HOME   ·Î±×ÀΠ  ȸ¿ø°¡ÀÔ
    
ȸ¿ø°¡ÀÔ
ºñ¹Ð¹øÈ£ ã±â ÀÚµ¿·Î±ä
ÀÌÀü°Ô½ÃÆÇ
   free_board
   °Ç°­°Ô½ÃÆÇ
   ¿À¶óŬDB
   Linux
   HTML/javascript
   Áú¹®°ú ´ä
È£¼­±â
   À̹ÌÁö°Ô½ÃÆÇ  
   °Ç°­°Ô½ÃÆÇ  
   À½¾ÇÀÚ·á  
   ¼ºÁØÀÌ °Ô½ÃÆÇ  
 Hit : 5022
 À̸§ : È£¼®  (211.¢½.74.31)
 ³¯Â¥ : 2006-06-13 17:39:23
 Á¦¸ñ : [º¸¾È] rkhunter ·Î ·çƮŶÀ» È®ÀÎÇÑ´Ù.
wget http://downloads.rootkit.nl/rkhunter-1.2.1.tar.gz ´Ù¿î ¹Þ´Â´Ù

 ./install.sh  ½ÇÇàÇÑ´Ù.

 rkhunter -c  üũÇÑ´Ù.

 ³¡




http://blog.naver.com/realnaut/120018264227
 
 
¾È³çÇϼ¼¿ä.
http://www.rootman.co.kr ¿î¿µÀÚ Á¤ÂùÈ£ÀÔ´Ï´Ù.

rkhunter´Â rootkitÀ» ã¾Æ ÁÖ´Â À¯Æ¿¸®Æ¼·Î ¼³Ä¡µµ °£´ÜÇÏ°í º¸´Â ¹ýµµ °£´ÜÇÕ´Ï´Ù.
¶ÇÇÑ Áß¿ä ÆÄÀÏ¿¡ ´ëÇÑ À§, º¯Á¶¸¦ ¾Ë·Á ÁÖ¾î °ü¸®ÀÚ·Î ÇÏ¿©±Ý ¾à°£ ¾Èµµ°¨À» ÁÖ´Â^^ ÇÁ·Î±×·¥ÀÌÁÒ.

Ȥ½Ã ¸ð¸£¼Ì´ø ºÐµé ÇÑ ¹ø ½á º¸¼¼¿ä.
µµ¿òÀÌ ²À µÇ½Ã±æ ¹Ù¶ó¸é¼­.

Have a good time !


1. °ü·Ã»çÀÌÆ®
   http://www.rootkit.nl/projects/rootkit_hunter.html


2. ¼Ò½º ´Ù¿î·Îµå
   (1) http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz
   (2) http://mirror.1day.co.kr/download/Security/rkhunter-1.2.7.tar.tar


3. ¼³Ä¡
[root@ns1 /usr/local/src]# tar xvfz rkhunter-1.2.7.tar.tar
[root@ns1 /usr/local/src]# cd rkhunter-1.2.7
[root@ns1 rkhunter-1.2.7]# ./installer.sh
Rootkit Hunter installer 1.2.7 (Copyright 2003-2005, Michael Boelen)
---------------
Starting installation/update

Checking  /usr/local... OK
Checking file retrieval tools... /usr/bin/wget
Checking installation directories...
- Checking /usr/local/rkhunter...Created
- Checking /usr/local/rkhunter/etc...Created
- Checking /usr/local/rkhunter/bin...Created
- Checking /usr/local/rkhunter/lib/rkhunter/db...Created
- Checking /usr/local/rkhunter/lib/rkhunter/docs...Created
- Checking /usr/local/rkhunter/lib/rkhunter/scripts...Created
- Checking /usr/local/rkhunter/lib/rkhunter/tmp...Created
- Checking /usr/local/etc...Exists
- Checking /usr/local/bin...Exists
Checking system settings...
    - Perl... OK
Installing files...
Installing  Perl module checker... OK
Installing  Database updater... OK
Installing  Portscanner... OK
Installing  MD5 Digest generator... OK
Installing  SHA1 Digest generator... OK
Installing  Directory viewer... OK
Installing  Database Backdoor ports... OK
Installing  Database Update mirrors... OK
Installing  Database Operating Systems... OK
Installing  Database Program versions... OK
Installing  Database Program versions... OK
Installing  Database Default file hashes... OK
Installing  Database MD5 blacklisted files... OK
Installing  Changelog... OK
Installing  Readme and FAQ... OK
Installing  Wishlist and TODO... OK
Installing  RK Hunter configuration file... OK
Installing  RK Hunter binary... OK
Configuration updated with installation path (/usr/local/rkhunter)

Installation ready.
See /usr/local/rkhunter/lib/rkhunter/docs for more information. Run 'rkhunter' (/usr/local/bin/rkhunter)


4. ½ÇÇà ÆÄÀÏ º¹»ç
[root@ns1 rkhunter-1.2.7]# cp rkhunter /usr/sbin/


5. ½Ã½ºÅÛ °Ë»çÇϱâ
(1) °Ë»ç ·¹Æ÷Æ® crt Ãâ·Â
[root@ns1 rkhunter-1.2.7]# rkhunter -c

