkit (롼Ȥä) ȤΤԤƥե⤷ѹꡢХåɥΤȤɸǤϤʤ̥ݡȤǵưsshdФǤȤˤߡץαá¾ΥзݡȥꡢSniffer ȤͥåȥΥѥåȤϤ뤳Ȥǡ桼̾ѥɤξ褦ʥץबŪ˱䤹ǤˤԤ褦ġ뷲ȸƤФΤǤ chkrootkit ϡ rootkit ®˸ơƥ˰ƶǽзٹƤġǤġ뼫Τˤϥƥ˥ե褦ʵǽϤޤޤǸФŪǤƥबι٤˴٤äꡢȤϤ ps ls ȤäŪʥޥɤޤ˻Ȥʤʤäꤷ顢ȤꤢäƤߤΤ⣱ĤˡǤ ʤƴطʤ衩ȤϻפäƤޤȤ iptables ǥ SSH FTP ȤäŪʥݡȤäƤƤ⡢ƤŪʥӥȼĤä硢ʥ뤳ȤΤǤͭ̾ʤȤǤϿǯ BIND ȼѤ ri0n 뤤ϥ顼ȸƤФࡢơOpenSSL ȼѤǤ礦 ܤаޤޤȤޤȡBIND DNS ӥȤưŪ DNS ФǤХݡ 53 ƤޤBIND 8 ȼȯƤޤʤȼѤƼȥФ֤ ri0n ȤबвäȤޤnamed root 桼¤Ǽ¹Ԥ뤳ȤޤΤǡʺǤ named Ȥѥ桼ưˤäƤȻפޤˡƥʥեߤȤȤޤ OpenSSL ȼǤ OpenSSL Υ饤֥Ѥ mod_sslĤޤ https ̿ˤĤݡ 443 ֤Ф빶⤬Ԥ줿Ȥޤ*1ˡȤäƥݡ 443 ȡapache μ¹ԥ桼¤ǥФؤΥƤޤȤޤ٥ȡԤ exploit(ץ)ȸƤФ root ¤å褹뤿ΥץѤ root ¤å褷ƥ⤷ꡢMP3 ֤ˤͷꡢ¾Υͥåȥ⤷ꡢȤϹꡢȤ⤢ޤ Τ褦ˡȤ iptables ǸǤƤ褦ѥեˤäƶǤʥͥåȥۤƤƤ⡢˸ƤݡȤ˱Ƥ乶뤪줬ޤ ޤ˥ͥåȥꡢޤ˥ޥɤȤʤʤäƽƹƤƤ⡢⤦ͥåȥڤΥʤϻĤƤޤ֥Τϥ륿פοԤǤ츫ϤդĤΥƥʤΤǤͥüʥ⥸塼Ȥ߹ޤ뤳ȤˤäơԤμ¹Ԥץͥåȥ褦ʤȤǤޤˤꡢ⤷ͥåȥץ㡦ϤץबŹޤƤ顢ĤΤޤˤ桼̾ȥѥɤ䡢糰ԽФʥǡ١νޤǽäƤΤǤ Ǥ顢ݸȤ̣Ǥ⡢ʤġ뷲¹ԤƥȤƤߤ뤳ȤᤷޤɡкҷΤ褦ʤΤȹͤƤ˲лʤƻפäƤޤȤˤϵΤǤȻפƤ⡢츫ƥʿŤݤäޤޤ⤷ޤ줳ԤλפĤܡǾҲ𤹤 chkrootkit ȤäơŪ˥ƥ˰۾郎ȯƤʤǧ褦ʽŤƤȤᤷޤĤƤǤ٤ΤǤ chkrootkit ȽƤ*2 rootkit ࡢLKM(Lodable Kernel Module) Ȥäƥȹġ뷲Τ뤿ΥեȤǤ(2006-10) version 0.47 ǿΤΤǤ Ʊͤ rootkit ХġȤ Rootkit Hunter ȤեȤҲ𤷤Ƥޤ chkrootkit ʾ˺٤ʥݡȤФƤޤ ǡchkrootkit ξϤɤ顩 †chkrootkit θڡϤǤ
б OS †
chkrootkit Υȡ †ȡˡϻäƴñǤ $ wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz Ƥ MD5 åӤơեǤ뤳ȤǰΤ˳ǧƤޤ $ md5sum chkrootkit.tar.gz 4c6455d202cef35395a673386e4bf01a8 chkrootkit.tar.gz ˥եŸƥǥ쥯ȥưޤ $ tar xfz chkrootkit.tar.gz $ cd chkrootkit-0.47 make ޤ $ make sense ǥХʥκϽޤ¹ԤϤΥǥ쥯ȥǹԤޤchkrootkit ΤǤΤۤΥץϢưưɬפ뤿Ǥ chkrootkit ñΤǤưϹԤޤ chkrootkit μ¹ †make ǥ쥯ȥ chkrootkit ¹Ԥޤ ȤƤϼ¹Իˤ root 桼¤ɬפȤʤޤ̥桼ǤϤ٤ƤθԤȤǤޤ # ./chkrootkit ʤߤ˰ʲ Fedora Core 4 Ǽ¹ԤƤߤ̤Ǥ ROOTDIR is `/' Checking `amd'... not found Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected Checking `cron'... not infected Checking `date'... not infected Checking `du'... not infected Checking `dirname'... not infected Checking `echo'... not infected Checking `egrep'... not infected Checking `env'... not infected Checking `find'... not infected Checking `fingerd'... not found Checking `gpm'... not infected Checking `grep'... not infected Checking `hdparm'... not infected Checking `su'... not infected Checking `ifconfig'... not infected Checking `inetd'... not tested Checking `inetdconf'... not found Checking `identd'... not found Checking `init'... not infected Checking `killall'... not infected Checking `ldsopreload'... not infected Checking `login'... not infected Checking `ls'... not infected Checking `lsof'... not infected Checking `mail'... not infected Checking `mingetty'... not infected Checking `netstat'... not infected Checking `named'... not infected Checking `passwd'... not infected Checking `pidof'... not infected Checking `pop2'... not found Checking `pop3'... not found Checking `ps'... not infected Checking `pstree'... not infected Checking `rpcinfo'... not infected Checking `rlogind'... not found Checking `rshd'... not found Checking `slogin'... not infected Checking `sendmail'... not infected Checking `sshd'... not infected Checking `syslogd'... not infected Checking `tar'... not infected Checking `tcpd'... not infected Checking `tcpdump'... not infected Checking `top'... not infected Checking `telnetd'... not infected Checking `timed'... not found Checking `traceroute'... not infected Checking `vdir'... not infected Checking `w'... not infected Checking `write'... not infected Checking `aliens'... no suspect files Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found Searching for Lion Worm default files and dirs... nothing found Searching for RSHA's default files and dir... nothing found Searching for RH-Sharpe's default files... nothing found Searching for Ambient's rootkit (ark) default files and dirs... nothing found Searching for suspicious files and dirs, it may take a while... /usr/lib/perl5/5.8.6/i386-linux-thread-multi/.packlist /usr/lib/perl5/vendor_perl/5.8.6/ i386-linux-thread-multi/auto/NKF/.packlist Searching for LPD Worm files and dirs... nothing found Searching for Ramen Worm files and dirs... nothing found Searching for Maniac files and dirs... nothing found Searching for RK17 files and dirs... nothing found Searching for Ducoci rootkit... nothing found Searching for Adore Worm... nothing found Searching for ShitC Worm... nothing found Searching for Omega Worm... nothing found Searching for Sadmind/IIS Worm... nothing found Searching for MonKit... nothing found Searching for Showtee... nothing found Searching for OpticKit... nothing founde Searching for T.R.K... nothing found Searching for Mithra... nothing found Searching for LOC rootkit... nothing found Searching for Romanian rootkit... nothing found Searching for HKRK rootkit... nothing found Searching for Suckit rootkit... nothing found Searching for Volc rootkit... nothing found Searching for Gold2 rootkit... nothing found Searching for TC2 Worm default files and dirs... nothing found Searching for Anonoying rootkit default files and dirs... nothing found Searching for ZK rootkit default files and dirs... nothing found Searching for ShKit rootkit default files and dirs... nothing found Searching for AjaKit rootkit default files and dirs... nothing found Searching for zaRwT rootkit default files and dirs... nothing found Searching for Madalin rootkit default files... nothing found Searching for Fu rootkit default files... nothing found Searching for ESRK rootkit default files... nothing found Searching for anomalies in shell history files... nothing found Checking `asp'... not infected Checking `bindshell'... INFECTED (PORTS: 465) Checking `lkm'... chkproc: nothing detected Checking `rexedcs'... not found Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets eth1: not promisc and no PF_PACKET sockets Checking `w55808'... not infected