Partage
  • Partager sur Facebook
  • Partager sur Twitter

compte piraté/analyse rootkit sous linux

    4 octobre 2016 à 18:22:38

    Bonjour, suite piratage de mes comptes, j ai fais une analyse rootkit. Qq'un est capable de l'analyser?

    -
    Edité par imostone 4 octobre 2016 à 18:23:59

    • Partager sur Facebook
    • Partager sur Twitter
    Anonyme
      4 octobre 2016 à 22:14:18

      @imostone Bonsoir,

      Pose ton log, sinon, personne ne pourras t'aider.

      • Partager sur Facebook
      • Partager sur Twitter
        18 octobre 2016 à 19:25:05

         Bonjour

        marc@marc-Inspiron-1545:~$ sudo rkhunter --checkall --report-warnings-only
        [sudo] Mot de passe de marc : 
        Warning: The file '/usr/sbin/sshd' does not exist on the system, but it is present in the 'rkhunter.dat' file.
        Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: a /usr/bin/perl -w script, ASCII text executable
        Warning: The SSH and rkhunter configuration options should be the same:
                 SSH configuration option 'PermitRootLogin': prohibit-password
                 Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
        Warning: Suspicious file types found in /dev:
                 /dev/shm/pulse-shm-373926045: data
                 /dev/shm/pulse-shm-993526091: data
                 /dev/shm/pulse-shm-1201614325: data
                 /dev/shm/pulse-shm-3151959120: data
                 /dev/shm/pulse-shm-2379779262: data
                 /dev/shm/pulse-shm-2232728287: data
                 /dev/shm/pulse-shm-21907826: data
                 /dev/shm/pulse-shm-4073403899: data
                 /dev/shm/pulse-shm-1414130538: data
                 /dev/shm/pulse-shm-3845534300: data
        marc@marc-Inspiron-1545:~$ rkhunter --update
        You must be the root user to run this program.
        marc@marc-Inspiron-1545:~$ sudo -i
        root@marc-Inspiron-1545:~# rkhunter -c
        [ Rootkit Hunter version 1.4.2 ]
        
        Checking system commands...
        
          Performing 'strings' command checks
            Checking 'strings' command                               [ OK ]
        
          Performing 'shared libraries' checks
            Checking for preloading variables                        [ None found ]
            Checking for preloaded libraries                         [ None found ]
            Checking LD_LIBRARY_PATH variable                        [ Not found ]
        
