ich habe gerade, weil ich es hier in einigen Threads gelesen habe, das chkrootkit runtergeladen und auf meinem rootserver ausgeführt. Dass lief auch fast problemlos durch, nur eine Linie beunruhigt mich:
"Checking `bindshell'... INFECTED (PORTS: 465)"
Das hört sich ja garnicht gut an. Was hat das zu bedeuten?
Hier noch meine Betriebssystemdaten:
Suse 8.1 (Update vom Support)
PHP 4.2.6
Zusätzlich installierte Programme:
- AWStats
- Midnight-Commander
Sonst ist nichts am System verändert (meinerseits)
Ein Portscan zeigt mir, dass der Port offen ist und mit "ssmtp" beschriftet wird.
Hier noch die Ausgaben von ein Paar Scripten
Code: Select all
netstat -an
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 0.0.0.0:995             0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:110             0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:465             0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:21              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:25              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN
tcp        0      0 217.160.133.26:80       217.83.42.112:2582      ESTABLISHED
tcp        0  78840 217.160.133.26:80       193.159.138.207:33755   ESTABLISHED
tcp        0      0 217.160.133.26:80       217.83.42.112:2578      TIME_WAIT
tcp        0      0 217.160.133.26:80       217.83.42.112:2576      ESTABLISHED
tcp        0      0 217.160.133.26:110      212.95.103.34:64719     TIME_WAIT
tcp        0      0 217.160.133.26:22       217.230.12.104:23763    ESTABLISHED
tcp        0      0 217.160.133.26:80       195.93.66.6:58377       ESTABLISHED
tcp        0      0 217.160.133.26:80       80.133.183.81:57934     TIME_WAIT
tcp        0      0 217.160.133.26:80       80.130.147.210:1655     ESTABLISHED
tcp        0      0 217.160.133.26:80       80.130.147.210:1654     ESTABLISHED
tcp        0      0 217.160.133.26:80       195.93.66.16:51878      ESTABLISHED
tcp        0      0 217.160.133.26:80       217.83.42.112:2574      ESTABLISHED
tcp        0      0 217.160.133.26:80       80.133.148.24:2158      ESTABLISHED
tcp        0      0 217.160.133.26:80       193.159.138.207:33762   TIME_WAIT
tcp        0      0 217.160.133.26:80       217.83.42.112:2575      ESTABLISHED
tcp        0      0 217.160.133.26:80       80.133.148.24:2159      ESTABLISHED
tcp        0      0 217.160.133.26:80       80.130.147.210:1657     ESTABLISHED
tcp        0      0 217.160.133.26:80       217.83.42.112:2572      TIME_WAIT
tcp        0      0 217.160.133.26:80       80.133.148.24:2156      ESTABLISHED
tcp        0      0 217.160.133.26:80       217.83.42.112:2573      ESTABLISHED
tcp        0      0 217.160.133.26:80       195.93.64.13:49939      ESTABLISHED
tcp        0      0 217.160.133.26:80       217.83.42.112:2571      ESTABLISHED
tcp        0      0 217.160.133.26:80       80.133.148.24:2152      ESTABLISHED
tcp        0      0 217.160.133.26:80       195.93.65.12:37681      ESTABLISHED
tcp        0      0 217.160.133.26:80       80.133.148.24:2153      ESTABLISHED
udp        0      0 0.0.0.0:68              0.0.0.0:*
udp        0      0 217.160.133.26:123      0.0.0.0:*
udp        0      0 127.0.0.1:123           0.0.0.0:*
udp        0      0 0.0.0.0:123             0.0.0.0:*
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags       Type       State         I-Node Path
unix  2      [ ACC ]     STREAM     LISTENING     3367   /var/run/.nscd_socket
unix  2      [ ACC ]     STREAM     LISTENING     1098   /var/lib/mysql/mysql.sock
unix  2      [ ACC ]     STREAM     LISTENING     1663   public/cleanup
unix  2      [ ACC ]     STREAM     LISTENING     1776   public/flush
unix  2      [ ACC ]     STREAM     LISTENING     1784   public/showq
unix  2      [ ACC ]     STREAM     LISTENING     1670   private/rewrite
unix  2      [ ACC ]     STREAM     LISTENING     1768   private/bounce
unix  2      [ ACC ]     STREAM     LISTENING     1772   private/defer
unix  2      [ ACC ]     STREAM     LISTENING     1780   private/smtp
unix  2      [ ACC ]     STREAM     LISTENING     1788   private/error
unix  2      [ ACC ]     STREAM     LISTENING     1792   private/local
unix  2      [ ACC ]     STREAM     LISTENING     1796   private/virtual
unix  2      [ ACC ]     STREAM     LISTENING     1800   private/lmtp
unix  2      [ ACC ]     STREAM     LISTENING     1804   private/cyrus
unix  2      [ ACC ]     STREAM     LISTENING     1808   private/uucp
