Do not do this project on your own ubuntu linux machine!



Download 303.47 Kb.
Page5/6
Date01.06.2018
Size303.47 Kb.
#52422
1   2   3   4   5   6

Saving the Screen Image


  1. Make sure the message saying Found parts of this rootkit/trojan is visible.

  2. On your desktop, press the PrntScn key to copy whole screen to the clipboard.

  3. On the your desktop, open Paint and paste in the image. Save it as a JPEG, with the filename Your Name Proj 12b.

Completing the rkhunter Scan


  1. When you see the message “[Press to continue]”, press Enter. rkhunter will do a lot of tests, and find a few more problems, all apparently connected with the rootkit you installed.

Removing the Rootkit


  1. The rootkit does not crash the Ubuntu machine while it’s running, but it won’t restart, not even in Recovery mode. You can use the infected machine, and you can close virtual machine, saving the machine’s running state, and restore that state, but you cannot shut it down normally.

Starting the Clean Machine

  1. Do NOT shut down the infected Ubuntu machine.

Installing the fix-fu rootkit removal tool

  1. On your Ubuntu desktop, open the CIT 2640 folder on the Desktop and double-click the fix-fu.tar.gz file. Click Extract. Click Extract. A folder named fix-fu should appear in the CIT 2640 folder. Close all windows.

Examining the backup-fu Script in the Clean Machine


  1. In your clean machine, from the Ubuntu menu bar, click Applications, Accessories, Terminal.

  2. In the terminal window, enter this command, then press the Enter key:

cd Desktop/CIT\ 2640/fix-fu

This changes the working directory to folder containing the scripts.



  1. In the terminal window, enter this command, then press the Enter key:

cat backup-fu

You should see the script, as shown to the right on this page. All it does is copy ten files into the fix‑fu folder.

Saving the Screen Image

  1. Make sure the Terminal window is visible, showing the ten cp commands.

  2. On your desktop, press the PrntScn key to copy whole screen to the clipboard.

  3. On your desktop, open Paint and paste in the image. Save it as a JPEG, with the filename Your Name Proj 12c.


Download 303.47 Kb.

Share with your friends:
1   2   3   4   5   6




The database is protected by copyright ©ininet.org 2024
send message

    Main page