在 CentOS 系统上发生 exploit(漏洞利用/入侵) 后的应急处置,核心目标是:止损 → 排查 → 清除 → 加固 → 溯源。下面给你一套可操作的应急流程(偏实战,适合服务器被攻破或怀疑被利用的场景)。
# 记录当前时间
date
# 锁定关键日志(只读)
chattr +a /var/log/messages
chattr +a /var/log/secure
top -c
ps -ef
ps aux --sort=-%cpu
重点看:
bash / sh / python / perlhttpd / nginx / redisnetstat -antup
ss -antup
异常:
ESTABLISHEDwho
w
last
lastlog
cat /var/log/secure | grep Failed
看是否有:
/etc/passwd/etc/shadowawk -F: '$3==0 {print}' /etc/passwd
常见被 exploit 的服务:
查看版本:
rpm -qa | grep -E "redis|nginx|httpd|openssl|sudo|polkit"
find /var/www -type f -name "*.php" -mtime -3
grep -R "eval(" /var/www
grep -R "base64_decode" /var/www
crontab -l
ls -la /etc/cron*
cat /etc/crontab
systemctl list-unit-files --type=service | grep enabled
ls -la /etc/systemd/system/
ls -la /
ls -la /tmp /dev/shm
rpm -Va # 检查系统文件被篡改
⚠️ 先备份证据再清理
kill -9 PID
userdel -r xxx
chattr -i /etc/passwd
chattr -i /etc/shadow
yum update -y
# 禁止 root 登录
PermitRootLogin no
# 改端口
Port 22222
# 仅密钥登录
PasswordAuthentication no
firewall-cmd --permanent --add-port=22222/tcp
firewall-cmd --reload
systemctl disable redis
如果你愿意,可以告诉我:
我可以直接帮你 定位入口 + 给精准清除命令。