Home | Data Center | Contact US | Login

Á¦¸ñ rkhunterÀ» ÅëÇÑ ½Ã½ºÅÛ ¹«°á¼º üũÇϱâ
÷ºÎÆÄÀÏ rkhunterÀ» ÅëÇÑ ½Ã½ºÅÛ ¹«°á¼º üũÇϱâ.pdf ÀÛ¼ºÀÏ 2007-01-31 10:24:58

ÀÛ¼ºÀÚ: ±â¼úÁö¿øºÎ ±è »ï ¼ö

rkhunterÀ» ÅëÇÑ ½Ã½ºÅÛ ¹«°á¼º üũÇϱâ

¹éµµ¾î³ª ·çƮŶÀ» ŽÁöÇϸç ÀϹÝÀûÀ¸·Î ·çƮŶÀÌ »ç¿ëÇÏ´Â ÆÄÀÏ ¹× ¼û±è ÆÄÀÏÀÇ Á¸Àç¿©
ºÎ¸¦ ÆǺ°ÇØÁÖ¸ç, ½ÇÇà½Ã °ü¸®ÀÚ¿¡°Ô °¢ ÆÄÆ®º°·Î üũ»çÇ×À» º¸¿©ÁÖ´Â ¸®Æ÷Æ®±â´ÉÀÌ
¶Ù¾î³ª¸çSOLARIS¸¦ Á¦¿ÜÇÑ ´ëºÎºÐÀÇ UNIX¸¦ Áö¿øÇÕ´Ï´Ù.


( 1 ) ´Ù¿î·Îµå

http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz
À§ÀÇ URLÀÌ ¾ÈµÇ½Ã´Â°æ¿ì http://sourceforge.net/projects/rkhunter/files/ À¸·Î Á¢¼ÓÇÏ¿©
ÃֽŠ¹öÀüÀ» ´Ù¿î¹ÞÀ¸½Ã±â ¹Ù¶ø´Ï´Ù.

wgetÀº À¥¿¡¼­ ÀÚµ¿ÀûÀ¸·Î ÆÄÀÏÀ» ¹Þ¾Æ¿À´Âµ¥ »ç¿ëµÇ´Â À¯Æ¿¸®Æ¼À̸ç HTTP, HTTPS, FTP ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÕ´Ï´Ù.

¨ç wget ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© rkhunter-1.2.7.tar.gzÆÄÀÏÀ» ´Ù¿î·Îµå ÇÕ´Ï´Ù.
[root@nextline ~]# wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz



( 2 ) ¾ÐÃàÇØÁ¦

[tar ¸í·É¾î ¿É¼Ç]
tar ¸í·É¾î´Â ÆÄÀÏÀ» ¹­°Å³ª Ç® ¶§ »ç¿ëµÇ´Â ¸®´ª½º ¸í·É¾î ÀÔ´Ï´Ù.
c : tar ÆÄÀÏÀ» »ý¼ºÇÒ ¶§(¿©·¯ °³ÀÇ ÆÄÀÏÀ» ÇϳªÀÇ ÆÄÀÏ·Î ¹­À» ¶§)
v : ¹­À» ¶§³ª Ç®¾îÁÙ ¶§ ÆÄÀϵéÀÇ ³»¿ëÀ» ÀÚ¼¼ÇÏ°Ô º¸·Á°í ÇÒ ¶§.
z : gzip°ú °ü·ÃÇÏ¿© ¾ÐÃàÀ̳ª ÇØÁ¦¸¦ ÇѲ¨¹ø¿¡ ÇÏ·Á°í ÇÒ ¶§ »ç¿ë.
x : ÁÖ¾îÁø À̸§ÀÇ ÆÄÀÏ¿¡ ´ëÇÏ¿© ÃßÃâ
»ç¿ë¹ý: tar [¿É¼Ç] ÆÄÀϸí

¨ç ´Ù¿î·ÎµåµÈrkhunter-1.2.7.tar.gzÆÄÀÏÀÇ ¾ÐÃàÀ» ÇØÁ¦ ÇÕ´Ï´Ù.
[root@nextline ~]# tar zxvf rkhunter-1.2.7.tar.gz



( 3 ) ÄÄÆÄÀÏ

¨ç ¾ÐÃàÇØÁ¦µÈ rkhunter µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.
[root@nextline ~]# cd rkhunter

¨è ./installer.sh¸¦ ½ÇÇàÇÕ´Ï´Ù.
[root@nextline rkhunter]# ./installer.sh



( 4 ) ½ÇÇàÆÄÀÏ


ÄÄÆÄÀÏ ÀÛ¾÷¿¡ ÀÇÇØ /usr/local/bin/rkhunter ½ÇÇà ÆÄÀÏÀÌ »ý¼ºµË´Ï´Ù.

