Re: [Security-Discuss] ChkRootkit reports infection after MandrivaUpdate
[email protected] (Robert M. Riches Jr.) Tue, 19 Sep 2006 05:39:06 -0700
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Organization | none-at-all |
| Message-ID | <[email protected]> |
> Date: Tue, 19 Sep 2006 03:46:28 -0400 > From: Tuxiq <tuxiq2304-FFYn/[email protected]> > > Just compared my log from chkrootkit for yesterday and today and apparently > AFTER the update from Mandriva chkrootkit reports a "bindshell" infection on > port 600 > > blocked the port just in case on my hardware router just in case but the only > activity I see on port 600 is from rpc.statd ??? > > Any reasons to be concerned or is this just a false positive. I know it > happens... I once had Norton and McAfee report that a program I just compiled > in Turbo Pascal was infected with some virus. A rename of a single variable > cleared the error. That's what happens when a virus detector only looks at a > stream of bytes without being able to identify the context. Oh, and BTW, that > was way back when; before I saw the light ;-) > > Anyways, anyone else noticed a similar problem on their system ? It's a false positive. By default, NFS uses a random port for rpc.statd. If you are unlucky enough to hit a port that chkrootkit's bindshell test looks at, you'll get the report. If you make the ports deterministic (4000-4003 or so) you'll still get the report. There was a discussion in one of the newsgroups (alt.os.linux.mandr* IIRC). Google will find other discussions. I have a wrapper script to run chkrootkit, and it omits the bindshell test. HTH Robert Riches [email protected] ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________