Checking `wted'... chkwtmp: nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... chklastlog: nothing deleted Checking `chkutmp'... chkutmp: nothing deleted ٤Ƥ ROOTDIR is `/' ܤ ROOTDIR / ۲٤ƤоݤȤƤȤ̣Ǥ Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected ܰʹߤ Checking ϼʥƥեǤ"not found"ȤΤϥե뤬ޤ"not infected" ȤǤƤв⤵ƤǽϤʤȤޤ ʤߤ˲⤵ƤȡΥեФƤ "INFECTED" ɽޤ Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found ³ Searching ³ƤΤϥ롼ȥåȤȤ߹ޤƤʤθФǤ"nothing found" ȤǤƤΤǤFOUND Ȥʤä顢ŹޤƤǽ˹⤤Ǥ Searching for suspicious files and dirs, it may take a while... Ǥϥե̾Ƭ . ĤƤơȻפեΰɽޤƥबѤΤǤϤޤʤե뤬ƤդǤ Checking `asp'... not infected Checking `bindshell'... INFECTED (PORTS: 465) äȡ bindshell INFECTED ȤǤƤޤޤܤϤ狼ʤΤǤ bindshell Ȥġ˥ݡ 465 Ȥ褦ʤΤäߤǤ͡ޡ夤ƥݡ 465 ǧޤ礦 # /usr/sbin/lsof -i tcp:465 COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME sendmail 1996 root 6u IPv4 5783 TCP *:smtps (LISTEN) ݡȤγǧ lsof ޥɤǤϤߤƤ̤ sendmail Submission Port(ѤΥ֥ߥåݡ)Ȥ smtps ̿ѤѤƤΤǤ顢ꤢޤ Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets eth1: not promisc and no PF_PACKET sockets Checking `w55808'... not infected Checking `wted'... chkwtmp: nothing deleted Checking `scalper'... not infected Checking `slapper'... not infected Checking `z2'... chklastlog: nothing deleted Checking `chkutmp'... chkutmp: nothing deleted Ǹϥͥåȥǽʾ֤ǤϤʤ(PROMICUS ⡼ɤɤˤγǧ utmp Ȥäβ⤬ߤʤåƤޤ ʤߤˡ Vine 2.1.5(빽ŤǤФǤ) ĶdzǧƤޤps ޥɤΰΥХǼΤ褦ʷٹ𤬤ǤƤޤ褦Ǥ OooPS! chkproc: Warning: Possible LKM Trojan installed Ȥꤢ¹ԤƤߤơƥ˰۾郎ʤ褦ʤ¿Ǥ⤷ INFECTED installed ȤǤ顢Ƥ˥ƥեդ md5sum ޥɤˤåӤꤷǧʤ®䤫˥ͥåȥڤΥн褹뤳Ȥˤʤޤ chkrootkit μ¹ԥץ †
# ./chkrootkit -h Usage: ./chkrootkit [options] [test ...] Options: -h show this help and exit -V show version information and exit -l show available tests and exit -d debug -q quiet mode -x expert mode -r dir use dir as the root directory -p dir1:dir2:dirN path for the external commands used by chkrootkit -n skip NFS mounted dirs
chkrootkit Ūʼ¹ԤǴƻ †äʥġʤΤǡư¹Ԥ褦ȤȤΤޤ礦cron Ǽ¹Ԥ뤿ΥץȤޤȤƤ chkrootkit ѥ뤵줿ĶȤΥǥ쥯ȥȼ¹ԤʤƤϤʤȤȤǤפ make ȤǼ¹ԡȤ̣Ǥ Ǥ /usr/local chkrootkit Υԡ֤褦ˤҤޤ ʤ /usr/local/chkrootkit-0.45 ŸΤȤޤ ޤΥܥå /usr/local/chkrootkit ˤϤޤƤΤϡ chkrootkit ΥСѤ뤳ȤäƤ⡢ѹ¾Υץȷˤϼäʤ褦ˤ뤿Ǥ # ln -s /usr/local/src/chkrootkit-0.45 /usr/local/chkrootkit ˥ץȥեޤ # vi /usr/local/bin/chkrootkit.sh եȤϼΤ褦ʤΤǤ #!/bin/sh cd /usr/local/chkrootkit ./chkrootkit | mail -s "[chkrootkit] HOSTNAME `date +%Y-%m-%d`" admin@example.jp Τ褦˵ҤƤHOSTNAME ϼʬΥۥ̾ admin@example.jp ϼʬʤ뤤ϥдԡˤΥ륢ɥ쥹Ҥޤ ۾郎ǤȤåФȤϰʲΤ褦ʥץĤۤɤǤ礦 ./chkrootkit -q | mail -s "[chkrootkit] HOSTNAME `date +%Y-%m-%d`" admin@example.jp ˼¹Ը¤Ϳޤ # chmod +x /usr/local/bin/chkrootkit.sh cron ؤϿǤ # crontab -e ȼ¹Ԥޤvi cron Խ̤ˤʤޤΤǡ 00 01 * * * /usr/local/bin/chkrootkit.sh > /dev/null 2>&1 εǤϡ chkrootkit.sh (ۤɵҤץ) ¹Ԥơ admin@example.jp ̾[chkrootkit] HOSTNAME 2005-07-20١ʺǴǯˤȤΤǤ̾ʬɬפ˱Ŭ˽ƻȤäƤߤƤ ʳǻ˥ץȤ¹ԤƤߤȡ뤬ϤϤǤ # /usr/local/bin/chkrootkit.sh Ȥϡڤåơ۾郎ʤǧ褦˽ŤƤȤɤǤ礦 chkrootkit Ϣܸɥ † |