          Performing file properties checks
            Checking for prerequisites                               [ OK ]
            /usr/sbin/adduser                                        [ OK ]
            /usr/sbin/chroot                                         [ OK ]
            /usr/sbin/cron                                           [ OK ]
            /usr/sbin/groupadd                                       [ OK ]
            /usr/sbin/groupdel                                       [ OK ]
            /usr/sbin/groupmod                                       [ OK ]
            /usr/sbin/grpck                                          [ OK ]
            /usr/sbin/nologin                                        [ OK ]
            /usr/sbin/pwck                                           [ OK ]
            /usr/sbin/rsyslogd                                       [ OK ]
            /usr/sbin/sshd                                           [ Warning ]
            /usr/sbin/tcpd                                           [ OK ]
            /usr/sbin/useradd                                        [ OK ]
            /usr/sbin/userdel                                        [ OK ]
            /usr/sbin/usermod                                        [ OK ]
            /usr/sbin/vipw                                           [ OK ]
            /usr/sbin/unhide                                         [ OK ]
            /usr/sbin/unhide-linux                                   [ OK ]
            /usr/sbin/unhide-posix                                   [ OK ]
            /usr/sbin/unhide-tcp                                     [ OK ]
            /usr/bin/awk                                             [ OK ]
            /usr/bin/basename                                        [ OK ]
            /usr/bin/chattr                                          [ OK ]
            /usr/bin/curl                                            [ OK ]
            /usr/bin/cut                                             [ OK ]
            /usr/bin/diff                                            [ OK ]
            /usr/bin/dirname                                         [ OK ]
            /usr/bin/dpkg                                            [ OK ]
            /usr/bin/dpkg-query                                      [ OK ]
            /usr/bin/du                                              [ OK ]
            /usr/bin/env                                             [ OK ]
            /usr/bin/file                                            [ OK ]
            /usr/bin/find                                            [ OK ]
            /usr/bin/GET                                             [ OK ]
            /usr/bin/groups                                          [ OK ]
            /usr/bin/head                                            [ OK ]
            /usr/bin/id                                              [ OK ]
            /usr/bin/killall                                         [ OK ]
            /usr/bin/last                                            [ OK ]
            /usr/bin/lastlog                                         [ OK ]
            /usr/bin/ldd                                             [ OK ]
            /usr/bin/less                                            [ OK ]
            /usr/bin/locate                                          [ OK ]
            /usr/bin/logger                                          [ OK ]
            /usr/bin/lsattr                                          [ OK ]
            /usr/bin/lsof                                            [ OK ]
            /usr/bin/mail                                            [ OK ]
            /usr/bin/md5sum                                          [ OK ]
            /usr/bin/mlocate                                         [ OK ]
            /usr/bin/newgrp                                          [ OK ]
            /usr/bin/passwd                                          [ OK ]
            /usr/bin/perl                                            [ OK ]
            /usr/bin/pgrep                                           [ OK ]
            /usr/bin/pkill                                           [ OK ]
            /usr/bin/pstree                                          [ OK ]
            /usr/bin/rkhunter                                        [ OK ]
            /usr/bin/rpm                                             [ OK ]
            /usr/bin/runcon                                          [ OK ]
            /usr/bin/sha1sum                                         [ OK ]
            /usr/bin/sha224sum                                       [ OK ]
            /usr/bin/sha256sum                                       [ OK ]
            /usr/bin/sha384sum                                       [ OK ]
            /usr/bin/sha512sum                                       [ OK ]
            /usr/bin/size                                            [ OK ]
            /usr/bin/sort                                            [ OK ]
            /usr/bin/ssh                                             [ OK ]
            /usr/bin/stat                                            [ OK ]
            /usr/bin/strace                                          [ OK ]
            /usr/bin/strings                                         [ OK ]
            /usr/bin/sudo                                            [ OK ]
            /usr/bin/tail                                            [ OK ]
            /usr/bin/telnet                                          [ OK ]
            /usr/bin/test                                            [ OK ]
            /usr/bin/top                                             [ OK ]
            /usr/bin/touch                                           [ OK ]
            /usr/bin/tr                                              [ OK ]
            /usr/bin/uniq                                            [ OK ]
            /usr/bin/users                                           [ OK ]
            /usr/bin/vmstat                                          [ OK ]
            /usr/bin/w                                               [ OK ]
            /usr/bin/watch                                           [ OK ]
            /usr/bin/wc                                              [ OK ]
            /usr/bin/wget                                            [ OK ]
            /usr/bin/whatis                                          [ OK ]
            /usr/bin/whereis                                         [ OK ]
            /usr/bin/which                                           [ OK ]
            /usr/bin/who                                             [ OK ]
            /usr/bin/whoami                                          [ OK ]
            /usr/bin/mawk                                            [ OK ]
            /usr/bin/lwp-request                                     [ Warning ]
            /usr/bin/s-nail                                          [ OK ]
            /usr/bin/x86_64-linux-gnu-size                           [ OK ]
            /usr/bin/x86_64-linux-gnu-strings                        [ OK ]
            /usr/bin/telnet.netkit                                   [ OK ]
            /usr/bin/w.procps                                        [ OK ]
            /sbin/depmod                                             [ OK ]
            /sbin/fsck                                               [ OK ]
            /sbin/ifconfig                                           [ OK ]
            /sbin/ifdown                                             [ OK ]
            /sbin/ifup                                               [ OK ]
            /sbin/init                                               [ OK ]
            /sbin/insmod                                             [ OK ]
            /sbin/ip                                                 [ OK ]
            /sbin/lsmod                                              [ OK ]
            /sbin/modinfo                                            [ OK ]
            /sbin/modprobe                                           [ OK ]
            /sbin/rmmod                                              [ OK ]
            /sbin/route                                              [ OK ]
            /sbin/runlevel                                           [ OK ]
            /sbin/sulogin                                            [ OK ]
            /sbin/sysctl                                             [ OK ]
            /bin/bash                                                [ OK ]
            /bin/cat                                                 [ OK ]
            /bin/chmod                                               [ OK ]
            /bin/chown                                               [ OK ]
            /bin/cp                                                  [ OK ]
            /bin/date                                                [ OK ]
            /bin/df                                                  [ OK ]
            /bin/dmesg                                               [ OK ]
            /bin/echo                                                [ OK ]
            /bin/ed                                                  [ OK ]
            /bin/egrep                                               [ OK ]
            /bin/fgrep                                               [ OK ]
            /bin/fuser                                               [ OK ]
            /bin/grep                                                [ OK ]
            /bin/ip                                                  [ OK ]
            /bin/kill                                                [ OK ]
            /bin/less                                                [ OK ]
            /bin/login                                               [ OK ]
            /bin/ls                                                  [ OK ]
            /bin/lsmod                                               [ OK ]
            /bin/mktemp                                              [ OK ]
            /bin/more                                                [ OK ]
            /bin/mount                                               [ OK ]
            /bin/mv                                                  [ OK ]
            /bin/netstat                                             [ OK ]
            /bin/ping                                                [ OK ]
            /bin/ps                                                  [ OK ]
            /bin/pwd                                                 [ OK ]
            /bin/readlink                                            [ OK ]
            /bin/sed                                                 [ OK ]
            /bin/sh                                                  [ OK ]
            /bin/su                                                  [ OK ]
            /bin/touch                                               [ OK ]
            /bin/uname                                               [ OK ]
            /bin/which                                               [ OK ]
            /bin/kmod                                                [ OK ]
            /bin/systemd                                             [ OK ]
            /bin/systemctl                                           [ OK ]
            /bin/dash                                                [ OK ]
            /lib/systemd/systemd                                     [ OK ]
        
