温馨提示×

如何用linux strings查后门

小樊
37
2026-10-08 09:22:35
栏目: 智能运维

在 Linux 下用 strings 查找“后门”或可疑程序,是一个辅助分析手段,不能单独作为结论。下面给你一条实战可用的思路,从“找什么”到“怎么看”。


一、strings 能干什么

strings 用来从二进制文件(ELF、脚本、库、内存镜像)中提取可读字符串,常能看到:

  • 连接的 IP / 域名
  • 端口号
  • 命令执行(/bin/sh, system, exec)
  • 加密密钥、密码
  • 隐藏参数、暗号
  • 可疑路径(/tmp/.x, /dev/shm)

二、基本用法

strings /path/to/file

常用参数

strings -n 6 file        # 只显示长度>=6的字符串
strings -a file          # 扫描整个文件(包括数据段)
strings -e l file        # 16位小端(某些样本有用)

三、查后门常用套路

1️⃣ 查对外连接(C2 / 反弹 shell)

strings file | grep -E "([0-9]{1,3}\.){3}[0-9]{1,3}"
strings file | grep -E "https?://"
strings file | grep -i "port"

看是否有:

  • 固定 IP
  • 域名
  • 非常规端口(4444、1337、6666)

2️⃣ 查 shell / 命令执行

strings file | grep -E "/bin/sh|/bin/bash|system|exec|popen"

典型后门特征:

/bin/sh -i
bash -i >& /dev/tcp/
system("/bin/sh")

3️⃣ 查隐藏路径

strings file | grep -E "/tmp|/dev/shm|/var/|/\."

例如:

/tmp/.sshd
/var/run/.lock

4️⃣ 查密码 / 暗号

strings file | grep -iE "password|passwd|secret|key|auth"

5️⃣ 查可疑参数(Rootkit / 后门开关)

strings file | grep -E "\-\-|\-p|\-s|\-c"

有些后门靠参数激活:

./prog --backdoor
./prog -s hidden

四、结合进程 / 文件实战

1️⃣ 查正在运行的进程

ps aux | grep -E "tmp|sh|bash"
ls -la /proc/<pid>/exe
strings /proc/<pid>/exe

2️⃣ 查开机启动

strings /etc/init.d/*
strings /etc/rc.local

3️⃣ 查系统命令是否被替换

which ps
strings /bin/ps | grep -i backdoor

五、进阶(更准)

strings 只是第一步,建议配合:

file file
ldd file
strace -f ./file
ltrace ./file

以及:

  • rkhunter
  • chkrootkit
  • clamav

六、重要提醒(安全)

✅ strings 不会执行文件
❌ 不要直接运行可疑文件
✅ 最好在 隔离环境 / 虚拟机


如果你愿意,可以:

  • 发一个 样本路径
  • 或贴一段 strings 输出

我可以帮你直接判断是不是后门。

0 踩