Solaris Fingerprint DataBase (sfpDB) ¤Î»È¤¤Êý
Solaris Fingerprint DataBase (sfpDB) ¤È¤Ï¡¢Sun ¤¬Ä󶡤·¤Æ¤¤¤ë MD5 ¤Ë¤è¤ë Solaris
¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤Î¥Ï¥Ã¥·¥åÃͥǡ¼¥¿¥Ù¡¼¥¹¤Ç¤¹¡£¤³¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤È¾È¹ç¤¹¤ë¤³¤È¤Ç¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤¬¡ÊÆÃ¤Ë¥³¥Þ¥ó¥ÉÅù¤¬ÉÔÀµ¿¯Æþ¼Ô¤Ë¤è¤Ã¤Æ¡Ë½ñ¤´¹¤¨¤é
¤ì¤Æ¤¤¤Ê¤¤¤«¤ò¸¡¾Ú¤¹¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
»È¤¤Êý¤Ï°Ê²¼¤Î¤è¤¦¤Ë£²Ä̤ꤢ¤ê¤Þ¤¹¡£
¢¡ ¥Ö¥é¥¦¥¶¤ò»ÈÍѤ·¡¢GUI ¤Ç¹Ô¤¦¡£
¡¡¡¡°Ê²¼¤Î¥µ¥¤¥È¤Ç MD5 ¥Ï¥Ã¥·¥åÃͤòޤêÉÕ¤±¤ë¤³¤È¤Ç¥Á¥§¥Ã¥¯¤Ç¤¤Þ¤¹¡£
¡¡¡¡¢ª¡¡
Solaris Fingerprint
DataBase
¡¡¡¡¤³¤ÎÊýË¡¤Ï¤Á¤ç¤Ã¤È¤·¤¿¥Õ¥¡¥¤¥ë¤ò¸¡ºº¤¹¤ë¤È¤¤ËÊØÍø¤Ç¤¹¡£
¢¡
sfpC.pl ¤ä
sidekick.sh ¥¹¥¯¥ê¥×¥È¤ò»ÈÍѤ·¤Æ¡¢¥³¥Þ¥ó¥É¥é¥¤¥ó¤«¤é
sfpDB ¤ò»²¾È¤·¤Ë¹Ô¤¯¥×¥í¥°¥é¥à¤òÁö¤é¤»¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
¡¡¡¡¤³¤ÎÊýË¡¤Ï¿¤¯¤Î¥Õ¥¡¥¤¥ë¤ò¤Þ¤È¤á¤Æ¥Á¥§¥Ã¥¯¤¹¤ë¤È¤¤ËÊØÍø¤Ç¤¹¡£
¡¡¡¡¾åµ¥¹¥¯¥ê¥×¥È¤Ï°Ê²¼¤Î¥µ¥¤¥È¤«¤éÆþ¼ê¤Ç¤¤Þ¤¹¡£
¡¡¡¡¢ª
Sun BluePrints OnLine -
Scripts and Tools
¡¡¡¡¥Ú¡¼¥¸²¼¤ÎÊý¤Î sfpc-1.2.tar.Z and sidekick.sh.Z ¤È¤¤¤¦¥ê¥ó¥¯¤«¤é¥À¥¦¥ó¥í¡¼¥É¤Ç¤¤Þ¤¹¡£
¤³¤³¤Ç¤Ï¼«Í³Å٤ι⤤¥¹¥¯¥ê¥×¥È¤ò»ÈÍѤ·¤Æ sfpDB ¤òÍøÍѤ¹¤ëÊýË¡¤ò¾Ò²ð¤·¤Þ¤¹¡£
¤Þ¤º¡¢¾åµ¤Î¥µ¥¤¥È¤«¤é¥¹¥¯¥ê¥×¥È¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤ÆÅ¬Åö¤Ê¥Ç¥£¥ì¥¯¥È¥ê¤ËŸ³«¤·¤Þ¤¹¡£
bash-3.00# pwd
/var/tmp/sfpDB
bash-3.00# ls
sfpC-1.2.tar.Z sidekick.sh.Z
bash-3.00# uncompress *
bash-3.00# ls
sfpC-1.2.tar sidekick.sh
bash-3.00# tar xvf sfpC-1.2.tar
x sfpC-1.2, 0 bytes, 0 ¥Æ¡¼¥×¥Ö¥í¥Ã¥¯
x sfpC-1.2/sfpC.pl, 6172 bytes, 13
¥Æ¡¼¥×¥Ö¥í¥Ã¥¯
x sfpC-1.2/README.sfpC, 8754 bytes,
