{"id":31355,"date":"2022-12-22T09:33:24","date_gmt":"2022-12-22T01:33:24","guid":{"rendered":"http:\/\/lrxjmw.cn\/?p=31355"},"modified":"2022-12-22T09:33:37","modified_gmt":"2022-12-22T01:33:37","slug":"linux-6th-ddos-virus","status":"publish","type":"post","link":"https:\/\/lrxjmw.cn\/linux-6th-ddos-virus.html","title":{"rendered":"\u65b0\u53d1\u73b0\u7684\u7b2c6\u4e2aLinuxDdos\u6728\u9a6c"},"content":{"rendered":"
\u5bfc\u8bfb<\/td>\n | Linux \u7528\u6237\u53c8\u6709\u4e00\u4e2a\u6728\u9a6c\u9700\u8981\u82e6\u607c\u4e86\uff0c\u5c31\u50cf\u4ee5\u5f80\u4e00\u6837\uff0c\u8fd9\u4e9b\u574f\u86cb\u5927\u591a\u90e8\u7f72\u5728\u88ab\u52ab\u6301\u7684 Linux \u7cfb\u7edf\u4e0a\uff0c\u5e76\u5728\u63a5\u53d7\u5230\u547d\u4ee4\u540e\u53d1\u8d77 DDoS \u653b\u51fb\u3002\u53d1\u73b0\u4e86\u8fd9\u4ef6\u4e8b\u7684 Dr.Web \u7684\u5b89\u5168\u7814\u7a76\u4eba\u5458\u8bf4\uff0c\u6728\u9a6c\u4f3c\u4e4e\u662f\u901a\u8fc7\u7834\u58f3\u6f0f\u6d1eShellshock\u611f\u67d3\u7684\u8fd9\u4e9bLinux \u673a\u5668\u7684\uff0c\u73b0\u5728\u4ecd\u7136\u6709\u5f88\u591a\u8bbe\u5907\u6ca1\u6709\u8865\u4e0a\u8fd9\u4e2a\u6f0f\u6d1e\u3002<\/strong><\/td>\n<\/tr>\n<\/table>\n <\/p>\n \u8be5\u6728\u9a6c\u88ab\u547d\u540d\u4e3a Linux.DDoS.93<\/strong>\uff0c\u5b83\u9996\u8981\u4f1a\u4fee\u6539 \/var\/run\/dhcpclient-eth0.pid \u8fd9\u4e2a\u6587\u4ef6\uff0c\u5e76\u901a\u8fc7\u5b83\u5728\u8ba1\u7b97\u673a\u542f\u52a8\u65f6\u8fd0\u884c\u3002\u5982\u679c\u8be5\u6587\u4ef6\u4e0d\u5b58\u5728\uff0c\u5c31\u4f1a\u81ea\u5df1\u521b\u5efa\u4e00\u4e2a\u3002\u5f53\u8be5\u6728\u9a6c\u8fd0\u884c\u8d77\u6765\u4ee5\u540e\u4f1a\u8fdb\u884c\u521d\u59cb\u5316\uff0c\u5b83\u4f1a\u542f\u52a8\u4e24\u4e2a\u8fdb\u7a0b\uff0c\u4e00\u4e2a\u7528\u4e8e\u4e0e C&C \uff08\u63a7\u5236\uff09\u670d\u52a1\u5668\u901a\u8baf\uff0c\u53e6\u5916\u4e00\u4e2a\u7528\u4e8e\u786e\u4fdd\u6728\u9a6c\u7684\u7236\u8fdb\u7a0b\u4e00\u76f4\u8fd0\u884c\u3002<\/p>\n \u5f53\u63a7\u5236\u8be5\u6728\u9a6c\u7f51\u7edc\u7684\u653b\u51fb\u8005\u53d1\u8d77\u653b\u51fb\u547d\u4ee4\u65f6\uff0c\u8fd9\u4e2a\u6728\u9a6c\u4f1a\u542f\u52a8 