        [Press <ENTER> to continue]
        
        
        Checking for rootkits...
        
          Performing check of known rootkit files and directories
            55808 Trojan - Variant A                                 [ Not found ]
            ADM Worm                                                 [ Not found ]
            AjaKit Rootkit                                           [ Not found ]
            Adore Rootkit                                            [ Not found ]
            aPa Kit                                                  [ Not found ]
            Apache Worm                                              [ Not found ]
            Ambient (ark) Rootkit                                    [ Not found ]
            Balaur Rootkit                                           [ Not found ]
            BeastKit Rootkit                                         [ Not found ]
            beX2 Rootkit                                             [ Not found ]
            BOBKit Rootkit                                           [ Not found ]
            cb Rootkit                                               [ Not found ]
            CiNIK Worm (Slapper.B variant)                           [ Not found ]
            Danny-Boy's Abuse Kit                                    [ Not found ]
            Devil RootKit                                            [ Not found ]
            Dica-Kit Rootkit                                         [ Not found ]
            Dreams Rootkit                                           [ Not found ]
            Duarawkz Rootkit                                         [ Not found ]
            Enye LKM                                                 [ Not found ]
            Flea Linux Rootkit                                       [ Not found ]
            Fu Rootkit                                               [ Not found ]
            Fuck`it Rootkit                                          [ Not found ]
            GasKit Rootkit                                           [ Not found ]
            Heroin LKM                                               [ Not found ]
            HjC Kit                                                  [ Not found ]
            ignoKit Rootkit                                          [ Not found ]
            IntoXonia-NG Rootkit                                     [ Not found ]
            Irix Rootkit                                             [ Not found ]
            Jynx Rootkit                                             [ Not found ]
            KBeast Rootkit                                           [ Not found ]
            Kitko Rootkit                                            [ Not found ]
            Knark Rootkit                                            [ Not found ]
            ld-linuxv.so Rootkit                                     [ Not found ]
            Li0n Worm                                                [ Not found ]
            Lockit / LJK2 Rootkit                                    [ Not found ]
            Mood-NT Rootkit                                          [ Not found ]
            MRK Rootkit                                              [ Not found ]
            Ni0 Rootkit                                              [ Not found ]
            Ohhara Rootkit                                           [ Not found ]
            Optic Kit (Tux) Worm                                     [ Not found ]
            Oz Rootkit                                               [ Not found ]
            Phalanx Rootkit                                          [ Not found ]
            Phalanx2 Rootkit                                         [ Not found ]
            Phalanx2 Rootkit (extended tests)                        [ Not found ]
            Portacelo Rootkit                                        [ Not found ]
            R3dstorm Toolkit                                         [ Not found ]
            RH-Sharpe's Rootkit                                      [ Not found ]
            RSHA's Rootkit                                           [ Not found ]
            Scalper Worm                                             [ Not found ]
            Sebek LKM                                                [ Not found ]
            Shutdown Rootkit                                         [ Not found ]
            SHV4 Rootkit                                             [ Not found ]
            SHV5 Rootkit                                             [ Not found ]
            Sin Rootkit                                              [ Not found ]
            Slapper Worm                                             [ Not found ]
            Sneakin Rootkit                                          [ Not found ]
            'Spanish' Rootkit                                        [ Not found ]
            Suckit Rootkit                                           [ Not found ]
            Superkit Rootkit                                         [ Not found ]
            TBD (Telnet BackDoor)                                    [ Not found ]
            TeLeKiT Rootkit                                          [ Not found ]
            T0rn Rootkit                                             [ Not found ]
            trNkit Rootkit                                           [ Not found ]
            Trojanit Kit                                             [ Not found ]
            Tuxtendo Rootkit                                         [ Not found ]
            URK Rootkit                                              [ Not found ]
            Vampire Rootkit                                          [ Not found ]
            VcKit Rootkit                                            [ Not found ]
            Volc Rootkit                                             [ Not found ]
            Xzibit Rootkit                                           [ Not found ]
            zaRwT.KiT Rootkit                                        [ Not found ]
            ZK Rootkit                                               [ Not found ]
        
