{"id":3620,"date":"2018-08-07T16:56:59","date_gmt":"2018-08-07T08:56:59","guid":{"rendered":"https:\/\/dingxuan.info\/wp\/?p=3620"},"modified":"2018-08-07T17:07:00","modified_gmt":"2018-08-07T09:07:00","slug":"%e9%83%a8%e7%bd%b2%e7%97%85%e6%af%92%e5%8f%8a%e6%81%b6%e6%84%8f%e8%84%9a%e6%9c%ac%e6%a3%80%e6%b5%8b%e7%a8%8b%e5%ba%8f-rkhunter-clamav-lmd","status":"publish","type":"post","link":"https:\/\/ybzx.vip\/wp\/?p=3620","title":{"rendered":"\u90e8\u7f72\u75c5\u6bd2\u53ca\u6076\u610f\u811a\u672c\u68c0\u6d4b\u7a0b\u5e8f Rkhunter \/ ClamAV \/ LMD"},"content":{"rendered":"<div>\n<div class=\"ennote\">\n<div><span style=\"font-size: 10pt;\">\u90e8\u7f72\u4e09\u4e2a\u68c0\u6d4b\u5de5\u5177rkhunter\uff0cClamAV\u53ca<\/span><a style=\"font-size: 10pt;\" href=\"https:\/\/www.rfxn.com\/projects\/linux-malware-detect\/\" target=\"_blank\" rel=\"noopener\">Linux Malware Detect<\/a><span style=\"font-size: 10pt;\">\u00a0\uff08LMD\uff09\u3002\u5206\u522b\u7528\u4e8erootkit\u548c\u6076\u610f\u811a\u672c\u68c0\u6d4b\u3002<\/span><\/div>\n<div><\/div>\n<div><span style=\"font-size: 24px;\">1.ClamAV<\/span><\/div>\n<div><\/div>\n<div style=\"box-sizing: border-box; padding: 8px; font-family: Monaco, Menlo, Consolas, 'Courier New', monospace; font-size: 12px; color: #333333; border-top-left-radius: 4px; border-top-right-radius: 4px; border-bottom-right-radius: 4px; border-bottom-left-radius: 4px; background-color: #fbfaf8; border: 1px solid rgba(0, 0, 0, 0.14902); background-position: initial initial; background-repeat: initial initial; -en-codeblock: true;\">\n<div><span style=\"font-size: 10pt;\">yum install clamav clamav-update clamav-scanner-systemd clamav-server-systemd<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">\u6216<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">yum install clamav<\/span><\/div>\n<div><\/div>\n<div><span style=\"font-size: 10pt;\">sudo sed -i -e &#8220;s\/^Example\/#Example\/&#8221; \/etc\/freshclam.conf<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">sudo sed -i -e &#8220;s\/^Example\/#Example\/&#8221; \/etc\/clamd.d\/scan.conf<\/span><\/div>\n<div><\/div>\n<div><span style=\"font-size: 10pt;\">freshclam<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">clamscan -r -i \/var\/www\/html<\/span><\/div>\n<\/div>\n<div><\/div>\n<div><\/div>\n<div><span style=\"font-size: 24px;\">2.Rkhunter<\/span><\/div>\n<div><\/div>\n<div style=\"box-sizing: border-box; padding: 8px; font-family: Monaco, Menlo, Consolas, 'Courier New', monospace; font-size: 12px; color: #333333; border-top-left-radius: 4px; border-top-right-radius: 4px; border-bottom-right-radius: 4px; border-bottom-left-radius: 4px; background-color: #fbfaf8; border: 1px solid rgba(0, 0, 0, 0.14902); background-position: initial initial; background-repeat: initial initial; -en-codeblock: true;\">\n<div><\/div>\n<div><span style=\"font-size: 10pt;\">yum install rkhunter<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">rkhunter &#8211;propupd<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">rkhunter -u<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">rkhunter &#8211;checkall<\/span><\/div>\n<div><\/div>\n<div><span style=\"font-size: 10pt;\">cat \/var\/log\/rkhunter\/rkhunter.log | grep -i warning<\/span><\/div>\n<\/div>\n<div><\/div>\n<div><\/div>\n<div><span style=\"font-size: 24px;\">3.LMD<\/span><\/div>\n<div style=\"box-sizing: border-box; padding: 8px; font-family: Monaco, Menlo, Consolas, 'Courier New', monospace; font-size: 12px; color: #333333; border-top-left-radius: 4px; border-top-right-radius: 4px; border-bottom-right-radius: 4px; border-bottom-left-radius: 4px; background-color: #fbfaf8; border: 1px solid rgba(0, 0, 0, 0.14902); background-position: initial initial; background-repeat: initial initial; -en-codeblock: true;\">\n<div><span style=\"font-size: 10pt;\">wget <\/span><a style=\"font-size: 10pt;\" href=\"http:\/\/www.rfxn.com\/downloads\/maldetect-current.tar.gz\" target=\"_blank\" rel=\"noopener\">http:\/\/www.rfxn.com\/downloads\/maldetect-current.tar.gz<\/a><\/div>\n<div><span style=\"font-size: 10pt;\">tar -xvf maldetect-current.tar.gz<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">cd maldetect-1.4.2<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">.\/install.sh<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">vim \/usr\/local\/maldetect\/conf.maldet<\/span><\/div>\n<\/div>\n<div><\/div>\n<div><\/div>\n<div><span style=\"font-size: 10pt;\">\/usr\/local\/maldetect\/conf.maldet\u00a0\u5178\u578b\u914d\u7f6e\uff1a<\/span><\/div>\n<div style=\"box-sizing: border-box; padding: 8px; font-family: Monaco, Menlo, Consolas, 'Courier New', monospace; font-size: 12px; color: #333333; border-top-left-radius: 4px; border-top-right-radius: 4px; border-bottom-right-radius: 4px; border-bottom-left-radius: 4px; background-color: #fbfaf8; border: 1px solid rgba(0, 0, 0, 0.14902); background-position: initial initial; background-repeat: initial initial; -en-codeblock: true;\">\n<div><span style=\"font-size: 10pt;\">email_alert=1<\/span><\/div>\n<div><span style=\"font-size: 10pt;\"><a href=\"mailto:email_addr=youremail@localhost\">email_addr=youremail@localhost<\/a><\/span><\/div>\n<div><span style=\"font-size: 10pt;\">email_subj=&#8221;Malware alerts for $HOSTNAME &#8211; $(date +%Y-%m-%d)&#8221;<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">quar_hits=1<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">quar_clean=1<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">clam_av=1<\/span><\/div>\n<\/div>\n<div><\/div>\n<div><\/div>\n<div><\/div>\n<div style=\"box-sizing: border-box; padding: 8px; font-family: Monaco, Menlo, Consolas, 'Courier New', monospace; font-size: 12px; color: #333333; border-top-left-radius: 4px; border-top-right-radius: 4px; border-bottom-right-radius: 4px; border-bottom-left-radius: 4px; background-color: #fbfaf8; border: 1px solid rgba(0, 0, 0, 0.14902); background-position: initial initial; background-repeat: initial initial; -en-codeblock: true;\">\n<div><span style=\"font-size: 10pt;\">maldet -u<\/span><\/div>\n<div><span style=\"font-size: 10pt;\">maldet &#8211;scan-all \/var\/www\/html<\/span><\/div>\n<\/div>\n<h3><span style=\"font-size: 24px;\">\u540e\u7eed\uff1a\u65e5\u5e38\u68c0\u67e5 \/ crontab\u8bbe\u7f6e<\/span><\/h3>\n<div>\n<div style=\"box-sizing: border-box; padding: 8px; font-family: Monaco, Menlo, Consolas, 'Courier New', monospace; font-size: 12px; color: #333333; border-top-left-radius: 4px; border-top-right-radius: 4px; border-bottom-right-radius: 4px; border-bottom-left-radius: 4px; background-color: #fbfaf8; border: 1px solid rgba(0, 0, 0, 0.14902); background-position: initial initial; background-repeat: initial initial; -en-codeblock: true;\">\n<div>maldet -u<\/div>\n<div>freshclam<\/div>\n<div>rkhunter -u<\/div>\n<div>rkhunter &#8211;propupd<\/div>\n<div><\/div>\n<div>rkhunter\u00a0&#8211;sk\u00a0&#8211;checkall<\/div>\n<div>maldet &#8211;scan-all \/var\/www\/html<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u90e8\u7f72\u4e09\u4e2a\u68c0\u6d4b\u5de5\u5177rkhunter\uff0cClamAV\u53caLinux Malware Detect\u00a0\uff08LMD\uff09\u3002\u5206\u522b\u7528\u4e8e &hellip; <a href=\"https:\/\/ybzx.vip\/wp\/?p=3620\" class=\"more-link\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">\u90e8\u7f72\u75c5\u6bd2\u53ca\u6076\u610f\u811a\u672c\u68c0\u6d4b\u7a0b\u5e8f Rkhunter \/ ClamAV \/ LMD<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[79],"class_list":["post-3620","post","type-post","status-publish","format-standard","hentry","category-live","tag-centos"],"_links":{"self":[{"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=\/wp\/v2\/posts\/3620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3620"}],"version-history":[{"count":0,"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=\/wp\/v2\/posts\/3620\/revisions"}],"wp:attachment":[{"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ybzx.vip\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}