´òÓ¡

solarisÖеÄϵͳlogÈÕÖ¾Ô­Àí·ÖÎö

solarisÖеÄϵͳlogÈÕÖ¾Ô­Àí·ÖÎö

×÷Ϊ¹¥»÷Õßµ±È»ÒªÖªµÀϵͳÊÇÈçºÎ¼Í¼Óû§µÄ»î¶¯µÄÇé¿öµÄÔ­ÀíµÄÁË£¬ºÇºÇ£¬²»È»ip±»¼ÇÏÂÀ´¶¼²»ÖªµÀ£¡

ºÇºÇ£¬ÆäʵһЩÈËÖ»»áµ½/var/adm/Ŀ¼ÀïȥɾÈÕÖ¾£¬ÄÇÊǺܱ¿ºÜ±¿µÄ×ö·¨¡£


ǰ¶Îʱ¼äÔÚwww.unixaid.net½áʶÁËÒ»¸öÍâµØµÄÏ ... ÑÕâЩдÏÂÀ´£¬ºÇºÇ¡£

unixϵͳµÄÈÕÖ¾ÆäʵÊǷdz£¸´ÔÓºÍÇ¿´óµÄ£¬ÌرðÊÇsolarisϵͳ£¬ÒòΪԴÂëµÄ²»¹«¿ª£¬ËùÒÔ±»ÃÉÉÏÁËÒ»²ãÉñÃØµÄÃæÉ´£¬ÎÒÑо¿·ÖÎöÁËÒ»Õó×ӵóöµÄ½áÂۺʹó¼Ò·ÖÏí£¬ÎÒµÄÄÜÁ¦ÓÐÏÞ£¬»¹Íû´ó¼Ò¶à¶àÖ¸½Ì¡£

¸ºÔðÈÕÖ¾¼ÇÕʵÄÓÐÁ½¸öÊØ»¤½ø³Ì£ºklogd,syslogd£¬ÎÒ×ÅÖØ½²ÕâÁ½¸ö½ø³Ì£¬µ±È»»¹Óнø³Ì¼ÇÕʽø³Ì£¬¾Í²»¶à½éÉÜÁË£¬ºÇºÇ£¬ÒòΪ»ù±¾ÉÏËùÓеÄϵͳ¶¯×÷¶¼»á±»ÕâÁ½¸ö½ø³Ì¼àÊÓ²¢¼Í¼£¬´ó¼ÒÈç¹ûÒª±àдһЩϵͳ³ÌÐòµÄ»°£¬Ò²»áÓõ½syslogÕâ¸ö½Ó¿ÚµÄ£¬ºÇºÇ£¬klogdÖ÷Òª¼Í¼һЩϵͳÄں˵͝×÷£¬¶Ô¹¥»÷Õß×îÊÜÓ°ÏìµÄÊÇsyslogdÕâ¸ö½ø³Ì.Ëü¿ÉÒÔ½ÓÊÕ·ÃÎÊϵͳµÄÈÕÖ¾ÐÅÏ¢²¢ÇÒ¸ù¾Ý/etc/syslog.confÅäÖÃÎļþÖеÄÖ¸Áî´¦Àí
ÕâЩÐÅÏ¢¡£Òò´Ë£¬ÈκÎÏ£ÍûÉú³ÉÈÕÖ¾ÐÅÏ¢µÄ³ÌÐò¶¼¿ÉÏòsyslog½Ó¿Úºô½ÐÀ´Éú³É¸ÄÐÅÏ¢¡£´ó²¿·ÖÄÚ²¿ÏµÍ³¹¤¾ßÈçÓʼþºÍ´òӡϵͳ¶¼ÊÇÈç´ËÉú³ÉÐÅÏ¢µÄ£¬Ðí¶àÐÂÔöµÄ³ÌÐòÈçTCP_wrappersºÍSSHÒ²ÊÇÈç´Ë¹¤×÷µÄ¡£½²µ½ÕâÀ´ó¼ÒÓеã¸ÅÄîÁ˰ɣ¿ºÇºÇ
/etc/syslog.confµÄ¸ñʽ±È½Ï¸´ÔÓ£¬´ó¼Ò¿ÉÒԲο¼Ò»ÏÂÓйØÊé¼®£¬Ö÷ÒªÊÇÈçÏÂÓï¾äÐÎʽ£º
facility.level¡¡ action
facility´ú±í¸÷ÖÖ·þÎñ£¬level´ú±ísyslogµÄÈÏÖ¤¼¶±ð£¬action´ú±íµÄÊÇÕë¶ÔÇ°ÃæÐÅÏ¢µÄ´¦Àí¡£´ó¼Ò¿ÉÒÔ×¢Òâaction×ֶΣ¬ÓÐʱºò»á°ÑÐÅÏ¢·¢Ë͵½ÁíÍâһ̨»úÆ÷¶ø²»ÊÇÊìϤµÄ/var/adm/messagesµÄ£¬ÕâÏÂÓ¦¸ÃÖªµÀÕâ¸öÎļþµÄÖØÒªÐÔÁ˰ɣ¿Èç¹ûÕæ°ÑÈÕÖ¾·¢µ½ÁíÍâһ̨»úÆ÷µÄ»°£¬¾ÍÏë°ì·¨°ÑÄÇ̨»úÆ÷dosµôÁË£¬²»ÊÇËüËÀÄãÊÇÄãÍö°¡£¬ºÇºÇ£¬ÓÐʱ»á·¢Ë͵½/dev/console,/dev/tty1»ò/dev/lp1µÈµÈÕâÑùµÄÉ豸£¬¾ÍÊÇ·¢Ë͵½Öն˰¡£¬ºÇºÇ£¬ÏëÏëÈç¹ûÄÇÖÕ¶Ë×÷µÄÊÇϵͳ¹ÜÀíÔ±£¬Äã²»ÊǺܲң¿

