“CentOS exploit”通常指CentOS 系统被漏洞利用(入侵/被攻破),而不是某一条固定命令。修复思路是:先止血 → 查入侵 → 补漏洞 → 加固 → 验证。下面按实战步骤来。
# 断网或撤公网IP
# 云服务器:安全组禁止入站
tar czf /mnt/backup/centos_$(date +%F).tar.gz \
/var/log /etc /root /home /tmp
top
ps -ef | grep -E "mining|bash|python|perl|sh"
netstat -antup
cat /etc/centos-release
uname -a
| 类型 | 例子 |
|---|---|
| 内核漏洞 | Dirty COW (CVE-2016-5195) |
| 服务漏洞 | OpenSSH / Nginx / Redis / Samba |
| 弱口令 | root 暴力破解 |
| 提权 | 低权用户 → root |
last
lastb
cat /var/log/secure | grep Failed
journalctl -xe
ps -ef | grep 可疑进程
kill -9 PID
crontab -l
ls -la /etc/cron*
cat /var/spool/cron/*
systemctl list-unit-files | grep enabled
ls /etc/init.d/
cat /etc/passwd
awk -F: '$3==0 {print}' /etc/passwd
yum clean all
yum update -y
reboot # 内核更新必须重启
例如:
yum update kernel -y
yum update openssh -y
systemctl disable telnet
systemctl stop telnet
vi /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
firewall-cmd --permanent --add-port=22/tcp
firewall-cmd --reload
yum install epel-release -y
yum install fail2ban -y
yum-cron
如果:
✅ 直接重装系统 + 恢复备份数据 是最安全方案。
如果你能补充:
我可以给你针对性的一键排查命令。