unix  2      [ ACC ]     STREAM     LISTENING     1812   private/ifmail
unix  2      [ ACC ]     STREAM     LISTENING     1816   private/bsmtp
unix  2      [ ACC ]     STREAM     LISTENING     1820   private/vscan
unix  2      [ ACC ]     STREAM     LISTENING     1824   private/procmail
unix  11     [ ]         DGRAM                    938    /dev/log
unix  2      [ ]         DGRAM                    1034014
unix  2      [ ]         DGRAM                    1016173
unix  2      [ ]         DGRAM                    285079
unix  3      [ ]         STREAM     CONNECTED     285050
unix  3      [ ]         STREAM     CONNECTED     285049
unix  3      [ ]         STREAM     CONNECTED     285048
unix  3      [ ]         STREAM     CONNECTED     285047
unix  3      [ ]         STREAM     CONNECTED     285046
unix  3      [ ]         STREAM     CONNECTED     285045
unix  3      [ ]         STREAM     CONNECTED     285044
unix  3      [ ]         STREAM     CONNECTED     285043
unix  3      [ ]         STREAM     CONNECTED     285042
unix  3      [ ]         STREAM     CONNECTED     285041
unix  3      [ ]         STREAM     CONNECTED     285040
unix  3      [ ]         STREAM     CONNECTED     285039
unix  3      [ ]         STREAM     CONNECTED     285038
unix  3      [ ]         STREAM     CONNECTED     285037
unix  3      [ ]         STREAM     CONNECTED     285036
unix  3      [ ]         STREAM     CONNECTED     285035
unix  3      [ ]         STREAM     CONNECTED     285034
unix  3      [ ]         STREAM     CONNECTED     285033
unix  3      [ ]         STREAM     CONNECTED     285030
unix  3      [ ]         STREAM     CONNECTED     285029
unix  3      [ ]         STREAM     CONNECTED     285028
unix  3      [ ]         STREAM     CONNECTED     285027
unix  3      [ ]         STREAM     CONNECTED     285026
unix  3      [ ]         STREAM     CONNECTED     285025
unix  3      [ ]         STREAM     CONNECTED     285024
unix  3      [ ]         STREAM     CONNECTED     285023
unix  3      [ ]         STREAM     CONNECTED     285022
unix  3      [ ]         STREAM     CONNECTED     285021
unix  3      [ ]         STREAM     CONNECTED     285020
unix  3      [ ]         STREAM     CONNECTED     285019
unix  3      [ ]         STREAM     CONNECTED     285018
unix  3      [ ]         STREAM     CONNECTED     285017
unix  3      [ ]         STREAM     CONNECTED     285016
unix  3      [ ]         STREAM     CONNECTED     285015
unix  3      [ ]         STREAM     CONNECTED     285014
unix  3      [ ]         STREAM     CONNECTED     285013
unix  3      [ ]         STREAM     CONNECTED     285012
unix  3      [ ]         STREAM     CONNECTED     285011
unix  3      [ ]         STREAM     CONNECTED     285010
unix  3      [ ]         STREAM     CONNECTED     285009
unix  3      [ ]         STREAM     CONNECTED     285008
unix  3      [ ]         STREAM     CONNECTED     285007
unix  2      [ ]         DGRAM                    239266
unix  2      [ ]         DGRAM                    3057
unix  2      [ ]         DGRAM                    1946
unix  2      [ ]         DGRAM                    1480
unix  2      [ ]         DGRAM                    1465
unix  2      [ ]         DGRAM                    1328
Code: Select all
netstat -a -n
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 0.0.0.0:995             0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:110             0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:465             0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:21              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:25              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN
tcp        0      0 217.160.133.26:22       217.230.12.104:23763    ESTABLISHED
tcp        0      0 217.160.133.26:80       193.159.138.207:33739   FIN_WAIT2
tcp        0      0 217.160.133.26:80       217.238.33.30:3483      ESTABLISHED
tcp        0      0 217.160.133.26:80       193.159.138.207:33743   FIN_WAIT2
tcp        0      0 217.160.133.26:80       212.33.63.179:3508      TIME_WAIT
tcp        0      0 217.160.133.26:80       217.238.33.30:3477      ESTABLISHED
udp        0      0 0.0.0.0:68              0.0.0.0:*
udp        0      0 217.160.133.26:123      0.0.0.0:*
udp        0      0 127.0.0.1:123           0.0.0.0:*
udp        0      0 0.0.0.0:123             0.0.0.0:*
