┌──[root@liruilongs.github.io]-[/usr/bin] └─$cat /etc/passwd root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin:/sbin/nologin ........ oprofile:x:16:16:Special user account to be used by OProfile:/var/lib/oprofile:/sbin/nologin ┌──[root@liruilongs.github.io]-[/usr/bin] └─$
┌──[root@liruilongs.github.io]-[~] └─$cat /var/log/cron | head -3 Feb 27 03:43:13 liruilongs run-parts(/etc/cron.daily)[65785]: finished man-db.cron Feb 27 03:43:13 liruilongs anacron[59178]: Job cron.daily'' terminated Feb 27 03:43:13 liruilongs anacron[59178]: Normal exit (1 job run) ┌──[root@liruilongs.github.io]-[~] └─$
查看相关日志记录文件ls /var/spool/mail
1 2 3 4 5
┌──[root@liruilongs.github.io]-[~] └─$ls /var/spool/mail/ liruilong test tom ┌──[root@liruilongs.github.io]-[~] └─$
查看自启动日志:
查看整体系统信息, cat /var/log/message
1 2 3 4 5 6 7
┌──[root@liruilongs.github.io]-[~] └─$cat /var/log/messages | head -3 Feb 27 03:50:01 liruilongs systemd: Started Session 157 of user root. Feb 27 03:55:18 liruilongs systemd: Starting Check pmlogger instances are running... Feb 27 03:55:21 liruilongs systemd: Started Check pmlogger instances are running. ┌──[root@liruilongs.github.io]-[~] └─$
查看验证和授权方面的信息, cat /var/log/secure
1 2 3 4 5 6 7 8 9
┌──[root@liruilongs.github.io]-[~] └─$cat /var/log/secure | head -5 Feb 27 11:17:41 liruilongs sshd[110566]: pam_unix(sshd:session): session closed for user root Feb 27 17:38:04 liruilongs sshd[148418]: Accepted password for root from 192.168.26.1 port 11561 ssh2 Feb 27 17:38:04 liruilongs sshd[148418]: pam_unix(sshd:session): session opened for user root by (uid=0) Feb 28 10:05:52 liruilongs sshd[148418]: pam_unix(sshd:session): session closed for user root Feb 28 12:12:37 liruilongs sshd[94739]: Accepted password for root from 192.168.26.1 port 13575 ssh2 ┌──[root@liruilongs.github.io]-[~] └─$
# Some files get updated automatically, so the inode/ctime/mtime change # but we want to know when the data inside them changes. DATAONLY = p+n+u+g+s+acl+selinux+xattrs+sha256
# Next decide what directories/files you want in the database. Aide # uses a first match system. Put file specific instructions before generic # matches. e.g. Put file matches before directories.
┌──[root@liruilongs.github.io]-[~] └─$echo aide test >> /tmp/test.txt
对/tmp目录下的文件进行修改,重新使用aide进行校验比对
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
┌──[root@liruilongs.github.io]-[~] └─$aide --check AIDE 0.15.1 found differences between database and filesystem!! Start timestamp: 2022-03-03 19:10:51
Summary: Total number of files: 2712 Added files: 1 Removed files: 0 Changed files: 0
┌──(root💀Liruilong)-[/mnt/e/docker] └─# nmap -n -A 192.168.26.55 Starting Nmap 7.91 ( https://nmap.org ) at 2022-03-03 19:27 CST Nmap scan report for 192.168.26.55 Host is up (0.00087s latency). Not shown: 995 closed ports PORT STATE SERVICE VERSION #目标主机开启了22端口,使用的是ssh服务,使用软件为OpenSSH 7.4 22/tcp open ssh OpenSSH 7.4 (protocol 2.0) | ssh-hostkey: | 2048 5b:40:0e:e6:1d:70:7f:f1:05:34:8d:2b:72:a1:c5:b3 (RSA) |_ 256 f1:27:ee:82:cc:94:b2:7c:68:c9:ea:a0:88:64:20:b3 (ECDSA) #目标主机开启了80端口,使用的是http服务,使用软件为 nginx 80/tcp open http nginx | http-robots.txt: 53 disallowed entries (15 shown) | / /autocomplete/users /search /api /admin /profile | /dashboard /projects/new /groups/new /groups/*/edit /users /help |_/s/ /snippets/new /snippets/*/edit 222/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: |_ 256 03:b8:32:59:ad:e7:9c:33:63:5c:04:7a:45:68:93:cb (ED25519) 8080/tcp open http Jetty 9.4.43.v20210629 |_http-title: Site doesn''t have a title (text/html;charset=utf-8). #目标主机开启了50000端口,使用的是http服务,使用软件为 Jenkins 50000/tcp open http Jenkins httpd 2.319 |_http-title: Site doesn't have a title (text/plain;charset=UTF-8). No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). TCP/IP fingerprint: OS:SCAN(V=7.91%E=4%D=3/3%OT=22%CT=1%CU=36908%PV=Y%DS=2%DC=T%G=Y%TM=6220A6BE OS:%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=10C%TI=Z%CI=I%II=I%TS=A)SEQ( OS:SP=102%GCD=1%ISR=10C%TI=Z%TS=A)SEQ(SP=102%GCD=1%ISR=10C%TI=Z%CI=I%TS=A)O OS:PS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=M5B4S OS:T11NW7%O6=M5B4ST11)WIN(W1=7120%W2=7120%W3=7120%W4=7120%W5=7120%W6=7120)E OS:CN(R=Y%DF=Y%T=40%W=7210%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F OS:=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5 OS:(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z OS:%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF= OS:N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=8E44%RUD=G)IE(R=Y%DFI=N%T= OS:40%CD=S) Network Distance: 2 hops Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel TRACEROUTE (using port 6002/tcp) HOP RTT ADDRESS 1 0.32 ms 172.24.208.1 2 0.77 ms 192.168.26.55 #整个检测一共花费了171.45秒 OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 171.45 seconds