在 Linux 下用 strings 查找“后门”或可疑程序,是一个辅助分析手段,不能单独作为结论。下面给你一条实战可用的思路,从“找什么”到“怎么看”。
strings 用来从二进制文件(ELF、脚本、库、内存镜像)中提取可读字符串,常能看到:
/bin/sh, system, exec)/tmp/.x, /dev/shm)strings /path/to/file
strings -n 6 file # 只显示长度>=6的字符串
strings -a file # 扫描整个文件(包括数据段)
strings -e l file # 16位小端(某些样本有用)
strings file | grep -E "([0-9]{1,3}\.){3}[0-9]{1,3}"
strings file | grep -E "https?://"
strings file | grep -i "port"
看是否有:
strings file | grep -E "/bin/sh|/bin/bash|system|exec|popen"
典型后门特征:
/bin/sh -i
bash -i >& /dev/tcp/
system("/bin/sh")
strings file | grep -E "/tmp|/dev/shm|/var/|/\."
例如:
/tmp/.sshd
/var/run/.lock
strings file | grep -iE "password|passwd|secret|key|auth"
strings file | grep -E "\-\-|\-p|\-s|\-c"
有些后门靠参数激活:
./prog --backdoor
./prog -s hidden
ps aux | grep -E "tmp|sh|bash"
ls -la /proc/<pid>/exe
strings /proc/<pid>/exe
strings /etc/init.d/*
strings /etc/rc.local
which ps
strings /bin/ps | grep -i backdoor
strings 只是第一步,建议配合:
file file
ldd file
strace -f ./file
ltrace ./file
以及:
rkhunterchkrootkitclamav✅ strings 不会执行文件
❌ 不要直接运行可疑文件
✅ 最好在 隔离环境 / 虚拟机
如果你愿意,可以:
我可以帮你直接判断是不是后门。