Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 18
  1. #1
    Member
    Join Date
    May 2002
    Posts
    161

    Default Scalper Worm

    chkrootkit (installed today - latest version) gives me this warning : Checking `scalper'... Warning: Possible Scalper Worm installed

    I have RH 7.3, apache 1.3.27 and 0.9.6b OpenSSL. I want to believe that I'm secure with the above software and even if the worm exists..the vulnerability should not exist anymore with the above versions. But on this maybe I'm totally wrong. Could you indicate me some steps in order to confirm the chkrottkit's warning?

    Another info I can provide (if it's useful) ..is that /tmp has no strange files in it.

    Thank you.

    cPanel.net Support Ticket Number:

  2. #2
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    Delete the files, /tmp/.uua or /tmp/.a if they exist.

    cPanel.net Support Ticket Number:
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  3. #3
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    also kill any process's that are running under those names.

    cPanel.net Support Ticket Number:
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  4. #4
    Member
    Join Date
    May 2002
    Posts
    161

    Default

    Thanks for your reply shaun.
    There are no files with these names and no processes related to these files.

    If you have any other suggestions, I'll be glad to hear them.
    Thanks again.

    cPanel.net Support Ticket Number:

  5. #5
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    do a search on google for scalper removal

    cPanel.net Support Ticket Number:
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  6. #6
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    I run cckrootkit every 3 hours and this morning for first time on 4 boxes:

    Checking `bindshell'... INFECTED (PORTS: 465)
    Checking `lkm'... You have 2 process hidden for readdir command
    You have 2 process hidden for ps command
    Warning: Possible LKM Trojan installed


    all 4 at same time. anyone else get this now all of a sudden?

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  7. #7
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Originally posted by rpmws
    I run cckrootkit every 3 hours and this morning for first time on 4 boxes:

    Checking `bindshell'... INFECTED (PORTS: 465)
    Checking `lkm'... You have 2 process hidden for readdir command
    You have 2 process hidden for ps command
    Warning: Possible LKM Trojan installed


    all 4 at same time. anyone else get this now all of a sudden?

    cPanel.net Support Ticket Number:
    If I run it a few more times the 465 port stays but the LKM goes away.

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  8. #8
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    Which version are you running? I get your basic 'all is well' output.

    # $Id: chkrootkit, v 0.39 2003/01/30

    Checking `asp'... not infected
    Checking `bindshell'... INFECTED (PORTS: 465)
    Checking `lkm'... Checking `rexedcs'... not found
    Checking `sniffer'... not tested: can't exec ./ifpromisc
    Checking `wted'... not tested: can't exec ./chkwtmp
    Checking `scalper'... not infected
    Checking `slapper'... not infected
    Checking `z2'... not tested: can't exec ./chklastlog

    The 'bindshell' msg. can be ignored. Something to do with the Script itself or the way Cpanel is setup -- not sure which.

    cPanel.net Support Ticket Number:
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  9. #9
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Originally posted by Website Rob
    Which version are you running? I get your basic 'all is well' output.

    # $Id: chkrootkit, v 0.39 2003/01/30

    Checking `asp'... not infected
    Checking `bindshell'... INFECTED (PORTS: 465)
    Checking `lkm'... Checking `rexedcs'... not found
    Checking `sniffer'... not tested: can't exec ./ifpromisc
    Checking `wted'... not tested: can't exec ./chkwtmp
    Checking `scalper'... not infected
    Checking `slapper'... not infected
    Checking `z2'... not tested: can't exec ./chklastlog

    The 'bindshell' msg. can be ignored. Something to do with the Script itself or the way Cpanel is setup -- not sure which.

    cPanel.net Support Ticket Number:
    .41

    for a few days I didn't see the nbindshell listed. then it came back last night.

    cPanel.net Support Ticket Number:
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  10. #10
    Member cass's Avatar
    Join Date
    Jul 2002
    Location
    Argentina/USA/Mexico
    Posts
    354

    Default

    Read :
    http://www.foxnews.com/story/0,2933,90957,00.html

    Government Warns of Mass Hacker Attacks...


    hehe

    cPanel.net Support Ticket Number:
    Carlos Ariel Sepúlveda
    CAS company :: 1997-2011, 14 Years! :: Dedicated Attitude
    http://www.cascompany.com :: Providing CPANEL/WHM Servers since 2002 !

  11. #11
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    Checking `bindshell'... INFECTED (PORTS: 465)

    Ignore that, it's picking up portsentry. Thats a false/positive

    cPanel.net Support Ticket Number:
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  12. #12
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    Originally posted by shaun
    Checking `bindshell'... INFECTED (PORTS: 465)

    Ignore that, it's picking up portsentry. Thats a false/positive

    cPanel.net Support Ticket Number:
    Is that like, when a girl says 'Yes' and she really means 'Maybe'?

    cPanel.net Support Ticket Number:
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  13. #13
    Member
    Join Date
    May 2002
    Posts
    161

    Default

    So, guys what do you think...we can live with some(that) warning(s) or we should spend time and money to get rid of them?

    cPanel.net Support Ticket Number:

  14. #14
    Member
    Join Date
    May 2002
    Posts
    161

    Default

    By accident I found out that the scalper warning is related with portsentry (or a specific configuration of it) -> at least in my case. And this on a new cpanel machine. With portsentry off..I get no warnings.

    cPanel.net Support Ticket Number:

  15. #15
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    After doing the following upgrades:

    RedHat 7.3
    WHM 7.1.0 cPanel 7.1.5-E37
    chkrootkit 4.1

    and portsentry being turned on, you can see that following is a normal output, although edited for brevity.

    Checking `lkm'... Checking `rexedcs'... not found
    Checking `sniffer'... not tested: can't exec ./ifpromisc
    Checking `wted'... not tested: can't exec ./chkwtmp
    Checking `w55808'... not infected
    Checking `scalper'... not infected
    Checking `slapper'... not infected
    Checking `z2'... not tested: can't exec ./chklastlog

    And is not much different from post above, when I was running WHM 6.4.x and chkrootkit v0.39.

    Not sure why yours would show different unless you're running free BSD or perhaps something to do with your Server setup.

    cPanel.net Support Ticket Number:
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

Similar Threads & Tags
Similar threads

  1. Gumblar Worm
    By oshs in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-21-2009, 12:58 PM
  2. Possible Slapper Worm?
    By xxkylexx in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-14-2006, 01:12 PM
  3. Worm.SomeFool.P
    By gflamerich in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-29-2004, 03:15 PM
  4. Slapper worm attack!!!
    By atul in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-20-2004, 09:37 AM
  5. support@microsoft.com is a Worm
    By Website Rob in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-23-2003, 02:17 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube