>> Read Reply from No. 27368 article  
RE: [질문] 해킹을 당한건지 아닌지 이상하게 변했어
요...

등록 2001-04-16 11:52:00     조회 2
이름 차주현    

		거의 확실 하네요.
 그것도 참 엉망으로 만들어 놨군요. 그래도 tripwire 라도 있었으니 다행이군요.
  : 안녕하세요
: 저는 얼마전에 래드헷 7.0을 구해서 설치를 했는데
: 근데 오늘 아침에 와 보니까 이상하게 시스템이
: 변해 있어서 연락을 드렸습니다.
:
: 다름이 아니라 시스템의 변화를 알수 있게끔 tripwire 를 설치하고 있는데
: 이러한 메세지가 있어서 글을 적었습니다.
:
: 이것이 해킹에 의한건지 아닌지 궁금해서요.
: 정말 해킹을 당한 건가요?
:
: 제가 해킹을 당했다고 생각하는 부분은
: hosts.allow 와 hosts.deny 가 삭제되어 있어서 해킹이라고 보는데
: 고수님들의 생각은 어떠신지...
:
: -------------------------------------------------
:
: tripwire 내용
:
:
:
: Rule Name                       Severity Level    Added    Removed  Modified
:   ---------                       --------------    -----    -------  --------
:   Invariant Directories           66                0        0        0       
:   Temporary directories           33                0        0        0       
:   Tripwire Data Files             100               0        0        0       
:   Critical devices                100               0        0        0       
: * User binaries                   66                5        0        8       
:   Tripwire Binaries               100               0        0        0       
: * Critical configuration files    100               0        2        3       
:   Libraries                       66                0        0        0       
:   Shell Binaries                  100               0        0        0       
: * File System and Disk Administraton Programs
:                                   100               0        0        9       
:   Kernel Administration Programs  100               0        0        0       
: * Networking Programs             100               0        0        1       
:   System Administration Programs  100               0        0        0       
:   Hardware and Device Control Programs
:                                   100               0        0        0       
:   System Information Programs     100               0        0        0       
:   Application Information Programs
:                                   100               0        0        0       
:   Shell Releated Programs         100               0        0        0       
:   Critical Utility Sym-Links      100               0        0        0       
:   Critical system boot files      100               0        0        0       
: * System boot changes             100               51       0        35     
: * OS executables and libraries    100               1        0        1       
:   Security Control                100               0        0        0       
:   Login Scripts                   100               0        0        0       
: * Operating System Utilities      100               0        0        5       
: * Root config files               100               7        0        4       
:
: Total objects scanned:  20373
: Total violations found:  132
:
: ===============================================================================
: Object Summary:
: ===============================================================================
:
: -------------------------------------------------------------------------------
: # Section: Unix File System
: -------------------------------------------------------------------------------
:
: -------------------------------------------------------------------------------
: Rule Name: User binaries (/usr/sbin)
: Severity Level: 66
: -------------------------------------------------------------------------------
:
: Added:
: "/usr/sbin/telnetd"
: "/usr/sbin/in.smbd"
: "/usr/sbin/in.inetd"
: "/usr/sbin/fixdate"
:
: -------------------------------------------------------------------------------
: Rule Name: User binaries (/usr/bin)
: Severity Level: 66
: -------------------------------------------------------------------------------
:
: Added:
: "/usr/bin/nmap"
:
: Modified:
: "/usr/bin/at"
: "/usr/bin/dir"
: "/usr/bin/du"
: "/usr/bin/find"
: "/usr/bin/mkfifo"
: "/usr/bin/oldps"
: "/usr/bin/top"
: "/usr/bin/vdir"
:
: -------------------------------------------------------------------------------
: Rule Name: Networking Programs (/sbin/ifconfig)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/sbin/ifconfig"
:
: -------------------------------------------------------------------------------
: Rule Name: System boot changes (/var/log)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/var/log/boot.log"
: "/var/log/boot.log.1"
: "/var/log/boot.log.2"
: "/var/log/boot.log.3"
: "/var/log/boot.log.4"
: "/var/log/cron"
: "/var/log/cron.1"
: "/var/log/cron.2"
: "/var/log/cron.3"
: "/var/log/cron.4"
: "/var/log/maillog"
: "/var/log/maillog.1"
: "/var/log/maillog.2"
: "/var/log/maillog.3"
: "/var/log/maillog.4"
: "/var/log/messages"
: "/var/log/messages.1"
: "/var/log/messages.2"
: "/var/log/messages.3"
: "/var/log/messages.4"
: "/var/log/secure"
: "/var/log/secure.1"
: "/var/log/secure.2"
: "/var/log/secure.3"
: "/var/log/secure.4"
: "/var/log/spooler"
: "/var/log/spooler.1"
: "/var/log/spooler.2"
: "/var/log/spooler.3"
: "/var/log/spooler.4"
: "/var/log/xferlog"
: "/var/log/xferlog.1"
: "/var/log/xferlog.2"
: "/var/log/xferlog.3"
: "/var/log/xferlog.4"
:
: -------------------------------------------------------------------------------
: Rule Name: System boot changes (/var/lock/subsys)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Added:
: "/var/lock/subsys/...datafile..."
: "/var/lock/subsys/...datafile.../...datafile..."
: "/var/lock/subsys/...datafile.../...datafile.../usr"
: "/var/lock/subsys/...datafile.../...datafile.../usr/sbin"
: "/var/lock/subsys/...datafile.../...datafile.../usr/sbin/in.telnetd"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/find"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/lsattr"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/dir"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/du"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/mkfifo"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/vdir"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/oldps"
: "/var/lock/subsys/...datafile.../...datafile.../usr/bin/top"
: "/var/lock/subsys/...datafile.../...datafile.../lib"
