Re: chkrootkit: Checking `bindshell'... INFECTED (PORTS: 600)

From: Matthijs (vanaalten_at_hotmail.com)
Date: 03/19/05

  • Next message: Gene Heskett: "Re: Scanner recommendation, please."
    Date: Sat, 19 Mar 2005 18:31:03 +0100
    To: debian-user@lists.debian.org
    
    

    On Sat, 19 Mar 2005 13:30:16 +0100, Vincent Lefevre
    <vincent@vinc17.org> wrote:

    > When running chkrootkit on some machine, I get:
    >
    > Checking `bindshell'... INFECTED (PORTS: 600)

    Same here, but then on port 4000.

    > "netstat -a" says:
    >
    > udp 0 0 *:600 *:*
    >
    > "lsof -i:600" says:
    >
    > COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
    > rpc.statd 1696 root 5u IPv4 1909 UDP *:600

    On my system:
    COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
    mlnet 2065 mldonkey 27u IPv4 4827 TCP *:4000 (LISTEN)

    ... yes, I've got mldonkey running, might be on port 4000, but what's
    that got to do with bindshell? Should I worry?

    > What's wrong?

    Don't know, but would like to know...

    -- 
    Matthijs
    vanaalten@hotmail.com
    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Gene Heskett: "Re: Scanner recommendation, please."

    Relevant Pages

    • Re: missing free space
      ... Output from lsof ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
      (Debian-User)
    • Re: Output from chkrootkit
      ... >> I've reinstalled chkrootkit and its now pointing the finger at bindshell ... >> as infected, again port 600. ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ...
      (comp.os.linux.security)
    • Re: Port 443?
      ... >>Can anyone tell me what listens on port 443? ... # lsof -Pi:443 ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ...
      (Fedora)
    • Re: chkrootkit: Checking `bindshell... INFECTED (PORTS: 600)
      ... >> COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ... CR INRIA - computer arithmetic / SPACES project at LORIA ... To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org ...
      (Debian-User)
    • Re: Fetchmail: Error message in maillog
      ... The first command produced absolutely nothing. ... COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME ... Are you _sure_ something is attached to port 25? ...
      (freebsd-questions)