ÏÖÔÚ´ó¼ÒÓ¦¸ÃÖªµÀ²»ÊÇɾɾ/var/adm/messages¾ÍÁËʵİÉ?ºÇºÇ

ºÃ£¬ÏÂÃæ½éÉÜÒ»ÏÂsolarisµÄÁíÍâÒ»¸ö¼ÇÕÊ£¬¾ÍÊÇwtmpºÍutmp£¬ËµÃ÷һϴó¼Ò³£¼ûµ½µÄwtmpxºÍutmpxÊÇwtmpºÍutmpµÄÀ©Õ¹°ÕÁË£¬´ó¼Ò¿ÉÒԲο´wtmp.h£¬utmp.hÀïµÄ¶¨ÒåµÄÊý¾Ý½á¹¹£¬»áÓÐд¸ÅÄºÇºÇ£¬ÔÚsolarisÀïÊÇͨ¹ýutmpd£¬wtmpdÕâÁ½¸ö½ø³ÌÀ´½øÐмÇÕʵģ¬È»ºóͨ¹ýutmppipeÕâ¸ö¹ÜµÀÎļþÏò/var/adm/utmpxÕâ¸öÎļþдÊý¾Ý£¬µ±È»utmpxÕâ¸öÎļþ²»ÊÇÏómessagesÒ»ÑùÊÇÎı¾ÐÎʽµÄ£¬ËüÊǶþ½øÖƵģ¬Ö»ÓÐwho,fingerÃüÁî¿ÉÒÔ·ÃÎÊ£¬ºÇºÇ£¬´ó¼ÒÖªµÀÁ˰ɣ¿¶ølastÃüÁîÊÇ·ÃÎÊwtmpxµÄ¡£utmpÊǼͼÓû§µÄ¶¯Ì¬»á»°Óõ쬶øwtmpÊǼͼÓû§µÄµÇ½ÓëÍÆ³öµÄ»î¶¯µÄ£¬Õâ¾ÍÊÇÇø±ð£¬ºÇºÇ¡£Ð´ÕâÆª

