在linux下用shell脚本检测木马文件的方法 分享一段shell 脚本,用于检测可能的木马程序文件。
代码:
#!/bin/sh
# Filename : whatever_you_name_it DIRS="/etc /home /bin /sbin /usr/bin /usr/sbin /usr/local /var /your_directory" ADMIN="email@your.domain.com" FROM="admin@your.domain.com" # 写入Sendmail的标头 echo "Subject: $HOSTNAME filesystem check" > /tmp/today.mail echo "From: $FROM" >> /tmp/today.mail echo "To: $ADMIN" >> /tmp/today.mail echo "This is filesystem report comes from $HOSTNAME" >> /tmp/today.mail # 报告目前正在执行的程式 ps axf >> /tmp/today.mail # 档案系统检查 echo "File System Check" >> /tmp/today.mail ls -alR $DIRS | gzip -9 > /tmp/today.gz zdiff /tmp/today.gz /tmp/yesterday.gz >> /tmp/today.mail mv -f /tmp/today.gz /tmp/yesterday.gz # 寄出信件 sendmail -t < /tmp/today.mail
加入crontab中,如下: 有些文件是固定会变动的,像/var/log/messages、/var/log/syslog、/dev/ttyX等。 (责任编辑:IT) |