음.. 이 글 2번째 쓰네용.. 이제 안써야쥐`~ 헤헤.. ^.^;;
----------------------------------------------------------------
http://whitehats.com/library/worms/ramen/index.html 에서 퍼왔습니다..
저두 걸려서 -.-a
근데, 망가진 index.html 은 어찌할수가 없네요..
흑흑.. -.-;
열시미 복구하세용~~
Incident Recovery
Once your computer has been compromised by the ramen worm, you will need to clean up several trouble spots to restore t
he system. If you want to allow anonymous FTP, then remove "ftp" and "anonymous" from /etc/ftpusers
If you use wu-ftpd in particular, then upgrade to the latest version from the redhat errata web site
If you use NFS then upgrade to the latest version from the redhat errata web site
If you use LPRng then upgrade to the latest version from the redhat errata web site
Remove "/usr/src/.poop/start*.sh" from /etc/rc.d/rc.sysinit
Delete the /usr/src/.poop directory containing worm files
Delete /tmp/ramen.tgz
Delete /sbin/asp
Redhat 6.2: Remove "asp stream tcp nowait root" from /etc/inetd.conf
Redhat 7.0: Delete /etc/xinetd.d/asp
Restore /etc/hosts.deny unless you didn't use tcp wrappers
Restore any replaced index.html files with originals from backup
Reboot the system to kill active worm daemons
When the computer is distracted by the reboot, see if you can sneak an OpenBSD boot floppy in! If you succeed, then cong
ratulations, you are well on your way to reducing embarassment of being rooted by a wet noodle.
: 요점 한청 날뛰고 잇는 리눅스전용 웜인 라면 웜이 당했어여... ㅠ.ㅠ
:
: 이거 어떻하면 되죠?
:
: (안철수 연구소에 가면 글이 있으니 한번 보시죠... )
:
: 제가 쓰고 있는 리눅스는 아델리눅스인데....
:
: 레드햇의 헛점을 뚫고 들어 간다드만... 걍 당했네여...--메룽~~ 서명 ^.^;