ÎÄÕÂÖ»ÊÇÒªÌáÐÑ´ó¼Ò²»ÒªËæ±ãɾÈÕÖ¾£¬ÄǺÜɵµÄ£¬ºÇºÇ£¬×îºÃ×Ô¼º±àдһЩɾÈÕÖ¾µÄС¹¤¾ß£¬ºÜÈÝÒ×£¬´ó¼Ò²Î¿¼Ò»ÏÂutmpÕâ¸öÊý¾Ý½á¹¹¾Í¿ÉÒÔÁË£¬Ò²¿ÉÒÔÓÃÒ»¸öÃüÁîÀ´É¾³ýmessagesÖеļͼ£º
eagle~# more /var/adm/messages|grep -v »ò >/var/adm/messages
ºÜ¼òµ¥²»ÊÇô£¿ºÇºÇ£¬µ±È»utmp,wtmpÖеļͼ¾ÍÒªÓóÌÐò½â¾öÁË£¬Ò²ÓÐÏֳɵijÌÐò±ÈÈ磺

wtmpdump.c,marry.c,remove.cµÈµÈ£¬ºÇºÇ¶¼²»´íµÄ£¬ÎÒÖ÷Ò³ÉÏÓÐÏÂÔØ£¬ºÇºÇ
attacker.qzone.com

ºÃÁË£¬¾Í˵Õâô¶àÁË£¬ÖØÉêÒ»¾ä£¬ÎÒÖ»ÊÇΪÁËÈôó¼Ò½øÐа®¹úÖ÷ÒåÐж¯µÄʱºò×¢ÒâÒÔÏÂÉÆºóµÄ¹¤×÷£¬ºÇºÇÆäÖÐÇ£Éæµ½µÄÖ»ÊǷdz£¶à£¬ÎҺܶàûÓÐÏêϸ˵Ã÷ºÍ½²½â£¬Ï£Íû´ó¼ÒÖØÊÓÈÕÖ¾£¬²Î¿¼Ò»ÏÂÓйØ×ÊÁÏ¡£

ÍüÁË£¬ÕâЩÊÇsolarisÖеÄÇé¿ö£¬ºÇºÇ£¬ÔÚlinuxÀïÓÖ´ó²»Ò»Ñù£¬ºÇºÇ£¬linuxÀïûÓÐutmpdÕâ¸ö½ø³Ì£¬ÊÇͨ¹ýPAMµÄÈÏ֤ģ¿éÀ´½øÐмÇÕʵģ¬PAMµÄ×ÊÁÏ´ó¼Ò¿ÉÒԲο¼Ò»ÏÂÊé¼®ºÜ¸´ÔÓ£¬ËµµÄ»°»á½üÍò×ÖÄØ£¬ºÇºÇ

  

×¢£º±¾ÎİæÈ¨Îª²¹ÌìÍøÂ簲ȫ¹«Ë¾£¬×ªÔØÇë±£³ÖÎÄÕµÄÍêÕûÐÔ£¡

TOP

תÌù ²»´í ÄÚÈݲ»´í¹þ
ÄУº¡°ÎÒ¿ÉÒÔÏòÄãÎÊ·Â𣿡±
Å®£º¡°µ½ÄÇÀ¡±
ÄУº¡°µ½ÄãÐÄÀ
Å®£º¡°±§Ç¸£¬´Ë·²»Í¨¡±

TOP


¸ÐлһֱÒÔÀ´Äú¶ÔÎÒÃǵÄÖ§³Ö£¡
µ±Ç°Ê±Çø GMT+8, ÏÖÔÚʱ¼äÊÇ 2008-9-6 11:30 ¾©ICPÖ¤060528 ºÅ

Designed By 17DST