¨ç ls ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© rkhunter ½ÇÇàÆÄÀÏÀ» È®ÀÎÇÕ´Ï´Ù.
[root@nextline rkhunter]# ls /usr/local/bin/rkhunter



( 5 ) rkhunter ¾÷µ¥ÀÌÆ®

[ rkhunter ¿É¼Ç ]

-c : °Ë»ç°á°ú¸¦ CRT·Î Ãâ·ÂÇÕ´Ï´Ù.
--checkall -–createlogfile : °Ë»ç°á°ú¸¦ /var/log/rkhunter.log ÆÄÀÏ¿¡ ÀúÀåÇÕ´Ï´Ù.
--versioncheck : rkhunterÀÇ ¹öÀüÀ» Ãâ·ÂÇÕ´Ï´Ù.
--update : rkhunter¸¦ ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.
--cronjob : crontab ¸ðµå·Î µ¿ÀÛÇÕ´Ï´Ù.(Ä÷¯·¹À̾ƿôÀ» Á¦°ÅÇÕ´Ï´Ù.)
--report-warnings-only : ¹®Á¦°¡ µÇ´Â »çÇ׸¸ Ãâ·ÂÇÕ´Ï´Ù.

¨ç ½Ã½ºÅÛ °Ë»ç¿¡ ¾Õ¼­ ÃÖ½ÅÁ¤º¸¸¦ ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.
°¢ Ç׸ñÀÇUpdate¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
[DB] Mirror file
[DB] MD5 hashes system binaries 
[DB] Operating System information
[DB] MD5 blacklisted tools/binaries  
[DB] Known good program versions 
[DB] Known bad program versions



( 6 ) rkhunter ½ÇÇà

¨ç rkhunter¸¦ ½ÇÇàÇÕ´Ï´Ù.
[root@nextline rkhunter]# /usr/local/bin/rkhunter –c
 
 
¨è Checking binaries
¡®known good¡¯ ¸Þ½ÃÁö¿Í ÇÔ²² ¸ðµç Ç׸ñÀÌ [OK]·Î Ãâ·ÂµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¹ÙÀÌ·¯¸® ÆÄÀÏ¿¡ ¿À·ù°¡ °¨ÁöµÇ¸é[BAD] ¸Þ½ÃÁö¸¦ Ãâ·ÂÇÕ´Ï´Ù.


¨é Check rootkits
rootkits ¸ðµç Ç׸ñÀÌ [OK]·Î Ç¥½ÃµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.

    
¨ê Networking
Networking ¸ðµç Ç׸ñÀÌ [OK]·Î Ç¥½ÃµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.


¨ë System checks
System checks ¸ðµç Ç׸ñÀÌ [Not found] [OK]·Î Ç¥½ÃµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
 

¨ì Application advisories
Application advisories Ç׸ñÀº ÀÀ¿ëÇÁ·Î±×·¥ÀÇ ¹öÀüÀ» ÃøÁ¤ÇÏ´Â Ç׸ñÀ¸·Î ¿À·¡µÈ ¹öÀüÀ»
»ç¿ëÇÏ°í °è½Ç °æ¿ì ÇØ´ç ÇÁ·Î±×·¥¿¡ [ Old or patched version ]ÀÌ Ãâ·ÂµË´Ï´Ù.


¨í Scan results
°¢ Ç׸ñÀÇ °Ë»ç°á°ú¸¦ °£·«È÷ º¸¿©ÁÖ´Â È­¸éÀÔ´Ï´Ù.
  TCP-Wrapper ±¸¼º
  ¾ÆÆÄÄ¡ 1.X ¹öÀü¿¡¼­ mod_throttle¸¦ ÀÌ¿ëÇÑ Æ®·¡ÇÈ°ü¸®





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