在 CentOS(或其他 Linux 系统)上发现 exploit(漏洞利用/入侵) 时,应按“止血 → 取证 → 排查 → 清除 → 恢复 → 加固”的流程做应急响应。下面给你一套可直接照做的操作清单。
# 如果有外网
iptables -I INPUT -p tcp --dport 22 -j DROP # 谨慎,别把自己踢了
# 或直接断网(云服务器:安全组禁公网)
⚠️ 除非必须,不要立即重启(会丢失内存证据)
date
who
w
last
netstat -antup
ss -antup
ps auxf
top -c
ps -eo pid,ppid,user,comm,etime,args | sort -k5
重点看:
cat /etc/passwd
cat /etc/shadow
awk -F: '$3==0 {print}' /etc/passwd
cat /etc/sudoers
ls -la ~/.ssh/
cat ~/.ssh/authorized_keys
systemctl list-unit-files | grep enabled
crontab -l
ls -la /etc/cron*
cat /etc/rc.local
ls -la /tmp /var/tmp /dev/shm
find / -perm -4000 -type f 2>/dev/null # SUID后门
/var/log/secure
/var/log/messages
/var/log/audit/audit.log
journalctl -xe
重点看:
rpm -qa | grep -E "kernel|openssl|sudo|polkit"
kill -9 <pid>
rm -rf /path/to/malware
yum update -y
CentOS 7 已 EOL(2024-06-30)
建议迁移到:
请直接告诉我:
我可以给你针对性的一步一步命令。