How To Check If Your Server Is Infected With The Linux/Rst-B Backdoor (Debian Etch)
How To Check If Your Server Is Infected With The Linux/Rst-B Backdoor (Debian Etch)Version 1.0 Linux Rst-B is a backdoor that can be used to add your server to botnets (see http://www.heise.de/newsticker/meldung/103563 (in German)). This short guide explains how you can install and use the Sophos Linux/RST-B detection tool to check your Debian Etch server and find out if it is infected with Linux Rst-B. I do not issue any guarantee that this will work for you!
1 Download And Install The Sophos Linux/RST-B Detection ToolI want to install the Linux/RST-B detection tool in the /usr/local/sbin directory (so that the detection tool is in our PATH later on): cd /usr/local/sbin You should then find the contents of the tar.gz file in the /usr/local/sbin/detection_tool directory. There are two ways of installing the detection tool: you can either use the pre-compiled binary that you can find in the /usr/local/sbin/detection_tool/pre-compiled directory, or you compile it yourself. I'll show both ways now.
1.1 Use The Pre-Compiled BinaryTo use the pre-compiled binary, we can either simply create a symlink called rst_detection_tool from the /usr/local/sbin directory to detection_tool/pre-compiled/detection_tool: cd /usr/local/sbin Or we move detection_tool/pre-compiled/detection_tool to /usr/local/sbin and rename it to rst_detection_tool: cd /usr/local/sbin
1.2 Build The Detection Tool From The SourcesTo compile the detection tool from the sources, we first install the package build-essential: apt-get install build-essential Afterwards we build the detection tool as follows: cd /usr/local/sbin/detection_tool This creates the program /usr/local/sbin/detection_tool/detection_tool. I want to have it directly in the /usr/local/sbin directory and name it rst_detection_tool, so we can either create a symlink: cd /usr/local/sbin Or we move detection_tool/detection_tool to /usr/local/sbin and rename it to rst_detection_tool: cd /usr/local/sbin
2 Use The Linux/RST-B Detection ToolNow we can use the detection tool as follows: Outside the /usr/local/sbin directory: rst_detection_tool [-v] <path> Inside the /usr/local/sbin directory we must prepend ./: ./rst_detection_tool [-v] <path> So if you want to scan your whole file system, you'd simply use: rst_detection_tool / or ./rst_detection_tool / if you are in /usr/local/sbin. On a clean system the output looks as follows: server2:/usr/local/sbin# ./rst_detection_tool / Scanned 43134 files, found 0 infections of Linux/Rst-B.
3 Links
|






Recent comments
3 hours 34 min ago
14 hours 25 min ago
15 hours 24 min ago
16 hours 53 min ago
18 hours 42 min ago
20 hours 43 min ago
22 hours 21 min ago
23 hours 19 min ago
1 day 1 hour ago
1 day 1 hour ago