Re: [Security-Discuss] ChkRootkit reports infection after MandrivaUpdate
Tuxiq <tuxiq2304-FFYn/[email protected]> Tue, 19 Sep 2006 11:39:28 -0400
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Tue September 19 2006 08:39 am, Robert M. Riches Jr. wrote: > > Date: Tue, 19 Sep 2006 03:46:28 -0400 > > From: Tuxiq <tuxiq2304-FFYn/[email protected]> > > > > Just compared my log from chkrootkit for yesterday and today and > > apparently AFTER the update from Mandriva chkrootkit reports a > > "bindshell" infection on port 600 > > > > blocked the port just in case on my hardware router just in case but the > > only activity I see on port 600 is from rpc.statd ??? > > > > Any reasons to be concerned or is this just a false positive. I know it > > happens... I once had Norton and McAfee report that a program I just > > compiled in Turbo Pascal was infected with some virus. A rename of a > > single variable cleared the error. That's what happens when a virus > > detector only looks at a stream of bytes without being able to identify > > the context. Oh, and BTW, that was way back when; before I saw the light > > ;-) > > > > Anyways, anyone else noticed a similar problem on their system ? > > It's a false positive. > > By default, NFS uses a random port for rpc.statd. If you are > unlucky enough to hit a port that chkrootkit's bindshell test > looks at, you'll get the report. If you make the ports > deterministic (4000-4003 or so) you'll still get the report. > > There was a discussion in one of the newsgroups (alt.os.linux.mandr* > IIRC). Google will find other discussions. > > I have a wrapper script to run chkrootkit, and it omits the > bindshell test. Thanks for the info Robert. ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________