DigiCrime
12-03-2002, 12:28 AM
Running this, nothing comes up infected except this
Checking `bindshell'... INFECTED (PORTS: 465)
Anyone can shed some light on this? Unfamilar territory for me
clockwork
12-03-2002, 04:04 AM
fuser -v 465/tcp
If someone is running "bindshell" on port 465, it's very likely you've been rooted.
Have fun!
DigiCrime
12-03-2002, 04:29 AM
heres what comes up
root@ [~]# fuser -v 465/tcp
USER PID ACCESS COMMAND
465/tcp root 1283 f.... stunnel-4.02loc
root 6243 f.... stunnel-4.02loc
clockwork
12-03-2002, 05:50 AM
Ah... cpanel box?
That's normal then.
[ssmtp]
accept = 465
connect = 25
(From stunnel config on a CPanel box)
I thought you actually had a process called "bindshell" running on there, which, generally, is a default-name for a backdoor.
Have fun! ;)
Darth
12-03-2002, 06:50 AM
hah, WHM thinks everything is infected :laugh:
eddy2099
01-02-2003, 05:00 PM
Yeah, did the Chkrootkit test too and got the same error and did that trojan check on WHM and true quite a number of files were suspected. hmm. Sure was scary until I did a search here before scaring myself.
So if it is normal, I can start cooling down.
EnigmaBiz
02-02-2003, 02:51 AM
I did a search awhile back, if you have a cpanel box
you're fine but people that run Plesk as well.
This is an old post but it's helpful when doing a 'search'
It is smtps for secure smtp...