25 \u4e2a\u5b50\u8fdb\u7a0b<\/strong>\u6765\u8fdb\u884c DDoS \u653b\u51fb\u3002\u5f53\u524d\u8be5\u6728\u9a6c\u53ef\u4ee5\u53d1\u51fa UDP \u6d2a\u6cdb\uff08\u9488\u5bf9\u968f\u673a\u6216\u7279\u5b9a\u7aef\u53e3\uff09\uff0cTCP \u6d2a\u6cdb\uff08\u7b80\u5355\u7684\u5305\uff0c\u6216\u7ed9\u6bcf\u4e2a\u5305\u968f\u673a\u589e\u52a0\u81f3\u591a 4096 \u5b57\u8282\u7684\u6570\u636e\uff09\u548c HTTP \u6d2a\u6cdb\uff08\u901a\u8fc7 POST\u3001GET \u6216 HEAD \u8bf7\u6c42\uff09\u3002\u800c\u4e14\uff0c\u8be5\u6728\u9a6c\u8fd8\u80fd\u81ea\u6211\u66f4\u65b0\u3001\u81ea\u6211\u5220\u9664\u3001\u7ec8\u6b62\u81ea\u5df1\u7684\u8fdb\u7a0b\u3001ping\u3001\u4ece C&C \u670d\u52a1\u5668\u4e0b\u8f7d\u548c\u8fd0\u884c\u6587\u4ef6\u3002<\/p>\n \u8fd9\u4e9b\u5b57\u7b26\u4e32\u5927\u591a\u6570\u4e0e\u4fe1\u606f\u5b89\u5168\u9886\u57df\u6709\u5173\uff0c\u4f3c\u4e4e\u662f\u4e3a\u4e86\u9632\u6b62\u5b89\u5168\u7814\u7a76\u4eba\u5458\u7684\u53cd\u5411\u5de5\u7a0b\u7814\u7a76\uff0c\u6216\u8005\u662f\u4e3a\u4e86\u907f\u514d\u611f\u67d3\u8be5\u6076\u610f\u8f6f\u4ef6\u4f5c\u8005\u81ea\u5df1\u7684\u673a\u5668\u3002\u5728\u611f\u67d3\u8fc7\u7a0b\u4e2d\uff0c\u8be5\u6728\u9a6c\u4e5f\u4f1a\u626b\u63cf\u5b83\u7684\u65e7\u7248\u672c\uff0c\u5e76\u4f1a\u5173\u95ed\u65e7\u7248\u672c\u7136\u540e\u5b89\u88c5\u4e00\u4e2a\u65b0\u7684\u3002\u8fd9\u610f\u5473\u7740\u8fd9\u662f\u4e00\u4e2a\u81ea\u52a8\u66f4\u65b0\u7cfb\u7edf\uff0c\u8be5\u6728\u9a6c\u7684\u6700\u65b0\u7248\u672c\u603b\u662f\u4f1a\u51fa\u73b0\u5728\u88ab\u611f\u67d3\u7684\u673a\u5668\u4e0a\u3002<\/p>\n Linux\u662f\u8fc7\u53bb\u4e00\u4e2a\u6708\u4ee5\u6765\u6700\u70ed\u95e8\u7684\u6728\u9a6c\u653b\u51fb\u5e73\u53f0\uff0c\u5728\u6700\u8fd1 30 \u5929\u5185\uff0c\u5b89\u5168\u7814\u7a76\u4eba\u5458\u5df2\u7ecf\u53d1\u73b0\u3001\u5206\u6790\u548c\u66dd\u5149\u4e86\u5176\u5b83\u4e94\u4e2a Linux \u6728\u9a6c\uff1a Rex<\/strong>\u3001PNScan<\/strong>\u3001Mirai<\/strong>\u3001 LuaBot <\/strong>\u548c Linux.BackDoor.Irc<\/strong>\u3002<\/p>\n \u539f\u6587\u6765\u81ea\uff1ahttps:\/\/linux.cn\/article-7782-1.html<\/a><\/p>\n |