Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jul 2002
    Posts
    5

    Default chkrootkit output

    i scanned my new cpanel system w/ chkrootkit and it said &bindshell INFECTED port 465&

    Now ive done some research and it said portsentry usually will trigger this. Well i havent setup port sentry. I checked /etc/passwd and nothing abnormal.

    So does cpanel use this port for anything?

    Thanks

  2. #2
    Member bmcpanel's Avatar
    Join Date
    Jun 2002
    Posts
    546

    Default

    If you definitely do not have Portsentry or any other firewall, then you should be concerned.

  3. #3
    Member bmcpanel's Avatar
    Join Date
    Jun 2002
    Posts
    546

    Default

    I put a few extra, known hacker ports in my /etc/portsentry/portsentry.conf file and ./chkrootkit then shows them as infected on the bindshell. Just to be sure, I deleted a couple of those ports in the /etc/portsentry/portsentry.conf file and restarted portsentry. I then ran chkrootkit again and it said those ports were NOT infected. Thus, it is true, Portsentry does trigger those warnings for bindshell.

  4. #4
    Member
    Join Date
    Dec 2001
    Posts
    42

    Default

    Anybody willing to post or email their conf for portsentry. Just wondering what other 'hacker' ports I should be blocking and in which section of the conf they should go.

    Thanks

    myros@neuralhq.com

    Myros
    http://www.neuralhq.com

  5. #5
    Member
    Join Date
    Dec 2002
    Posts
    12

    Default

    I know this is an old topic but.......

    From chkrootkit.org:

    I'm running PortSentry/klaxon. What's wrong with the bindshell test?
    If you're running PortSentry/klaxon or another program that binds itself to unused ports probably chkrootkit will give you a false positive on the bindshell test (ports 114/tcp, 465/tcp, 511/tcp, 1008/tcp, 1524/tcp, 1999/tcp, 3879/tcp, 4369/tcp, 5665/tcp, 10008/tcp, 12321/tcp, 23132/tcp, 27374/tcp, 29364/tcp, 31336/tcp, 31337/tcp, 45454/tcp, 47017/tcp, 47889/tcp, 60001/tcp).



    Mike

Similar Threads & Tags
Similar threads

  1. /bin/sh: /root/chkrootkit-0.46a/chkrootkit: Permission denied
    By jsimon in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-05-2006, 03:04 AM
  2. Need help with chkrootkit output
    By Tina in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 11-05-2005, 05:42 PM
  3. Chkrootkit
    By netlook in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-25-2004, 10:34 AM
  4. chkrootkit
    By jackal in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-16-2003, 09:18 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube