Results 1 to 3 of 3

Thread: Chkrootkit

  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2004
    Posts
    347

    Default Chkrootkit

    Hello,

    I've check my system with chkrootkit and got:

    Checking 'bindshell' ... warning, got bogus unix line (INFECTED PORTS 465)

    Have I to worry?

  2. #2
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    From the CHKROOTKIT website :

    Item 7 on the FAQ (which is displayed on the homepage BTW): I'm running PortSentry/klaxon. What's wrong with the bindshell test?

    If you're running PortSentry/klaxon or another program that binds itself to unused ports probably chkrootkit will give you a false positive on the bindshell test (ports 114/tcp, 465/tcp, 511/tcp, 1008/tcp, 1524/tcp, 1999/tcp, 3879/tcp, 4369/tcp, 5665/tcp, 10008/tcp, 12321/tcp, 23132/tcp, 27374/tcp, 29364/tcp, 31336/tcp, 31337/tcp, 45454/tcp, 47017/tcp, 47889/tcp, 60001/tcp).

    I do not know your configuration so I cannot answer your question. I can tell you that this warning is common (one that a search on chkrootkit would have answered <cough> <cough>) on cPanel servers.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2004
    Posts
    347

    Default

    Ok, thanks.

Similar Threads

  1. /bin/sh: /root/chkrootkit-0.46a/chkrootkit: Permission denied
    By jsimon in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 10-05-2006, 02:04 AM
  2. rkhunter - chkrootkit
    By oderland in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 11-03-2004, 01:57 PM
  3. chkrootkit
    By jackal in forum cPanel & WHM Discussions
    Replies: 1
    Last Post: 06-16-2003, 08:18 PM
  4. chkrootkit output
    By neoraver in forum cPanel & WHM Discussions
    Replies: 4
    Last Post: 01-24-2003, 02:58 AM