ich habe gerade, weil ich es hier in einigen Threads gelesen habe, das chkrootkit runtergeladen und auf meinem rootserver ausgeführt. Dass lief auch fast problemlos durch, nur eine Linie beunruhigt mich:
"Checking `bindshell'... INFECTED (PORTS: 465)"
Das hört sich ja garnicht gut an. Was hat das zu bedeuten?
Hier noch meine Betriebssystemdaten:
Suse 8.1 (Update vom Support)
PHP 4.2.6
Zusätzlich installierte Programme:
- AWStats
- Midnight-Commander
Sonst ist nichts am System verändert (meinerseits)
Ein Portscan zeigt mir, dass der Port offen ist und mit "ssmtp" beschriftet wird.
Hier noch die Ausgaben von ein Paar Scripten
Code: Select all
netstat -an
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:995 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:110 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:465 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN
tcp 0 0 217.160.133.26:80 217.83.42.112:2582 ESTABLISHED
tcp 0 78840 217.160.133.26:80 193.159.138.207:33755 ESTABLISHED
tcp 0 0 217.160.133.26:80 217.83.42.112:2578 TIME_WAIT
tcp 0 0 217.160.133.26:80 217.83.42.112:2576 ESTABLISHED
tcp 0 0 217.160.133.26:110 212.95.103.34:64719 TIME_WAIT
tcp 0 0 217.160.133.26:22 217.230.12.104:23763 ESTABLISHED
tcp 0 0 217.160.133.26:80 195.93.66.6:58377 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.133.183.81:57934 TIME_WAIT
tcp 0 0 217.160.133.26:80 80.130.147.210:1655 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.130.147.210:1654 ESTABLISHED
tcp 0 0 217.160.133.26:80 195.93.66.16:51878 ESTABLISHED
tcp 0 0 217.160.133.26:80 217.83.42.112:2574 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.133.148.24:2158 ESTABLISHED
tcp 0 0 217.160.133.26:80 193.159.138.207:33762 TIME_WAIT
tcp 0 0 217.160.133.26:80 217.83.42.112:2575 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.133.148.24:2159 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.130.147.210:1657 ESTABLISHED
tcp 0 0 217.160.133.26:80 217.83.42.112:2572 TIME_WAIT
tcp 0 0 217.160.133.26:80 80.133.148.24:2156 ESTABLISHED
tcp 0 0 217.160.133.26:80 217.83.42.112:2573 ESTABLISHED
tcp 0 0 217.160.133.26:80 195.93.64.13:49939 ESTABLISHED
tcp 0 0 217.160.133.26:80 217.83.42.112:2571 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.133.148.24:2152 ESTABLISHED
tcp 0 0 217.160.133.26:80 195.93.65.12:37681 ESTABLISHED
tcp 0 0 217.160.133.26:80 80.133.148.24:2153 ESTABLISHED
udp 0 0 0.0.0.0:68 0.0.0.0:*
udp 0 0 217.160.133.26:123 0.0.0.0:*
udp 0 0 127.0.0.1:123 0.0.0.0:*
udp 0 0 0.0.0.0:123 0.0.0.0:*
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node Path
unix 2 [ ACC ] STREAM LISTENING 3367 /var/run/.nscd_socket
unix 2 [ ACC ] STREAM LISTENING 1098 /var/lib/mysql/mysql.sock
unix 2 [ ACC ] STREAM LISTENING 1663 public/cleanup
unix 2 [ ACC ] STREAM LISTENING 1776 public/flush
unix 2 [ ACC ] STREAM LISTENING 1784 public/showq
unix 2 [ ACC ] STREAM LISTENING 1670 private/rewrite
unix 2 [ ACC ] STREAM LISTENING 1768 private/bounce
unix 2 [ ACC ] STREAM LISTENING 1772 private/defer
unix 2 [ ACC ] STREAM LISTENING 1780 private/smtp
unix 2 [ ACC ] STREAM LISTENING 1788 private/error