        [Press <ENTER> to continue]
        
        
          Performing additional rootkit checks
            Suckit Rookit additional checks                          [ OK ]
            Checking for possible rootkit files and directories      [ None found ]
            Checking for possible rootkit strings                    [ None found ]
        
          Performing malware checks
            Checking running processes for suspicious files          [ None found ]
            Checking for login backdoors                             [ None found ]
            Checking for suspicious directories                      [ None found ]
            Checking for sniffer log files                           [ None found ]
            Suspicious Shared Memory segments                        [ None found ]
        
          Performing Linux specific checks
            Checking loaded kernel modules                           [ OK ]
            Checking kernel module names                             [ OK ]
        
        [Press <ENTER> to continue]
        
        
        Checking the network...
        
          Performing checks on the network ports
            Checking for backdoor ports                              [ None found ]
            Checking for hidden ports                                [ None found ]
        
          Performing checks on the network interfaces
            Checking for promiscuous interfaces                      [ None found ]
        
        Checking the local host...
        
          Performing system boot checks
            Checking for local host name                             [ Found ]
            Checking for system startup files                        [ Found ]
            Checking system startup files for malware                [ None found ]
        
          Performing group and account checks
            Checking for passwd file                                 [ Found ]
            Checking for root equivalent (UID 0) accounts            [ None found ]
            Checking for passwordless accounts                       [ None found ]
            Checking for passwd file changes                         [ None found ]
            Checking for group file changes                          [ None found ]
            Checking root account shell history files                [ OK ]
        
          Performing system configuration file checks
            Checking for an SSH configuration file                   [ Found ]
            Checking if SSH root access is allowed                   [ Warning ]
            Checking if SSH protocol v1 is allowed                   [ Not allowed ]
            Checking for a running system logging daemon             [ Found ]
            Checking for a system logging configuration file         [ Found ]
            Checking if syslog remote logging is allowed             [ Not allowed ]
        
          Performing filesystem checks
            Checking /dev for suspicious file types                  [ Warning ]
            Checking for hidden files and directories                [ None found ]
        
        [Press <ENTER> to continue]
        
        
        
        System checks summary
        =====================
        
        File properties checks...
            Files checked: 150
            Suspect files: 2
        
        Rootkit checks...
            Rootkits checked : 365
            Possible rootkits: 0
        
        Applications checks...
            All checks skipped
        
        The system checks took: 2 minutes and 3 seconds
        
        All results have been written to the log file: /var/log/rkhunter.log
        
        One or more warnings have been found while checking the system.
        Please check the log file (/var/log/rkhunter.log)
        
        root@marc-Inspiron-1545:~# 
        

        -
        Edité par imostone 18 octobre 2016 à 19:33:02

        • Partager sur Facebook
        • Partager sur Twitter

        compte piraté/analyse rootkit sous linux

        × Après avoir cliqué sur "Répondre" vous serez invité à vous connecter pour que votre message soit publié.
        × Attention, ce sujet est très ancien. Le déterrer n'est pas forcément approprié. Nous te conseillons de créer un nouveau sujet pour poser ta question.
        • Editeur
        • Markdown