ÀÛ¼ºÀÚ: ±â¼úÁö¿øºÎ ±è »ï ¼ö
rkhunterÀ» ÅëÇÑ ½Ã½ºÅÛ ¹«°á¼º üũÇϱâ
¹éµµ¾î³ª ·çƮŶÀ» ŽÁöÇϸç ÀϹÝÀûÀ¸·Î ·çƮŶÀÌ »ç¿ëÇÏ´Â ÆÄÀÏ ¹× ¼û±è ÆÄÀÏÀÇ Á¸Àç¿© ºÎ¸¦ ÆǺ°ÇØÁÖ¸ç, ½ÇÇà½Ã °ü¸®ÀÚ¿¡°Ô °¢ ÆÄÆ®º°·Î üũ»çÇ×À» º¸¿©ÁÖ´Â ¸®Æ÷Æ®±â´ÉÀÌ ¶Ù¾î³ª¸çSOLARIS¸¦ Á¦¿ÜÇÑ ´ëºÎºÐÀÇ UNIX¸¦ Áö¿øÇÕ´Ï´Ù.
( 1 ) ´Ù¿î·Îµå
http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz À§ÀÇ URLÀÌ ¾ÈµÇ½Ã´Â°æ¿ì http://sourceforge.net/projects/rkhunter/files/ À¸·Î Á¢¼ÓÇÏ¿©
ÃֽŠ¹öÀüÀ» ´Ù¿î¹ÞÀ¸½Ã±â ¹Ù¶ø´Ï´Ù.
wgetÀº À¥¿¡¼ ÀÚµ¿ÀûÀ¸·Î ÆÄÀÏÀ» ¹Þ¾Æ¿À´Âµ¥ »ç¿ëµÇ´Â À¯Æ¿¸®Æ¼À̸ç HTTP, HTTPS, FTP ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÕ´Ï´Ù.
¨ç wget ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© rkhunter-1.2.7.tar.gzÆÄÀÏÀ» ´Ù¿î·Îµå ÇÕ´Ï´Ù. [root@nextline ~]# wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz
( 2 ) ¾ÐÃàÇØÁ¦
[tar ¸í·É¾î ¿É¼Ç] tar ¸í·É¾î´Â ÆÄÀÏÀ» ¹°Å³ª Ç® ¶§ »ç¿ëµÇ´Â ¸®´ª½º ¸í·É¾î ÀÔ´Ï´Ù. c : tar ÆÄÀÏÀ» »ý¼ºÇÒ ¶§(¿©·¯ °³ÀÇ ÆÄÀÏÀ» ÇϳªÀÇ ÆÄÀÏ·Î ¹À» ¶§) v : ¹À» ¶§³ª Ç®¾îÁÙ ¶§ ÆÄÀϵéÀÇ ³»¿ëÀ» ÀÚ¼¼ÇÏ°Ô º¸·Á°í ÇÒ ¶§. z : gzip°ú °ü·ÃÇÏ¿© ¾ÐÃàÀ̳ª ÇØÁ¦¸¦ ÇѲ¨¹ø¿¡ ÇÏ·Á°í ÇÒ ¶§ »ç¿ë. x : ÁÖ¾îÁø À̸§ÀÇ ÆÄÀÏ¿¡ ´ëÇÏ¿© ÃßÃâ »ç¿ë¹ý: tar [¿É¼Ç] ÆÄÀϸí
¨ç ´Ù¿î·ÎµåµÈrkhunter-1.2.7.tar.gzÆÄÀÏÀÇ ¾ÐÃàÀ» ÇØÁ¦ ÇÕ´Ï´Ù. [root@nextline ~]# tar zxvf rkhunter-1.2.7.tar.gz
( 3 ) ÄÄÆÄÀÏ
¨ç ¾ÐÃàÇØÁ¦µÈ rkhunter µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù. [root@nextline ~]# cd rkhunter
¨è ./installer.sh¸¦ ½ÇÇàÇÕ´Ï´Ù. [root@nextline rkhunter]# ./installer.sh
( 4 ) ½ÇÇàÆÄÀÏ
ÄÄÆÄÀÏ ÀÛ¾÷¿¡ ÀÇÇØ /usr/local/bin/rkhunter ½ÇÇà ÆÄÀÏÀÌ »ý¼ºµË´Ï´Ù.
