LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-03-2008, 09:27 AM   #1
DotHQ
Member
 
Registered: Mar 2006
Location: Ohio, USA
Distribution: Red Hat, Fedora, Knoppix,
Posts: 548

Rep: Reputation: 33
Chk Root Kit reported infection


I've just run chkrootkit on a few servers. One server shows an infection, but I don't know what to look for or what action to take about it.

Here is the output: `bindshell'... INFECTED (PORTS: 465)


Any clues for me?
TIA
 
Old 01-03-2008, 09:40 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
Investigate what is on that port and whether it is a false positive:
Code:
Important Note: If you see 'Checking `bindshell'... INFECTED (PORTS:  465)' read on.
I'm running PortSentry/klaxon. What's wrong with the bindshell test?
If you're running PortSentry/klaxon or another program that binds itself to unused ports probably chkrootkit will give you a false positive on the bindshell test (ports 114/tcp, 465/tcp, 511/tcp, 1008/tcp, 1524/tcp, 1999/tcp, 3879/tcp, 4369/tcp, 5665/tcp, 10008/tcp, 12321/tcp, 23132/tcp, 27374/tcp, 29364/tcp, 31336/tcp, 31337/tcp, 45454/tcp, 47017/tcp, 47889/tcp, 60001/tcp).
http://www.webhostgear.com/25.html

Some programs will trigger a false alarm because they employ a technique that a cracker might. You need to determine whether this is the case or if you do indeed have a problem. Is this server running PortSentry/klaxon or something similar.
 
Old 01-03-2008, 09:52 AM   #3
DotHQ
Member
 
Registered: Mar 2006
Location: Ohio, USA
Distribution: Red Hat, Fedora, Knoppix,
Posts: 548

Original Poster
Rep: Reputation: 33
Yep, we are running port sentry. Thanks. Had me worried there for a minute.
 
Old 01-03-2008, 05:26 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by DotHQ View Post
Yep, we are running port sentry.
While on the subject allow me to (with all due respect) reverse plug this piece of code:
http://www.linuxquestions.org/questi...7/#post2094032
http://www.linuxquestions.org/questi...2/#post2413068
http://www.linuxquestions.org/questi...0/#post2432706

I hope you get the idea.
 
Old 01-03-2008, 11:36 PM   #5
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
Did Cisco aquire them simply to eliminate the competition or to raid their technology? That is a worry of mine. Open Source companies being aquired for the purpose of shutting down an open source project by removing it's sponsorship or support.

---

It looks like it may be a one man operation now
http://sourceforge.net/forum/forum.php?forum_id=275043
Unless this is a different project.

Last edited by jschiwal; 01-03-2008 at 11:43 PM.
 
Old 01-04-2008, 03:55 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by jschiwal View Post
It looks like it may be a one man operation now (..) Unless this is a different project.
Yes, that *is* the project. But look at the CVS tracker stats and you'll find it's a no man operation: no commits being done for ages.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CHK File Disaster! deepgrewal Linux - Software 1 02-28-2007 10:05 AM
loads of .chk files appeared... XP or Linux??? Adrian Baker Linux - General 2 12-09-2006 03:49 PM
SONY BMG root kit -- do their discs play on Linux? beeblequix Linux - Software 1 12-02-2005 02:03 PM
*sigh* Virus infection.... xodustrance Linux - Newbie 3 07-14-2003 03:21 AM
Showtee root kit jimrt Linux - Security 1 03-12-2003 10:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:13 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration