本文共 1365 字,大约阅读时间需要 4 分钟。
查看passwd的修改时间,判断是否在不知的情况下添加用户 awk -F: ‘$3= =0 {print $1}’ /etc/passwd awk -F: ‘length($2)= =0 {print $1}’ /etc/shadow ps -ef | awk ‘{print }’ | sort -n | uniq >1 ls /porc |sort -n|uniq >2 find / -uid 0 –perm -4000 –print find / -size +10000k –print rpm -Va #注意相关的/sbin,/bin,/usr/sbin,/usr/bin M – Mode differs (permissions) D – Device number mismatch L – readLink path mismatch U – user ownership differs G – group ownership differs T – modification time differs ip link | grep PROMISC(正常网卡不该在promisc模式,可能存在sniffer) netstat –nap(察看不正常打开的TCP/UDP端口) 转载于:https://www.cnblogs.com/Anwar/p/9743853.html