网络与信息安全应急响应技术规范与指南 - 百度文库

2026/1/13 21:22:23

QB-XX-XXX-2004

ͨcoreļûзʲô. rootkit

ͨchkrootkit飬ûз쳣 ûļ ļ

ûз쳣

ϵͳսжԱ, ļǷı ʹlsofļͽ̹

49 ҳ 89 ҳ

QB-XX-XXX-2004

lsof | grep *: һбǣΪsendmailĽ,TCP2457˿ڣSendmailῪôߵĶ˿ڣ ⣬telnet localhost 2457

SSHˣ˸sendmail֣ȷΪֲװrootkitš ܽ᣺

ڻУûзġɼrootkit˶˿ںͽ(ͨ滻netstat psļ)rootkit.ʵøɾıϵͳһ֤

50 ҳ 89 ҳ

QB-XX-XXX-2004

ǴӦӦ̿netstatԿ2457˿ڼ ɼںģ

ͨնԱȼ⣬ûзʲô쳣 sendmailú ûз쳣

/usr/bin/loginͨնԱȼ⣬ļ滻 /usr/bin/suͨնԱȼ⣬ûзʲô쳣

51 ҳ 89 ҳ

QB-XX-XXX-2004

2.4 簲ȫ¼ⷽ 2.4.1 ܾ¼ⷽ

2.4.1.1 ϵͳ©ľܾ񹥻ⷽ

ͨòϵͳ©ܶϵͳоܾ񹥻ܹϵͳϵͳУCPUռʹߣڴռʹߵ ڴ๥ʽͨ·⣺

ʹԴSolarisʹps Caux鵱ǰڴ桢CPUԴռ ϵͳ̺ͿնԱȣҳǷ̣

ӺͿնԱȣҳɵӡ 2.4.1.2 Эľܾ񹥻ⷽ

ЭijЩԿܶϵͳܾ񹥻˵õSYN-FLOODTCPЭֵص㷢Ĺ

1) SYN-FLOODͨnetstat Can Windows/Unixϵͳ

ֵܷǰӵ״̬дڴSYN_RECEIVED״̬ϵͳܵSYN-FLOODܾ񹥻

2) ͨʹSNIFFERִӣЭķֲicmp

UDPЭݳ20%ϵͳܾܵ񹥻 2.4.2 ƭȫ¼ⷽ

2.4.2.1 DNSƭ淶

DNSƭֻҪarpƭͿˣԷμ2.4.3.2SNIFFER淶

μ2.4.3.2SNIFFER淶 2.4.2.2 WEBƭ淶

webƭֻҪarpƭͿˣԷμ2.4.3.2SNIFFER淶

μ2.4.3.2SNIFFER淶

52 ҳ 89 ҳ


网络与信息安全应急响应技术规范与指南 - 百度文库.doc ĵWordĵص
ڣ 网络与信息安全应急响应技术规范与指南 - ĵ
Ƽ
Ķ
οͿͨغɸƺŰ棩

رĵҪ֧ 10 Ԫ

֧ʽ

ͨVIP»Ա ؼۣ29Ԫ/

עĵпܡֻĿ¼ݲȫ֮ǰעѸ޷ػ⣬ϵЭ㴦
΢ţxuecool-com QQ370150219