LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-18-2004, 01:23 PM   #1
saag
LQ Newbie
 
Registered: Mar 2004
Location: thailand
Distribution: red 8
Posts: 15

Rep: Reputation: 0
bindshell ..INFECTED


Could someone help on this please.

when checking syslogs I keep getting the binding error on 111. I'm running under portsentry -atcp and -sudp

Checking `bindshell'... INFECTED (PORTS: 1524 31337) showed up after I ran a chkrootkit. it sounds like a trojan to me but i'm not sure....

whats it all about then ? I'm newbie and trying to find this one asap.

syslog shows up with ... adminalert: ERROR: could not bind TCP socket: 111. Attempting to continue.

I look through the threads and it seems ps is not to popular with linux guru's. whats new on the market and easy to configure for a wanna be linux like me.....

This also pops it head up on start up...

warning: /var/spool/postfix/etc/resolv.conf and /etc/resolv.conf differ. I deleted to match the pair, but its back again.

I also store, but not run firestarter for fun. should I KEEP or DELETE ?

Just trying to get opinion on the firewalls...and would be very glad of a kind guru.

thanks for any help

Last edited by saag; 03-18-2004 at 03:56 PM.
 
Old 03-18-2004, 05:44 PM   #2
Khabi
Member
 
Registered: Aug 2003
Location: Arizona
Distribution: Gentoo
Posts: 142

Rep: Reputation: 15
well, I don't use portsentry, but I have a basic understanding of it and most of your problems seem to spawn from that. Quick portsentry info: Portsentry listens on certian ports and when they are scanned (depends on how many you setup to trigger this) it'll block that host from everything on your computer. So when you ran chkrootkit the reason it showed those "INFECTED PORTS" its because portsentry is listening on those.
That is mostly likely the problem with port 111 not binding, I'll bet if you look at the portsentry config you see that its binding 111 and only one program can be bound to a port at a time.

now on to the postfix resolve problem, its nothing horribly bad. Postfix uses its own resolve.conf to do DNS stuff. I've never heard of anyone having a problem because the /etc/resolv.conf and postfix's resolve.conf are mismatched, but I've also never really read up on that, anyone else had any problems with that?

Firestarter is a great program. I would keep using it, its just a frontend for iptables and will provide resaonably good protection. Over all I would say drop portsentry and just run Firestarter on its own.
 
Old 03-18-2004, 08:55 PM   #3
saag
LQ Newbie
 
Registered: Mar 2004
Location: thailand
Distribution: red 8
Posts: 15

Original Poster
Rep: Reputation: 0
Khabi

Thanks for the quick response.

I spent all night banging, tweaking, reading, pushing, swearing and thumping the damn thing. What ever I did, its gone. I deleted this and that old programme, scripted a config and deleted guardog, it shows clear on binding. ..Dont ask me, I dont know.....It just is...rebooted a few times and it still is clear. anyway happy now.

Just the prefix thing-ma-jig to sort now.

For interest from previous thread
I spent hours mindstorming to get f-prot to run. then a guru said use chkrootkit. five mins to put in, bloody easy start command, runs through the whole system for virus problems. Its not easy when you know nothing is it....

Maybe another thread after tomorrow, only linux knows...!
 
Old 03-19-2004, 01:20 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I spent hours mindstorming to get f-prot to run. then a guru said use chkrootkit.
F-Prot and Chkrootkit aren' similar products. Chkrootkit scans the local system for all sorts of malicious activity typical for *nixes, while F-Prot is an antivirus scanner. // While on the subject of AV, last time I tested F-Prot the detection results where way below what I find acceptable. NAI's uvscan isn't free but performs better than F-P, BitDefender is free for personal use and performs better than F-P and NAI.
 
Old 03-19-2004, 09:40 AM   #5
saag
LQ Newbie
 
Registered: Mar 2004
Location: thailand
Distribution: red 8
Posts: 15

Original Poster
Rep: Reputation: 0
Thanks for the lesson unSpawn

Going to keep chkrootkit for when needed. Will now look at bitDefender upon your advice of FREE. Sounds like the type of performance scanner I have been searching for over the past few weeks. Not happy or fully secure in the head over the present Virus scanner on my box. Again thanks for the tip......



Many thanks for any further help given on the above issues

Last edited by saag; 03-20-2004 at 02:17 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
blocking port 111 wedgeworth Linux - Newbie 1 04-19-2004 01:56 PM
port 111 - firewall question taz76 Linux - Networking 5 04-04-2003 03:04 PM
sunrpc port 111 MrJoshua Linux - General 4 12-20-2002 03:47 AM
scan port at 111 is open.... Qebex Linux - Security 5 09-21-2002 06:29 PM
Closing port 111 psyklops Linux - General 3 05-01-2002 12:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration