Skip to content

Is it a false alarm - /usr/sbin/sshd被篡改 ? #14

@greendow

Description

@greendow

I tried to run GScan on the desktop version of Ubuntu 20.04 and 22.04, the instruction is:
sudo python3 GScan.py
The result both includes:
[1][风险] 黑客在未知时间,进行了SSHwrapper 后门植入,/usr/sbin/sshd被篡改,文件非可执行文件
But sshd file does not exist. See below:
ls -al /usr/sbin/sshd
ls: cannot access '/usr/sbin/sshd': No such file or directory
Is it a false alarm?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions