项目首页:
https://github.com/sektioneins/osx_verify
项目简介:
随着OSX的普及,现在越来越多的恶意软件顶上了OSX,甚至有的恶意软件会替换/修改/捆绑到正常的APP里面,导致了系统的沦陷。
OSX Installer Verifier是通过内置的APP HASH与系统已经安装的APP进行对比,如果存在差异,即该APP就有可能遭到了恶意软件的篡改。
安装:
首先你需要安装 Python
git clone https://github.com/sektioneins/osx_verify
使用方法:
cd osx_verify
./osx_verify.py --scan /Applications/Install\ OS\ X\ El\ Capitan.app
[+] loading database
[+] scanning files in /Applications/Install OS X El Capitan.app... (this may take a while)
[+] comparing...
[+] -----------
[+] Results for Install OS X Mavericks 10.9.3.app (./db/Install OS X Mavericks 10.9.3.app.json):
[+] 1211 files are different. use --verbose to see details
[+] Results for Install OS X Mavericks 10.9.1.app (./db/Install OS X Mavericks 10.9.1.app.json):
[+] 1211 files are different. use --verbose to see details
[+] Results for Install OS X Mavericks 10.9.5.app (./db/Install OS X Mavericks 10.9.5.app.json):
[+] 1211 files are different. use --verbose to see details
[+] Results for Install OS X Mavericks 10.9.0.app (./db/Install OS X Mavericks 10.9.0.app.json):
[+] 1210 files are different. use --verbose to see details
[+] Results for Install OS X Mountain Lion 10.8.2.app (./db/Install OS X Mountain Lion 10.8.2.app.json):
[+] 1205 files are different. use --verbose to see details
[+] Results for Install OS X Lion 10.7.3.app (./db/Install Mac OS X Lion 10.7.3.app.json):
[+] 1164 files are different. use --verbose to see details
[+] Results for Install OS X 10.10 Developer Preview.app (./db/Install OS X 10.10 Developer Preview.app.json):
[+] 360 files are different. use --verbose to see details
[+] Results for Install OS X Yosemite 10.10.1.app (./db/Install OS X Yosemite 10.10.1.app.json):
[+] 350 files are different. use --verbose to see details
[+] Results for Install OS X Yosemite 10.10.5.app (./db/Install OS X Yosemite 10.10.5.app.json):
[+] 350 files are different. use --verbose to see details
[+] Results for Install OS X 10.11 Developer Beta 1.app (./db/Install OS X 10.11 Developer Beta 1.app.json):
[+] 275 files are different. use --verbose to see details
[+] Results for Install OSX 10.11.2.app (./db/Install OS X El Capitan.10.11.2.app.json):
[+] perfect match
[+] bye.
文章出处:黑客工具箱
你可能喜欢