18 ¥Æ¡¼¥×¥Ö¥í¥Ã¥¯
bash-3.00#
¤³¤³¤Ç¥Á¥§¥Ã¥¯¤·¤¿¤¤¥Õ¥¡¥¤¥ë¤Î md5 ¥Ï¥Ã¥·¥åÃͤòµá¤á¤Þ¤¹¡£
Solaris 10 ¤Ç¤¢¤ì¤Ð¡¢É¸½à¤ÇÆþ¤Ã¤Æ¤¤¤ë
digest
¥³¥Þ¥ó¥É¤ò»È¤Ã¤Æ¤â¤è¤¤¤Ç¤¹¤¬¡¢
sfpC.pl ¤â
sidekick.sh ¤â md5
¥³¥Þ¥ó¥É¤ò»ÈÍѤ¹¤ë¤è¤¦¤ËÀ߷פµ¤ì¤Æ¤¤¤ë¤è¤¦¤Ç¤¹¤Î¤Ç¡¢md5 ¥³¥Þ¥ó¥É¤Î¥Ð¥¤¥Ê¥ê¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Þ¤¹¡£
¢ª
md5 ¥³¥Þ¥ó¥É¤Î¥À¥¦¥ó¥í¡¼¥É
¥À¥¦¥ó¥í¡¼¥É¤·¤¿ md5 ¥³¥Þ¥ó¥É¤Î¥Ð¥¤¥Ê¥ê¤ò°Ê²¼¤Î¤è¤¦¤Ë¥»¥Ã¥È¥¢¥Ã¥×¤·¤Þ¤¹¡£
bash-3.00# pwd
/var/tmp/sfpDB
bash-3.00# ls
md5.tar.Z
sfpC-1.2 sfpC-1.2.tar sidekick.sh
bash-3.00# uncompress md5.tar.Z
bash-3.00# tar xvf md5.tar
x md5, 0 bytes, 0 ¥Æ¡¼¥×¥Ö¥í¥Ã¥¯
x md5/md5-x86, 23452 bytes, 46
¥Æ¡¼¥×¥Ö¥í¥Ã¥¯
x md5/md5-sparc, 23892 bytes, 47
¥Æ¡¼¥×¥Ö¥í¥Ã¥¯
bash-3.00# cp md5/md5-sparc /usr/sbin/md5
bash-3.00# chmod 700 /usr/sbin/md5
bash-3.00# ls -l /usr/sbin/md5
-rwx------ 1
root root
23892 8·î 16Æü 13:17 /usr/sbin/md5
bash-3.00#
»ÈÍÑÊýË¡¤Ï´Êñ¤Ç°Ê²¼¤Î¤è¤¦¤Ë¼Â¹Ô¤¹¤ë¤À¤±¤Ç¤¹¡£
bash-3.00# md5 /usr/bin/ls
MD5 (/usr/bin/ls) =
ae08d6328d118dfc6ee87cd42436972e
¤Á¤Ê¤ß¤ËƱ¤¸½ÐÎϤò Solaris 10 ɸ½à¤Î
digest
¥³¥Þ¥ó¥É¤ÇÆÀ¤ë¾ì¹ç¤Ï¡¢°Ê²¼¤Î¤è¤¦¤Ë¼Â¹Ô¤·¤Þ¤¹¡£°ì¸«Ê£»¨¤Ë¸«¤¨¤Þ¤¹¤¬¡¢Â¿µ¡Ç½¤Ê¤¿¤á¥¢¥ë¥´¥ê¥º¥à»ØÄê¤Ê¤É¤¬Æþ¤Ã¤Æ¤¤¤ë¤À¤±¤Ç¤¹¡£¤Þ¤¿¥Ñ¥¤¥×(|)¤Î±¦Â¦
¤Ï¾®Ê¸»ú¤Ç½ÐÎϤµ¤ì¤ë md5 ¤ò Âçʸ»ú¤Î MD5 ¤ËÊÑ´¹¤·¤Æ¤¤¤ë¤À¤±¤Ç¤¹¡£
¡ÊÃí°Õ¡§sfpDB ¤Ç¤ÏÂçʸ»ú¤Ç MD5 ¤Èµ½Ò¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¡Ë
bash-3.00# digest -a md5 -v /usr/bin/ls | sed
's/md5/MD5/'
MD5 (/usr/bin/ls) =
ae08d6328d118dfc6ee87cd42436972e
¡Ú
sfpC.pl ¥¹¥¯¥ê¥×¥È¤Î¼Â¹Ô¡Û
½àÈ÷¤¬¤Ç¤¤¿¤é sfpC.pl ¥¹¥¯¥ê¥×¥È¤Î¤¢¤ë¾ì½ê¤Þ¤Ç°Üư¤·¤Þ¤¹¡£
bash-3.00# pwd
