- 论坛徽章:
- 0
|
今天history|more一下历史操作记录,我疯了.发现很多奇怪的命令. 我贴出一部分命令,大家看看是咋回事了,是不是当做肉鸡用了?幸好没有删除我的资料.
- wget [url]http://umn.dl.sourceforge.net/sourceforge/denyhosts/DenyHosts-2.6.tar.gz[/url]
- tar -xzvf DenyHosts-2.6.tar.gz
- 363 /sbin/hdparm -tT /dev/sda
- 364 ls
- 365 /sbin/hdparm -tT /dev/sda
- 366 cd /
- 367 ll
- 368 ls
- 369 ll /home/
- 370 su - mysql
- 371 useradd nagios
- 372 chattr -i /etc/passwd
- 373 useradd nagios
- 374 chattr -i /etc/group
- 375 useradd nagios
- 376 passwd nagios
- 377 chattr +i /etc/group
- 378 chattr +i /etc/passwd
- 379 ls
- 380 userdel nagios
- cd /etc/sysconfig/
- 818 vi iptables
- 819 /etc/init.d/iptables restart
- 820 vi iptables
- 821 /etc/init.d/iptables restart
- 822 /sbin/iptables -L -n
- 823 /etc/init.d/iptables stop
- 824 chkconfig --list iptables
- 825 /etc/init.d/iptables start
- 826 vi iptables
- 827 /etc/init.d/iptables stop
- 828 /sbin/ifconfig
- 829 su cacti
- 830 tail -f /var/log/messages
- 831 tcpdump |grep 909
- 832 /sbin/ifconfig |more
- 833 tcpdump -i eth0 |grep 218.15.67
- 834 tcpdump -i eth0 |grep 909
- 835 tcpdump
- 836 tcpdump |grep -v gd
- 837 tcpdump |grep -v gd|grep -v smtp|grep -v http
- 838 arp -a
- 839 vi /etc/resolv.conf
- 840 tcpdump |grep 909
复制代码
以下是防火墙的配置也改成这样了:
- # Generated by iptables-save v1.3.5 on Thu Mar 5 15:37:35 2009
- *filter
- :INPUT ACCEPT [309880095:39739457214]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [305544893:286478456406]
- -A INPUT -s 59.41.223.0/255.255.255.0 -p tcp -m multiport --dports 909 -j ACCEPT
- -A INPUT -s 218.15.67.0/255.255.255.0 -p tcp -m multiport --dports 909 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 909 -j DROP
- COMMIT
- # Completed on Thu Mar 5 15:37:35 2009
复制代码
各位大侠,我看中了什么漏洞了,我看是MYSQL |
|