Re: [Security-Discuss] ChkRootkit reports infection after MandrivaUpdate

[email protected] (Robert M. Riches Jr.) Tue, 19 Sep 2006 05:39:06 -0700
Newsgroups gmane.linux.mandrake.security.general
Organization none-at-all
Message-ID <[email protected]>
> Date: Tue, 19 Sep 2006 03:46:28 -0400
> From: Tuxiq <tuxiq2304-FFYn/[email protected]>
>
> Just compared my log from chkrootkit for yesterday and today and apparently 
> AFTER the update from Mandriva chkrootkit reports a "bindshell" infection on 
> port 600
>
> blocked the port just in case on my hardware router just in case but the only 
> activity I see on port 600 is from rpc.statd ???
>
> 	Any reasons to be concerned or is this just a false positive. I know it 
> happens... I once had Norton and McAfee report that a program I just compiled 
> in Turbo Pascal was infected with some virus. A rename of a single variable 
> cleared the error. That's what happens when a virus detector only looks at a 
> stream of bytes without being able to identify the context. Oh, and BTW, that 
> was way back when; before I saw the light ;-)
>
> Anyways, anyone else noticed a similar problem on their system ?

It's a false positive.

By default, NFS uses a random port for rpc.statd.  If you are
unlucky enough to hit a port that chkrootkit's bindshell test
looks at, you'll get the report.  If you make the ports
deterministic (4000-4003 or so) you'll still get the report.

There was a discussion in one of the newsgroups (alt.os.linux.mandr*
IIRC).  Google will find other discussions.

I have a wrapper script to run chkrootkit, and it omits the
bindshell test.

HTH

Robert Riches
[email protected]
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________