Web Hosting Talk







View Full Version : chkrootkit


DigiCrime
12-03-2002, 12:28 AM
Running this, nothing comes up infected except this

Checking `bindshell'... INFECTED (PORTS: 465)

Anyone can shed some light on this? Unfamilar territory for me

clockwork
12-03-2002, 04:04 AM
fuser -v 465/tcp

If someone is running "bindshell" on port 465, it's very likely you've been rooted.

Have fun!

DigiCrime
12-03-2002, 04:29 AM
heres what comes up

root@ [~]# fuser -v 465/tcp

USER PID ACCESS COMMAND
465/tcp root 1283 f.... stunnel-4.02loc
root 6243 f.... stunnel-4.02loc

clockwork
12-03-2002, 05:50 AM
Ah... cpanel box?

That's normal then.

[ssmtp]
accept = 465
connect = 25

(From stunnel config on a CPanel box)

I thought you actually had a process called "bindshell" running on there, which, generally, is a default-name for a backdoor.

Have fun! ;)

Darth
12-03-2002, 06:50 AM
hah, WHM thinks everything is infected :laugh:

eddy2099
01-02-2003, 05:00 PM
Yeah, did the Chkrootkit test too and got the same error and did that trojan check on WHM and true quite a number of files were suspected. hmm. Sure was scary until I did a search here before scaring myself.

So if it is normal, I can start cooling down.

EnigmaBiz
02-02-2003, 02:51 AM
I did a search awhile back, if you have a cpanel box
you're fine but people that run Plesk as well.

This is an old post but it's helpful when doing a 'search'

It is smtps for secure smtp...