/var/tmp/sfpDB
bash-3.00# cd sfpC-1.2
bash-3.00# ls
README.sfpC sfpC.pl
¤³¤Îµ»ö¤ò½ñ¤¤¤Æ¤¤¤ë 2007ǯ8·î16Æü»þÅÀ¤Ë¥À¥¦¥ó¥í¡¼¥É¤·¤¿
sfpC.pl
¤Ç¤Ï¾åµ¥¹¥¯¥ê¥×¥È¤Ë¤¢¤ë sfpDB ¤Î URL ¤Ï¸Å¤¤¤â¤Î¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£
sfpC.pl ¤ò¥¨¥Ç¥£¥¿¤Ç³«¤¤¤Æ 137
¹ÔÌÜÉÕ¶á¤Î°Ê²¼¤Î¥¨¥ó¥È¥ê¤ò½ñ¤´¹¤¨¤Æ¤¯¤À¤µ¤¤¡£
Êѹ¹Á°¡§
my $req = POST
'http://sunsolve.Sun.COM/pub-cgi/fileFingerprints.pl',
¢
Êѹ¹¸å¡§
my $req = POST
'http://jp.sunsolve.sun.com/fileFingerprints.do',
¤½¤·¤Æ¡¢Àè¤Û¤É¤Î md5 ¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Æ¥Á¥§¥Ã¥¯¤·¤¿¤¤¥Õ¥¡¥¤¥ë¤Î MD5 ¥Ï¥Ã¥·¥å¤ò¥Õ¥¡¥¤¥ë¤ËÍî¤È¤·¤Þ¤¹¡£¤³¤³¤Ç¤Ï
/usr/bin/ls ¥³¥Þ¥ó¥É¤òÄ´¤Ù¤ë¤È²¾Äꤷ¤Þ¤¹¡£
bash-3.00# md5 /usr/bin/ls > md5.out
bash-3.00# cat md5.out
MD5 (/usr/bin/ls) =
ae08d6328d118dfc6ee87cd42436972e
¸å¤Ï¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ë
sfpC.pl
¥¹¥¯¥ê¥×¥È¤ò°Ê²¼¤Î¤è¤¦¤Ë¼Â¹Ô¤¹¤ë¤À¤±¤Ç¤¹¡£
¢¨Ãí°Õ¡§ Solaris ɸ½à¤Î perl
¤Ç¤ÏɬÍפʥ⥸¥å¡¼¥ë¤¬¸«¤Ä¤«¤é¤º¡¢¼ºÇÔ¤¹¤ë¤³¤È¤¬¤¢¤ê¤Þ¤¹¡£README.sfpC ¥Õ¥¡¥¤¥ë¤ò¸«¤Æ¡¢perl
¤ËɬÍפʥ⥸¥å¡¼¥ë¤òÁȤ߹þ¤à¤«¡¢ÊÌÅÓ perl ¥Ñ¥Ã¥±¡¼¥¸¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ sfpC.pl Æâ¤Î perl
¤Î¥Ñ¥¹¤òÊѹ¹¤¹¤ë¤Ê¤É½¤Àµ¤¬É¬ÍפǤ¹¡£
bash-3.00# ./sfpC.pl md5.out
ae08d6328d118dfc6ee87cd42436972e - - 1 match(es)
canonical-path: /usr/bin/ls
package: SUNWcsu
version: 11.10.0,REV=2005.01.21.15.53
architecture: sparc
source: Solaris 10/SPARC
patch: 118855-36RS
¡Ú
sidekick.sh ¥¹¥¯¥ê¥×¥È¤Î¼Â¹Ô¡Û
¤Þ¤º
sidekick.sh
¥¹¥¯¥ê¥×¥È¤Î°Ê²¼¤ÎÉôʬ¤ò¥·¥¹¥Æ¥à¤Î¹½À®¤Ë¹ç¤ï¤»¤ÆÊÔ½¸¤·¡¢¥¹¥¯¥ê¥×¥È¤Ë¼Â¹Ô¸¢¤ò¤Ä¤±¤Þ¤¹¡£
bash-3.00# vi sidekick.sh
----------------------------
...
