全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 3754|回复: 10

大神们,怎么清理Ebury Rootkit木马?Hostigation说我中标了!

[复制链接]
发表于 2014-3-20 12:14:26 | 显示全部楼层 |阅读模式
Hostigation received third party information that your VPS may be compromised with the Ebury Trojan. The Ebury trojan steals SSH login credentials from incoming and outgoing SSH connections and forwards them to a dropzone server in specially crafted DNS packets. The trojan is normally found in a binary directory on Unix-based systems in one of the following locations:

/usr/bin/ssh
/usr/bin/sshd
/usr/bin/ssh-add

According to the data we received, your VPS was sending harvested SSH credentials to a dropzone server. They only guaranteed way to remove this trojan is to reinstall your VPS. If your VPS is OpenVZ, we can provide you with a small amount of backup space so you may retrieve critical files once your VPS is reinstalled. Due to the nature of this trojan, any infected KVM VPS will have to be reinstalled completely from scratch.
发表于 2014-3-20 12:17:00 | 显示全部楼层
rkhunter 这个行不行?
 楼主| 发表于 2014-3-20 12:18:28 | 显示全部楼层
本帖最后由 asmon 于 2014-4-2 23:51 编辑

ipcs -m


查出3个不明东西!狗日!都超过3MB了!
 楼主| 发表于 2014-3-20 12:21:42 | 显示全部楼层
用OpenVZ,都查一下吧:ipcs -m
发表于 2014-3-20 12:26:38 | 显示全部楼层
ipcs -m 是查共享内存的   不是查进程的
 楼主| 发表于 2014-3-20 13:14:31 | 显示全部楼层
cgs3238 发表于 2014-3-20 12:26
ipcs -m 是查共享内存的   不是查进程的

有没有处理办法?
发表于 2014-3-20 14:00:02 | 显示全部楼层
听说超过3M和666权限的概率高一些。
发表于 2014-3-20 14:05:52 | 显示全部楼层
网上看到的解决办法,最好重装系统,不重装系统的话就重装libkeyutils。
  1. Re-install libkeyutils (using rpm --replacepkg option) and reboot the server.
  2.    Change the password of all SSH user account.
复制代码
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2025-1-11 02:21 , Processed in 0.275235 second(s), 14 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表