下面给你一套在 Debian 上排查 exploit / 入侵的实战流程,从“快速判断是否中招”到“深度取证”,适合服务器或工作站。
who
w
last
lastlog
重点看:
ss -antup
netstat -antup # 若无 ss
关注:
top
ps auxf
重点:
[kworker]、sshd 伪装)/tmp、/dev/shm、/var/tmpcat /etc/passwd
cat /etc/shadow
异常特征:
/bin/bash 的异常用户cat /etc/sudoers
ls -l /etc/sudoers.d/
crontab -l
ls -l /etc/cron*
cat /etc/crontab
重点:
/tmp、.sh、.py 定时执行systemctl list-unit-files --type=service
ls -l /etc/init.d/
find / -mtime -7 -type f 2>/dev/null
重点目录:
/bin, /sbin, /usr/bin, /usr/sbin/etc/tmp, /var/tmpdpkg -V
或:
debsums -c
uname -a
cat /etc/os-release
对照:
lsmod
可疑:
dmesg | tail -50
journalctl -xe
关注:
cat /var/log/auth.log
重点:
cat /var/log/syslog
如:
/var/log/nginx/
/var/log/apache2/
/var/log/mysql/
apt install chkrootkit rkhunter
chkrootkit
rkhunter --check
apt install clamav
freshclam
clamscan -r / --bell
lsof -p <pid>
strace -p <pid>
不要只删文件,建议:
apt update && apt upgrade如果你愿意,可以告诉我:
我可以帮你针对性分析 exploit 类型。