Re: [Security-Discuss] ChkRootkit reports infection after MandrivaUpdate

Tuxiq <tuxiq2304-FFYn/[email protected]> Tue, 19 Sep 2006 11:39:28 -0400
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Tue September 19 2006 08:39 am, Robert M. Riches Jr. wrote:
> > Date: Tue, 19 Sep 2006 03:46:28 -0400
> > From: Tuxiq <tuxiq2304-FFYn/[email protected]>
> >
> > Just compared my log from chkrootkit for yesterday and today and
> > apparently AFTER the update from Mandriva chkrootkit reports a
> > "bindshell" infection on port 600
> >
> > blocked the port just in case on my hardware router just in case but the
> > only activity I see on port 600 is from rpc.statd ???
> >
> > 	Any reasons to be concerned or is this just a false positive. I know it
> > happens... I once had Norton and McAfee report that a program I just
> > compiled in Turbo Pascal was infected with some virus. A rename of a
> > single variable cleared the error. That's what happens when a virus
> > detector only looks at a stream of bytes without being able to identify
> > the context. Oh, and BTW, that was way back when; before I saw the light
> > ;-)
> >
> > Anyways, anyone else noticed a similar problem on their system ?
>
> It's a false positive.
>
> By default, NFS uses a random port for rpc.statd.  If you are
> unlucky enough to hit a port that chkrootkit's bindshell test
> looks at, you'll get the report.  If you make the ports
> deterministic (4000-4003 or so) you'll still get the report.
>
> There was a discussion in one of the newsgroups (alt.os.linux.mandr*
> IIRC).  Google will find other discussions.
>
> I have a wrapper script to run chkrootkit, and it omits the
> bindshell test.

Thanks for the info Robert.
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________