: "/var/lock/subsys/...datafile.../...datafile.../lib/security"
: "/var/lock/subsys/...datafile.../...datafile.../lib/security/pam_pwdb.so"
: "/var/lock/subsys/...datafile.../...datafile.../bin"
: "/var/lock/subsys/...datafile.../...datafile.../bin/touch"
: "/var/lock/subsys/...datafile.../...datafile.../bin/mkdir"
: "/var/lock/subsys/...datafile.../...datafile.../bin/mknod"
: "/var/lock/subsys/...datafile.../...datafile.../bin/rm"
: "/var/lock/subsys/...datafile.../...datafile.../bin/rmdir"
: "/var/lock/subsys/...datafile.../...datafile.../bin/chgrp"
: "/var/lock/subsys/...datafile.../...datafile.../bin/chmod"
: "/var/lock/subsys/...datafile.../...datafile.../bin/chown"
: "/var/lock/subsys/...datafile.../...datafile.../bin/cp"
: "/var/lock/subsys/...datafile.../...datafile.../bin/ifconfig"
: "/var/lock/subsys/...datafile.../...datafile.../bin/ln"
: "/var/lock/subsys/...datafile.../...datafile.../bin/ls"
: "/var/lock/subsys/...datafile.../...datafile.../bin/mv"
: "/var/lock/subsys/...datafile.../...datafile.../bin/netstat"
: "/var/lock/subsys/...datafile.../...datafile.../bin/ps"
: "/var/lock/subsys/...datafile.../...datafile.../info"
: "/var/lock/subsys/...datafile.../...datafile.../out"
: "/var/lock/subsys/...datafile.../...datafile.../ns"
: "/var/lock/subsys/...datafile.../...datafile.../in.smbd.log"
: "/var/lock/subsys/...datafile.../...datafile.../typescript"
: "/var/lock/subsys/...datafile.../...datafile.../ohhara.tar.gz"
: "/var/lock/subsys/...datafile.../...datafile.../tt"
: "/var/lock/subsys/...datafile.../...datafile.../st"
: "/var/lock/subsys/...datafile.../...datafile.../n2"
: "/var/lock/subsys/...datafile.../...datafile.../tt.c"
: "/var/lock/subsys/...datafile.../...datafile.../info.c"
: "/var/lock/subsys/...datafile.../...net..."
: "/var/lock/subsys/...datafile.../...port..."
: "/var/lock/subsys/...datafile.../...ps..."
: "/var/lock/subsys/...datafile.../...file..."
: "/var/lock/subsys/...datafile.../out"
: "/var/lock/subsys/...datafile.../ns"
:
: -------------------------------------------------------------------------------
: Rule Name: System boot changes (/var/run)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Added:
: "/var/run/ftp.pids-remote"
:
: -------------------------------------------------------------------------------
: Rule Name: OS executables and libraries (/lib)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Added:
: "/lib/libproc.so.2.0.0"
:
: Modified:
: "/lib/security/pam_pwdb.so"
:
: -------------------------------------------------------------------------------
: Rule Name: Critical configuration files (/etc/hosts.allow)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Removed:
: "/etc/hosts.allow"
:
: -------------------------------------------------------------------------------
: Rule Name: Critical configuration files (/etc/hosts.deny)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Removed:
: "/etc/hosts.deny"
:
: -------------------------------------------------------------------------------
: Rule Name: Critical configuration files (/etc/rc.d)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/etc/rc.d/rc.local"
:
: -------------------------------------------------------------------------------
: Rule Name: Critical configuration files (/etc/passwd)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/etc/passwd"
:
: -------------------------------------------------------------------------------
: Rule Name: Critical configuration files (/etc/sysconfig)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/etc/sysconfig/hwconf"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/touch)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/touch"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/mkdir)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/mkdir"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/mknod)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/mknod"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/rm)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/rm"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/rmdir)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/rmdir"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/chgrp)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/chgrp"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/chmod)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/chmod"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/chown)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/chown"
:
: -------------------------------------------------------------------------------
: Rule Name: File System and Disk Administraton Programs (/bin/cp)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/cp"
:
: -------------------------------------------------------------------------------
: Rule Name: Operating System Utilities (/bin/ln)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/ln"
:
: -------------------------------------------------------------------------------
: Rule Name: Operating System Utilities (/bin/ls)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/ls"
:
: -------------------------------------------------------------------------------
: Rule Name: Operating System Utilities (/bin/mv)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/mv"
:
: -------------------------------------------------------------------------------
: Rule Name: Operating System Utilities (/bin/netstat)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/netstat"
:
: -------------------------------------------------------------------------------
: Rule Name: Operating System Utilities (/bin/ps)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Modified:
: "/bin/ps"
:
: -------------------------------------------------------------------------------
: Rule Name: Root config files (/root)
: Severity Level:100
: -------------------------------------------------------------------------------
:
: Added:
: "/root/.ncftp"
: "/root/.ncftp/log"
: "/root/.ncftp/firewall"
: "/root/.ncftp/history"
: "/root/.ncftp/trace"
: "/root/.ncftp/init_v3"
: "/root/.ncftp/prefs_v3"
:
: Modified:
: "/root/.cedit/cooledit.block"
: "/root/.cedit/cooledit.error"
: "/root/.cedit/cooledit.temp"
: "/root/.mysql_history"--return true
이름
암호


>> 관련글
27368 [질문] 해킹을 당한건지 아닌지 이상하게 변했어요...  이영동  2001.04.16  ....
  답장 RE: [질문] 해킹을 당한건지 아닌지 이상하게 변했어요...  차주현  2001.04.16  ....
Register [ localhost 목록보기 윗글 아랫글
글쓰기
답장쓰기 수정 삭제
정규표현식 [ 상세 검색 ]
페이지로딩: [ 4.81 초 ] 작업시간: [ 1.09 초 ]

Copyleft 1999-2026 by JSBoard Open Project
Theme Designed by IDOO All right reserved
[TOP]

적수네 동네
+
| 적수네 동네
| 공부방
| 리눅스 잡지 서고
| LSN 소스
| 링크 모음
+---+
게시판
+
| 떠들어보세!
| 질문과 답변
| 새소식과 정보
| 1원짜리 팁?
| 대화방
+---+
칼럼?
+
| 세하 훔쳐보기
| Welcome2nite
| 혜진의 염장판
+---+
리눅스 상표권
+
| 반대 서명란
| 토론 게시판
+---+
GNU
+
| GNU 선언문
| GNU GPL
| GNU 미러 목록
+---+
프로젝트?
+
| 리눅스카운터
| RC5DES
| 실질헌법 제작
+---+
커널 소식
+
| 안정 버젼: 2.4.14
+---+
테마 선택
+
LSN 방송국?
+
| OFF AIR
+---+
회원
+
| 로그인
+---+
[ 적수네 동네 ] [ 리눅스 상표권 독점 반대 ] [ 한글 리눅스 문서 프로젝트 ] [ KrLine ] [ 사랑넷 ] [ Valid HTML 4.0! ] [ SlashDot ] [ Freshmeat ]
Copyleft (C) 1998-2001 Byeong-Chan Kim . License
TIME: 1789576686
System by WYZsoft, HDD by I.O.Linux, Mizi Research, Embryo, WOWLINUX, Domain by SarangNet, Network by KrLine.