前言
一直以来学习都是在本地虚拟机,公司有专有服务器,双11各大云服务商开始搞活动引诱你,好吧,贪便宜买了一台想体验下,年88还挺便宜哈。买了后放了半个多月吧,没怎么用,突然收到微信加短信,主机遭黑客入侵了,想了想我上边儿啥也没有,所以不害怕,反倒觉得好玩儿。
做为一个IT人,拥有主机,难免会遇到这样的问题,还真得学习一下该怎么防御,被入侵后怎么查杀,这时候windows上的软件点一点扫一扫没有了哈。
根据短信找这个/usr/bin/rkynlpmldy文件居然没找到。
搜一下linux 木马查找:
https://www.cnblogs.com/Juvenile/p/7871802.html
https://blog.youkuaiyun.com/bittersweet0324/article/details/80650626
top
[root@VM_0_2_centos ~]# top
top - 16:55:42 up 1:14, 1 user, load average: 2.12, 2.33, 2.33
Tasks: 79 total, 2 running, 77 sleeping, 0 stopped, 0 zombie
%Cpu(s): 99.7 us, 0.3 sy, 0.0 ni, 0.0 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st
KiB Mem : 1882752 total, 1287892 free, 226720 used, 368140 buff/cache
KiB Swap: 0 total, 0 free, 0 used. 1488716 avail Mem
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
6475 root 20 0 40248 3840 1028 S 95.3 0.2 62:26.07 Donald
4038 root 20 0 184344 125896 5872 S 4.0 6.7 3:38.16 wflsfa5
1178 root 20 0 578716 28748 13132 S 0.3 1.5 0:02.01 dockerd-current
1 root 20 0 43392 3772 2572 S 0.0 0.2 0:01.69 systemd
2 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kthreadd
3 root 20 0 0 0 0 S 0.0 0.0 0:00.02 ksoftirqd/0
4 root 20 0 0 0 0 S 0.0 0.0 0:00.26 kworker/0:0
5 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kworker/0:0H
6 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kworker/u2:0
7 root rt 0 0 0 0 S 0.0 0.0 0:00.00 migration/0
8 root 20 0 0 0 0 S 0.0 0.0 0:00.00 rcu_bh
9 root 20 0 0 0 0 S 0.0 0.0 0:00.79 rcu_sched
8 root 20 0 0 0 0 S 0.0 0.0 0:00.00 rcu_bh
9 root 20 0 0 0 0 S 0.0 0.0 0:00.79 rcu_sched
10 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 lru-add-drain
11 root rt 0 0 0 0 S 0.0 0.0 0:00.01 watchdog/0
13 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kdevtmpfs
14 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 netns
15 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtaskd
18 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 bioset
19 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kblockd
20 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 md
21 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 edac-poller