SIDEKICK_MD5=/usr/sbin/md5
...
SIDEKICK_PERL=/usr/local/bin/perl
...
SIDEKICK_SFPC=/var/tmp/sfpDB/sfpC-1.2/sfpC.pl
-----------------------------------
bash-3.00# chmod 744 sidekick.sh
bash-3.00# ls -l sidekick.sh
-rwxr--r-- 1
root root
10711 Aug 16 13:03 sidekick.sh
°Ê²¼¤Î¤è¤¦¤Ë¼Â¹Ô¤¹¤ë¤È´Êñ¤Ê»ÈÍÑÊýË¡¤¬½ÐÎϤµ¤ì¤Þ¤¹¡£
bash-3.00# ./sidekick.sh -h
./sidekick.sh
-R
new-root-dir Specify an alternate root directory.
-r
Find files commonly found in root kits.
-u
Find files with the set-uid bit set.
-g
Find files with the set-gid bit set.
-s
Find files with the sticky bit set.
-U
Find files with no valid user.
-G
Find files with no valid group.
-a
Find all files. warning: slow and many false
positives will ocure
-S
Standalone mode. sfpC will not be executed.
-h
Display this message.
Î㤨¤Ð¡¢rootkit ¤Ê¤É¤Î¸¡½Ð¤Ë»ÈÍѤ¹¤ë¤È¤¤Ë¤Ï°Ê²¼¤Î¤è¤¦¤Ë¼Â¹Ô¤·¤Þ¤¹¡£¤³¤ì¤Ï rootkit
¤Ë¤è¤Ã¤ÆÃÖ¤´¹¤¨¤é¤ì¤½¤¦¤Ê¥³¥Þ¥ó¥É¤¬¤¢¤é¤«¤¸¤á¥¹¥¯¥ê¥×¥ÈÆâ¤ËÅÐÏ¿¤µ¤ì¤Æ¤ª¤ê¡¢£±¤Ä£±¤Ä¤ËÂФ·¤ÆÁ°½Ò¤Î sfpC.pl
¥¹¥¯¥ê¥×¥È¤¬¼Â¹Ô¤µ¤ì¤Æ¤¤¤ë¤À¤±¤Ç¤¹¡£
bash-3.00# ./sidekick.sh -r
Searching for files commonly found
in rootkits.
The output has been saved to
rootkitfiles-md5.20070817110238.
Using sfpC to process MD5
signatures from file, rootkitfiles-md5.20070817110238.
00a7737d352eca7e4e7e7a7434bdc9d5 - - 1 match(es)
canonical-path: /usr/bin/date
package: SUNWcsu
version: 11.10.0,REV=2005.01.21.15.53
architecture: sparc
source: Solaris 10/SPARC
patch: 107551-01
...
¡Ê°Ê²¼¾Êά¡Ë
¾åµ·ë²Ì¤Î¤è¤¦¤Ë sfpDB ¤Ë¥Þ¥Ã¥Á (match) ¤·¤Æ¤¤¤ì¤Ð°ÂÁ´¤Ç¤¹¡££±¤Ä¤Ç¤â 0 match
¤Ê¤É¤Îɽµ¤¬¸«¤Ä¤«¤Ã¤¿¤é¡¢ÉÔÀµ¤ËÃÖ¤´¹¤¨¤é¤ì¤Æ¤¤¤ë¤³¤È¤ò¼¨¤·¤Þ¤¹¤Î¤ÇÃí°Õ¤¬É¬ÍפǤ¹¡£
¡Ú¥¢¥ó¥±¡¼¥È¡Û
¤³¤Îµ»ö¤Ï¤¿¤á¤Ë¤Ê¤ê¤Þ¤·¤¿¤«¡©
¡¡¡¡¡¡¤Ï¤¤¡¡¡¡/¡¡¡¡¤¤¤¤¤¨