From 271af1d6da1ead465b79f682b5442e1916bc2060 Mon Sep 17 00:00:00 2001 From: gongdongdong Date: Fri, 29 Nov 2019 20:56:09 +0800 Subject: [PATCH] . --- lib/plugins/Backdoor_Analysis.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/lib/plugins/Backdoor_Analysis.py b/lib/plugins/Backdoor_Analysis.py index fc68bb9..5ed301a 100644 --- a/lib/plugins/Backdoor_Analysis.py +++ b/lib/plugins/Backdoor_Analysis.py @@ -187,7 +187,8 @@ def check_SSH(self): pid = info.split("/")[0] if os.path.exists('/proc/%s/exe' % pid): if 'sshd' in os.readlink('/proc/%s/exe' % pid): - malice_result(u'常规后门检测', u'SSH 后门', os.readlink('/proc/%s/exe' % pid), pid, u"非22端口的sshd服务", + malice_result(u'常规后门检测', u'SSH 后门', os.readlink('/proc/%s/exe' % pid), pid, + u"非22端口的sshd服务,进程pid: %s" % pid, u'[1]ls -l /porc/%s [2]ps -ef|grep %s|grep -v grep' % (pid, pid), u'风险', programme=u'kill %s #关闭异常sshd进程' % pid) malice = True