kurulum yapıldı taramayıda yaptım sanırım bulaşmış dc den
Greetings! Rkhunter does not appear to indicate any rootkits. However, as stated previously, the scripts responsible for this attack are located in /tmp and /var/tmp -- shown below. These need to be removed and the method in which they were inserted needs to be determined and secured.
[root@server1 tmp]# ls -loba |grep -Ev sess_ |grep nobody
-rw-r--r-- 1 nobody 11052 Oct 1 2006 bd.txt
-rw-r--r-- 1 nobody 27919 Jul 6 21:03 botnet2.txt
-rw-r--r-- 1 nobody 27921 Jul 6 23:35 botnet.txt
-rw-r--r-- 1 nobody 39273 Jul 6 21:29 botscan7.txt
-rw-r--r-- 1 nobody 39255 Jul 6 21:53 botscan7.txt.1
-rw-r--r-- 1 nobody 39255 Jul 6 21:53 botscan7.txt.2
-rw-r--r-- 1 nobody 5792 Jul 6 21:03 ds2.txt
söyle bir mail geldi bulasmıs oldugunu onlarda ilettiler. peki bu bulasanları nasıl kaldırabiliriz sanırım kaldırmak cok zor veya cok ugrastırır re-install mı yapmak gerek servera ??