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags       Type       State         I-Node Path
unix  2      [ ACC ]     STREAM     LISTENING     3367   /var/run/.nscd_socket
unix  2      [ ACC ]     STREAM     LISTENING     1098   /var/lib/mysql/mysql.sock
unix  2      [ ACC ]     STREAM     LISTENING     1663   public/cleanup
unix  2      [ ACC ]     STREAM     LISTENING     1776   public/flush
unix  2      [ ACC ]     STREAM     LISTENING     1784   public/showq
unix  2      [ ACC ]     STREAM     LISTENING     1670   private/rewrite
unix  2      [ ACC ]     STREAM     LISTENING     1768   private/bounce
unix  2      [ ACC ]     STREAM     LISTENING     1772   private/defer
unix  2      [ ACC ]     STREAM     LISTENING     1780   private/smtp
unix  2      [ ACC ]     STREAM     LISTENING     1788   private/error
unix  2      [ ACC ]     STREAM     LISTENING     1792   private/local
unix  2      [ ACC ]     STREAM     LISTENING     1796   private/virtual
unix  2      [ ACC ]     STREAM     LISTENING     1800   private/lmtp
unix  2      [ ACC ]     STREAM     LISTENING     1804   private/cyrus
unix  2      [ ACC ]     STREAM     LISTENING     1808   private/uucp
unix  2      [ ACC ]     STREAM     LISTENING     1812   private/ifmail
unix  2      [ ACC ]     STREAM     LISTENING     1816   private/bsmtp
unix  2      [ ACC ]     STREAM     LISTENING     1820   private/vscan
unix  2      [ ACC ]     STREAM     LISTENING     1824   private/procmail
unix  11     [ ]         DGRAM                    938    /dev/log
unix  2      [ ]         DGRAM                    1042377
unix  2      [ ]         DGRAM                    1016173
unix  2      [ ]         DGRAM                    285079
unix  3      [ ]         STREAM     CONNECTED     285050
unix  3      [ ]         STREAM     CONNECTED     285049
unix  3      [ ]         STREAM     CONNECTED     285048
unix  3      [ ]         STREAM     CONNECTED     285047
unix  3      [ ]         STREAM     CONNECTED     285046
unix  3      [ ]         STREAM     CONNECTED     285045
unix  3      [ ]         STREAM     CONNECTED     285044
unix  3      [ ]         STREAM     CONNECTED     285043
unix  3      [ ]         STREAM     CONNECTED     285042
unix  3      [ ]         STREAM     CONNECTED     285041
unix  3      [ ]         STREAM     CONNECTED     285040
unix  3      [ ]         STREAM     CONNECTED     285039
unix  3      [ ]         STREAM     CONNECTED     285038
unix  3      [ ]         STREAM     CONNECTED     285037
unix  3      [ ]         STREAM     CONNECTED     285036
unix  3      [ ]         STREAM     CONNECTED     285035
unix  3      [ ]         STREAM     CONNECTED     285034
unix  3      [ ]         STREAM     CONNECTED     285033
unix  3      [ ]         STREAM     CONNECTED     285030
unix  3      [ ]         STREAM     CONNECTED     285029
unix  3      [ ]         STREAM     CONNECTED     285028
unix  3      [ ]         STREAM     CONNECTED     285027
unix  3      [ ]         STREAM     CONNECTED     285026
unix  3      [ ]         STREAM     CONNECTED     285025
unix  3      [ ]         STREAM     CONNECTED     285024
unix  3      [ ]         STREAM     CONNECTED     285023
unix  3      [ ]         STREAM     CONNECTED     285022
unix  3      [ ]         STREAM     CONNECTED     285021
unix  3      [ ]         STREAM     CONNECTED     285020
unix  3      [ ]         STREAM     CONNECTED     285019
unix  3      [ ]         STREAM     CONNECTED     285018
unix  3      [ ]         STREAM     CONNECTED     285017
unix  3      [ ]         STREAM     CONNECTED     285016
unix  3      [ ]         STREAM     CONNECTED     285015
unix  3      [ ]         STREAM     CONNECTED     285014
unix  3      [ ]         STREAM     CONNECTED     285013
unix  3      [ ]         STREAM     CONNECTED     285012
unix  3      [ ]         STREAM     CONNECTED     285011
unix  3      [ ]         STREAM     CONNECTED     285010
unix  3      [ ]         STREAM     CONNECTED     285009
unix  3      [ ]         STREAM     CONNECTED     285008
unix  3      [ ]         STREAM     CONNECTED     285007
unix  2      [ ]         DGRAM                    239266
unix  2      [ ]         DGRAM                    3057
unix  2      [ ]         DGRAM                    1946
unix  2      [ ]         DGRAM                    1480
unix  2      [ ]         DGRAM                    1465
unix  2      [ ]         DGRAM                    1328
Vielen, Viele Danke
TO
