rkhunter是Linux下的一款開(kāi)源入侵檢測(cè)工具。rkhunter具有比chrootkit更為全面的掃描范圍。除rootkit特征碼掃描外,rkhunter還支持端口掃描,常用開(kāi)源軟件版本和文件變動(dòng)情況檢查等。
rkhunter快速安裝
cd /tmp rm -fR rkhunter* wget -N http://downloads.sourceforge.net/project/rkhunter/rkhunter/1.3.6/rkhunter-1.3.6.tar.gz gzip -d -c rkhunter-1.3.6.tar.gz | gtar xvf - cd rkhunter-1.3.6 ./installer.sh --install ./installer.sh --show
rkhunter配置文件調(diào)整
sed -i 's/DISABLE_TESTS="suspscan hidden_procs deleted_files packet_cap_apps"/DISABLE_TESTS="suspscan deleted_files"/' /etc/rkhunter.conf sed -i 's/ALLOW_SSH_ROOT_USER=no/ALLOW_SSH_ROOT_USER=without-password/' /etc/rkhunter.conf sed -i 's/#ATTRWHITELIST=\/bin\/ps/ATTRWHITELIST=\/bin\/ps/' /etc/rkhunter.conf sed -i 's/#WRITEWHITELIST=\/bin\/ps/WRITEWHITELIST=\/bin\/ps/' /etc/rkhunter.conf sed -i 's/#SCRIPTWHITELIST=\/sbin\/ifup/SCRIPTWHITELIST=\/sbin\/ifup/' /etc/rkhunter.conf sed -i 's/#SCRIPTWHITELIST=\/sbin\/ifdown/SCRIPTWHITELIST=\/sbin\/ifdown/' /etc/rkhunter.conf sed -i 's/#SCRIPTWHITELIST=\/usr\/bin\/groups/SCRIPTWHITELIST=\/usr\/bin\/groups/' /etc/rkhunter.conf sed -i 's/#ALLOWHIDDENDIR=\/dev\/.udev/ALLOWHIDDENDIR=\/dev\/.udev/' /etc/rkhunter.conf sed -i 's/#ALLOWHIDDENDIR=\/dev\/.udevdb/ALLOWHIDDENDIR=\/dev\/.udevdb/' /etc/rkhunter.conf sed -i 's/#ALLOWHIDDENFILE=\/usr\/sbin\/.sshd.hmac/ALLOWHIDDENFILE=\/usr\/sbin\/.sshd.hmac/' /etc/rkhunter.conf sed -i 's/#ALLOWHIDDENFILE=\/usr\/bin\/.ssh.hmac/ALLOWHIDDENFILE=\/usr\/bin\/.ssh.hmac/' /etc/rkhunter.conf sed -i 's/#ALLOWHIDDENFILE=\/usr\/bin\/.fipscheck.hmac/ALLOWHIDDENFILE=\/usr\/bin\/.fipscheck.hmac/' /etc/rkhunter.conf echo 'ALLOWHIDDENDIR=/dev/ida' >> /etc/rkhunter.conf sed -i 's/#SCRIPTWHITELIST=\/sbin\/ifdown/SCRIPTWHITELIST=\/sbin\/ifdown/' /etc/rkhunter.conf sed -i 's/#SCRIPTWHITELIST=\/usr\/bin\/groups/SCRIPTWHITELIST=\/usr\/bin\/groups/' /etc/rkhunter.conf echo 'SCRIPTWHITELIST=/usr/bin/ldd' >> /etc/rkhunter.conf echo 'SCRIPTWHITELIST=/usr/bin/whatis' >> /etc/rkhunter.conf echo 'SCRIPTWHITELIST=/usr/bin/GET' >> /etc/rkhunter.conf ## 更新rkhunter數(shù)據(jù)庫(kù) ## rkhunter --update rkhunter --propupd /usr/local/bin/rkhunter --cronjob -l --nomow --rwo
rkhunter的crontab定期掃描
運(yùn)行crontab -e添加以下信息。
3 * * * (/usr/local/bin/rkhunter --cronjob -l --nomow --rwo | mail -s "【標(biāo)題】rkhunter 本文出自:億恩科技【1tcdy.com】
服務(wù)器租用/服務(wù)器托管中國(guó)五強(qiáng)!虛擬主機(jī)域名注冊(cè)頂級(jí)提供商!15年品質(zhì)保障!--億恩科技[ENKJ.COM]
|