Re: chkrootkit: Checking `bindshell'... INFECTED (PORTS: 600)

From: Vincent Lefevre (vincent_at_vinc17.org)
Date: 03/19/05

  • Next message: Paolo Alexis Falcone: "Re: Wireless PCMCIA/Cardbus supporting monitor mode and external antenna"
    Date: Sat, 19 Mar 2005 23:37:43 +0100
    To: debian-user@lists.debian.org
    
    

    On 2005-03-19 18:31:03 +0100, Matthijs wrote:
    > On Sat, 19 Mar 2005 13:30:16 +0100, Vincent Lefevre
    > <vincent@vinc17.org> wrote:
    > > COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
    > > rpc.statd 1696 root 5u IPv4 1909 UDP *:600
    >
    > On my system:
    > COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
    > mlnet 2065 mldonkey 27u IPv4 4827 TCP *:4000 (LISTEN)
    >
    > ... yes, I've got mldonkey running, might be on port 4000, but what's
    > that got to do with bindshell? Should I worry?

    In my case, I don't even know why rpc.statd listens on port 600.

    -- 
    Vincent Lefèvre <vincent@vinc17.org> - Web: <http://www.vinc17.org/>
    100% accessible validated (X)HTML - Blog: <http://www.vinc17.org/blog/>
    Work: CR INRIA - computer arithmetic / SPACES project at LORIA
    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Paolo Alexis Falcone: "Re: Wireless PCMCIA/Cardbus supporting monitor mode and external antenna"

    Relevant Pages

    • Re: missing free space
      ... Output from lsof ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
      (Debian-User)
    • Re: Help in finding a file needed
      ... COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME ... running lsof, but renaming the open file instead will show the new ... TeXShop 216 rowland txt VREG ...
      (uk.comp.sys.mac)
    • Re: OSS device "/dev/dsp" is already in use by another program
      ... Try using lsof (may be installed by running `apt-get install lsof`) on the ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ... You may then use kill to kill the process by pid. ...
      (Debian-User)
    • security question
      ... lsof: WARNING: can't stat() reiserfs file system /dev/.static/dev ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ...
      (Debian-User)
    • DoS Tool Identification
      ... Here is the ps and lsof identification: ... COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ... George Mason University ...
      (Incidents)