我剛剛發現了rkhunter,並決定在我的CentOS專用服務器上運行掃描,沒有發現rootkit(謝天謝地),但有警告,我只是好奇,如果有人遇到這些,或者如果這是我應該擔心還是在進一步調查?5個警告提出來了,我應該擔心嗎?
下面是我從rkhunter收到警告:
[22:01:58] /sbin/ifdown [ Warning ]
[22:01:58] Warning: The command '/sbin/ifdown' has been replaced by a script: /sbin/ifdown: Bourne-Again shell script text executable
[22:01:58] /sbin/ifup [ Warning ]
[22:01:58] Warning: The command '/sbin/ifup' has been replaced by a script: /sbin/ifup: Bourne-Again shell script text executable
[22:02:05] /usr/bin/GET [ Warning ]
[22:02:05] Warning: The command '/usr/bin/GET' has been replaced by a script: /usr/bin/GET: a /usr/bin/perl -w script text executable
[22:02:05] /usr/bin/ldd [ Warning ]
[22:02:05] Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne-Again shell script text executable
[22:02:07] /usr/bin/whatis [ Warning ]
[22:02:07] Warning: The command '/usr/bin/whatis' has been replaced by a script: /usr/bin/whatis: POSIX shell script text executable
[22:03:03] Info: SCAN_MODE_DEV set to 'THOROUGH'
[22:03:05] Checking /dev for suspicious file types [ Warning ]
[22:03:05] Warning: Suspicious file types found in /dev:
[22:03:05] /dev/md/autorebuild.pid: ASCII text
[22:03:05] /dev/md/md-device-map: ASCII text
[22:03:05] /dev/.udev/queue.bin: Applesoft BASIC program data
[22:03:05] /dev/.udev/db/block:md0: ASCII text
[22:03:05] /dev/.udev/db/block:md1: ASCII text
[22:03:05] /dev/.udev/db/block:sda1: ASCII text
[22:03:05] /dev/.udev/db/net:eth1: ASCII text
[22:03:05] /dev/.udev/db/net:eth0: ASCII text
[22:03:05] /dev/.udev/db/block:sdb3: ASCII text
[22:03:05] /dev/.udev/db/block:sdb1: ASCII text
[22:03:05] /dev/.udev/db/block:sda3: ASCII text
[22:03:05] /dev/.udev/db/block:sda2: ASCII text
[22:03:05] /dev/.udev/db/block:sdb2: ASCII text
[22:03:05] /dev/.udev/db/input:event2: ASCII text
[22:03:05] /dev/.udev/db/input:event0: ASCII text
[22:03:05] /dev/.udev/db/block:sda: ASCII text
[22:03:05] /dev/.udev/db/block:sdb: ASCII text
[22:03:05] /dev/.udev/db/input:event4: ASCII text
[22:03:05] /dev/.udev/db/input:mouse1: ASCII text
[22:03:05] /dev/.udev/db/input:event3: ASCII text
[22:03:05] /dev/.udev/db/input:event1: ASCII text
[22:03:05] /dev/.udev/db/block:ram9: ASCII text
[22:03:05] /dev/.udev/db/block:ram8: ASCII text
[22:03:05] /dev/.udev/db/block:ram4: ASCII text
[22:03:05] /dev/.udev/db/block:ram5: ASCII text
[22:03:05] /dev/.udev/db/block:ram7: ASCII text
[22:03:05] /dev/.udev/db/block:ram6: ASCII text
[22:03:05] /dev/.udev/db/block:ram3: ASCII text
[22:03:06] /dev/.udev/db/block:ram2: ASCII text
[22:03:06] /dev/.udev/db/block:ram15: ASCII text
[22:03:06] /dev/.udev/db/block:ram14: ASCII text
[22:03:06] /dev/.udev/db/block:ram13: ASCII text
[22:03:06] /dev/.udev/db/block:ram12: ASCII text
[22:03:06] /dev/.udev/db/block:ram0: ASCII text
[22:03:06] /dev/.udev/db/block:ram1: ASCII text
[22:03:06] /dev/.udev/db/block:ram11: ASCII text
[22:03:06] /dev/.udev/db/block:ram10: ASCII text
[22:03:06] /dev/.udev/db/block:loop7: ASCII text
[22:03:06] /dev/.udev/db/block:loop3: ASCII text
[22:03:06] /dev/.udev/db/block:loop5: ASCII text
[22:03:06] /dev/.udev/db/block:loop4: ASCII text
[22:03:06] /dev/.udev/db/block:loop6: ASCII text
[22:03:06] /dev/.udev/db/block:loop1: ASCII text
[22:03:06] /dev/.udev/db/block:loop2: ASCII text
[22:03:06] /dev/.udev/db/block:loop0: ASCII text
[22:03:06] /dev/.udev/db/usb:2-1: ASCII text
[22:03:06] /dev/.udev/db/usb:1-1: ASCII text
[22:03:06] /dev/.udev/db/usb:3-7.1: ASCII text
[22:03:06] /dev/.udev/db/usb:3-7: ASCII text
[22:03:06] /dev/.udev/db/usb:usb1: ASCII text
[22:03:06] /dev/.udev/db/usb:usb3: ASCII text
[22:03:06] /dev/.udev/db/usb:usb4: ASCII text
[22:03:06] /dev/.udev/db/usb:usb2: ASCII text
[22:03:06] /dev/.udev/rules.d/99-root.rules: ASCII text
[22:03:06] Checking for hidden files and directories [ Warning ]
[22:03:06] Warning: Hidden directory found: /dev/.mdadm
[22:03:06] Warning: Hidden directory found: /dev/.udev
[22:03:06] Warning: Hidden file found: /usr/share/man/man5/.k5login.5.gz: gzip compressed data, from Unix, max compression
[22:03:06] Warning: Hidden file found: /usr/share/man/man5/.k5identity.5.gz: gzip compressed data, from Unix, max compression
[22:03:06] Warning: Hidden file found: /usr/share/man/man1/..1.gz: gzip compressed data, from Unix, max compression
[22:03:06] Warning: Hidden file found: /usr/bin/.fipscheck.hmac: ASCII text
[22:03:06] Warning: Hidden file found: /usr/bin/.ssh.hmac: ASCII text
[22:03:06] Warning: Hidden file found: /usr/sbin/.sshd.hmac: ASCII text
感謝您的回覆,我會upvote您的評論,但有人一直downvoting我的問題...所以我永遠不會達到15級,似乎... – x80 2015-03-05 00:12:19