(2) °Ë»ç ÆÄÀÏ ÀúÀåÇϱâ
[root@ns1 rkhunter-1.2.7]# rkhunter --checkall --createlogfile
....
....
---------------------------- Scan results ----------------------------
MD5
MD5 compared: 0
Incorrect MD5 checksums: 0

File scan
Scanned files: 342
Possible infected files: 0

Application scan
Vulnerable applications: 3

Scanning took 365 seconds
Scan results written to logfile (/var/log/rkhunter.log)


6. ¹öÀü È®ÀÎÇϱâ
[root@ns1 rkhunter-1.2.7]# /usr/local/bin/rkhunter --versioncheck
http://www.rootkit.nl/rkhunter/rkhunter_latest.dat

Rootkit Hunter 1.2.3, copyright Michael Boelen

This version:   1.2.3
Latest version: 1.2.7
Update available


7. rkhunter ¾÷µ¥ÀÌÆ®Çϱâ
[root@ns1 root]# /usr/local/bin/rkhunter --update     
Running updater...

Mirrorfile /usr/local/rkhunter/lib/rkhunter/db/mirrors.dat rotated
Using mirror http://www.rootkit.nl/rkhunter
[DB] Mirror file                      : Update available
  Action: Database updated (current version: 2005033000, new version 2005050700)
[DB] MD5 hashes system binaries       : Update available
  Action: Database updated (current version: 2005041000, new version 2005080200)
[DB] Operating System information     : Update available
  Action: Database updated (current version: 2005032500, new version 2005091100)
[DB] MD5 blacklisted tools/binaries   : Up to date
[DB] Known good program versions      : Update available
  Action: Database updated (current version: 2005040300, new version 2005071500)
[DB] Known bad program versions       : Update available
  Action: Database updated (current version: 2005040300, new version 2005071500)

Ready.

- ÀÌ»ó -
°Ô½Ã¹° 121°Ç
¹øÈ£ ºÐ·ù Á¦¸ñ
À̸§
³¯Â¥ ÀÐÀ½
23 ÀÏ¹Ý   °í¼º´É ftp Ŭ¶óÀ̾ðÆ® sftp, http µî Áö¿ø È£¼® 06-03-17 5353
53 ÀÏ¹Ý   À¥¿¡¼­ ½Ã½ºÅÛÆÄÀÏ °ü¸®Çϱâ good (1) È£¼® 07-06-18 5353
24 ÀÏ¹Ý   SYN_RECV È£¼® 06-03-23 5338
57 ÀÏ¹Ý   raid ±¸ÃàÇϱâ È£¼® 07-07-03 5159
40 ÀÏ¹Ý   iptables ·Î °£´ÜÇÑ ¹æÈ­º®À» ±¸ÃàÇÏÀÚ (1) È£¼® 06-09-16 5108
63 ÀÏ¹Ý   ¡Ú¡Ú¡Ú¡Ú¡Ú ¾ÆÆÄÄ¡ ÅèÄÏÀÇ ¿¬µ¿ (2) È£¼® 08-01-22 5097
77 ÀÏ¹Ý   iptraf =>IP Æ®·¡ÇÈ, ÀÎÅÍÆäÀ̽º Åë°è, LAN station ¸ð´ÏÅ͵î È£¼® 08-11-10 5092
92 ÀÏ¹Ý   MRTG ¼³Ä¡ ¼Ö¶ó¸®½º È£¼® 09-04-12 5068
25 ÀÏ¹Ý   Rootkit Hunter´Â À¯´Ð½º ¹× ¸®´ª½º ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡ ·çƮŶÀ̳ª ¹éµµ¾îµîÀÇ ¼³Ä¡¿©¡¦ È£¼® 06-03-23 5059
¡æ ÀÏ¹Ý   [º¸¾È] rkhunter ·Î ·çƮŶÀ» È®ÀÎÇÑ´Ù. È£¼® 06-06-13 5023
31 ÀÏ¹Ý   [º¸¾È] º¸¾ÈÀýÂ÷¼­ ( ±âÃʺ¸¾È ) (1) È£¼® 06-04-19 5012
14 ÀÏ¹Ý      sar ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ ¸ð´ÏÅ͸µÇϱâ (1) È£¼® 07-10-09 5004
82 ÀÏ¹Ý   ¾ÆÆÄÄ¡ https ssl ·Î ¼³Ä¡Çϱâ È£¼® 09-01-14 5002
7 ÀÏ¹Ý   ¾ÆÆÄÄ¡ + ¸®´ª½º + ÅèÄÏ ¼³Ä¡ È£¼® 05-07-04 4998
64 ÀÏ¹Ý   ¸®´ª½º¿¡¼­ ¾ÆÆÄÄ¡ + ÀÚ¹Ù + ÅèÄÏ ¿¬µ¿Çϱâ (1) È£¼® 07-12-31 4998
óÀ½ÀÌÀü  [1] [2] [3] 4 [5] [6] [7] [8] [9]  ´ÙÀ½¸Ç³¡
 
Copyright © zenos.pe.kr. All rights reserved.