今天早上收到通知说服务器的root密码被修改了,赶紧测试,果然无法链接登陆,通过其他渠道经过一系列周折恢复密码,经过初步诊断在无人修改密码的情况下被修改了密码,只有系统被***的可能性了。然后在使用命令查看进程时出现下面的提示:
- Unknown HZ value! (288) Assume 100.
- root 15575 0.0 0.0 61116 740 pts/3 S 11:40 0:00 grep httpd
- Unknown HZ value! (##) Assume 100 -- You've been hacked!
- On RHEL or Centos 4 or 5, If you run the linux command top and you see something like:
- "Unknown HZ value! (75) Assume 100"
- Yours might not say "75" -- it could be any number.
- If you see this, you should run rkhunter immediately, because your box has probably been taken over by arootkit -- either SHV4 or SHV5.
- The only reason you see this clue "Unknown HZ value" is because the rootkit replaces the top command (among others)with a substitute top command that will hide its processes. Their replacement top is old (version 1.2) and cannothandle the HZ value of the 2.6 linux kernel.
- Sad to say, but if this happens to you, its time to reinstall your OS!
- Rootkit checks...
- Rootkits checked : 258
- Possible rootkits: 3
- Rootkit names : cb Rootkit, SHV4 Rootkit, SHV5 Rootkit