¨ç ls ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© rkhunter ½ÇÇàÆÄÀÏÀ» È®ÀÎÇÕ´Ï´Ù. [root@nextline rkhunter]# ls /usr/local/bin/rkhunter
( 5 ) rkhunter ¾÷µ¥ÀÌÆ®
[ rkhunter ¿É¼Ç ]
-c : °Ë»ç°á°ú¸¦ CRT·Î Ãâ·ÂÇÕ´Ï´Ù. --checkall -–createlogfile : °Ë»ç°á°ú¸¦ /var/log/rkhunter.log ÆÄÀÏ¿¡ ÀúÀåÇÕ´Ï´Ù. --versioncheck : rkhunterÀÇ ¹öÀüÀ» Ãâ·ÂÇÕ´Ï´Ù. --update : rkhunter¸¦ ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù. --cronjob : crontab ¸ðµå·Î µ¿ÀÛÇÕ´Ï´Ù.(Ä÷¯·¹À̾ƿôÀ» Á¦°ÅÇÕ´Ï´Ù.) --report-warnings-only : ¹®Á¦°¡ µÇ´Â »çÇ׸¸ Ãâ·ÂÇÕ´Ï´Ù.
¨ç ½Ã½ºÅÛ °Ë»ç¿¡ ¾Õ¼ ÃÖ½ÅÁ¤º¸¸¦ ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù. °¢ Ç׸ñÀÇUpdate¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. [DB] Mirror file [DB] MD5 hashes system binaries [DB] Operating System information [DB] MD5 blacklisted tools/binaries [DB] Known good program versions [DB] Known bad program versions
( 6 ) rkhunter ½ÇÇà
¨ç rkhunter¸¦ ½ÇÇàÇÕ´Ï´Ù. [root@nextline rkhunter]# /usr/local/bin/rkhunter –c ¨è Checking binaries ¡®known good¡¯ ¸Þ½ÃÁö¿Í ÇÔ²² ¸ðµç Ç׸ñÀÌ [OK]·Î Ãâ·ÂµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¹ÙÀÌ·¯¸® ÆÄÀÏ¿¡ ¿À·ù°¡ °¨ÁöµÇ¸é[BAD] ¸Þ½ÃÁö¸¦ Ãâ·ÂÇÕ´Ï´Ù.
¨é Check rootkits rootkits ¸ðµç Ç׸ñÀÌ [OK]·Î Ç¥½ÃµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¨ê Networking Networking ¸ðµç Ç׸ñÀÌ [OK]·Î Ç¥½ÃµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¨ë System checks System checks ¸ðµç Ç׸ñÀÌ [Not found] [OK]·Î Ç¥½ÃµÇ¸é [ENTER]¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¨ì Application advisories Application advisories Ç׸ñÀº ÀÀ¿ëÇÁ·Î±×·¥ÀÇ ¹öÀüÀ» ÃøÁ¤ÇÏ´Â Ç׸ñÀ¸·Î ¿À·¡µÈ ¹öÀüÀ» »ç¿ëÇÏ°í °è½Ç °æ¿ì ÇØ´ç ÇÁ·Î±×·¥¿¡ [ Old or patched version ]ÀÌ Ãâ·ÂµË´Ï´Ù.
¨í Scan results °¢ Ç׸ñÀÇ °Ë»ç°á°ú¸¦ °£·«È÷ º¸¿©Áִ ȸéÀÔ´Ï´Ù.
|
|