unix 2 [ ACC ] STREAM LISTENING 1792 private/local
unix 2 [ ACC ] STREAM LISTENING 1796 private/virtual
unix 2 [ ACC ] STREAM LISTENING 1800 private/lmtp
unix 2 [ ACC ] STREAM LISTENING 1804 private/cyrus
unix 2 [ ACC ] STREAM LISTENING 1808 private/uucp
unix 2 [ ACC ] STREAM LISTENING 1812 private/ifmail
unix 2 [ ACC ] STREAM LISTENING 1816 private/bsmtp
unix 2 [ ACC ] STREAM LISTENING 1820 private/vscan
unix 2 [ ACC ] STREAM LISTENING 1824 private/procmail
unix 11 [ ] DGRAM 938 /dev/log
unix 2 [ ] DGRAM 1034014
unix 2 [ ] DGRAM 1016173
unix 2 [ ] DGRAM 285079
unix 3 [ ] STREAM CONNECTED 285050
unix 3 [ ] STREAM CONNECTED 285049
unix 3 [ ] STREAM CONNECTED 285048
unix 3 [ ] STREAM CONNECTED 285047
unix 3 [ ] STREAM CONNECTED 285046
unix 3 [ ] STREAM CONNECTED 285045
unix 3 [ ] STREAM CONNECTED 285044
unix 3 [ ] STREAM CONNECTED 285043
unix 3 [ ] STREAM CONNECTED 285042
unix 3 [ ] STREAM CONNECTED 285041
unix 3 [ ] STREAM CONNECTED 285040
unix 3 [ ] STREAM CONNECTED 285039
unix 3 [ ] STREAM CONNECTED 285038
unix 3 [ ] STREAM CONNECTED 285037
unix 3 [ ] STREAM CONNECTED 285036
unix 3 [ ] STREAM CONNECTED 285035
unix 3 [ ] STREAM CONNECTED 285034
unix 3 [ ] STREAM CONNECTED 285033
unix 3 [ ] STREAM CONNECTED 285030
unix 3 [ ] STREAM CONNECTED 285029
unix 3 [ ] STREAM CONNECTED 285028
unix 3 [ ] STREAM CONNECTED 285027
unix 3 [ ] STREAM CONNECTED 285026
unix 3 [ ] STREAM CONNECTED 285025
unix 3 [ ] STREAM CONNECTED 285024
unix 3 [ ] STREAM CONNECTED 285023
unix 3 [ ] STREAM CONNECTED 285022
unix 3 [ ] STREAM CONNECTED 285021
unix 3 [ ] STREAM CONNECTED 285020
unix 3 [ ] STREAM CONNECTED 285019
unix 3 [ ] STREAM CONNECTED 285018
unix 3 [ ] STREAM CONNECTED 285017
unix 3 [ ] STREAM CONNECTED 285016
unix 3 [ ] STREAM CONNECTED 285015
unix 3 [ ] STREAM CONNECTED 285014
unix 3 [ ] STREAM CONNECTED 285013
unix 3 [ ] STREAM CONNECTED 285012
unix 3 [ ] STREAM CONNECTED 285011
unix 3 [ ] STREAM CONNECTED 285010
unix 3 [ ] STREAM CONNECTED 285009
unix 3 [ ] STREAM CONNECTED 285008
unix 3 [ ] STREAM CONNECTED 285007
unix 2 [ ] DGRAM 239266
unix 2 [ ] DGRAM 3057
unix 2 [ ] DGRAM 1946
unix 2 [ ] DGRAM 1480
unix 2 [ ] DGRAM 1465
unix 2 [ ] DGRAM 1328
Code: Select all
netstat -a -n
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:995 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:110 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:465 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN
tcp 0 0 217.160.133.26:22 217.230.12.104:23763 ESTABLISHED
tcp 0 0 217.160.133.26:80 193.159.138.207:33739 FIN_WAIT2
tcp 0 0 217.160.133.26:80 217.238.33.30:3483 ESTABLISHED
tcp 0 0 217.160.133.26:80 193.159.138.207:33743 FIN_WAIT2
tcp 0 0 217.160.133.26:80 212.33.63.179:3508 TIME_WAIT
tcp 0 0 217.160.133.26:80 217.238.33.30:3477 ESTABLISHED
udp 0 0 0.0.0.0:68 0.0.0.0:*
udp 0 0 217.160.133.26:123 0.0.0.0:*
udp 0 0 127.0.0.1:123 0.0.0.0:*
udp 0 0 0.0.0.0:123 0.0.0.0:*
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node Path
unix 2 [ ACC ] STREAM LISTENING 3367 /var/run/.nscd_socket
unix 2 [ ACC ] STREAM LISTENING 1098 /var/lib/mysql/mysql.sock
unix 2 [ ACC ] STREAM LISTENING 1663 public/cleanup
unix 2 [ ACC ] STREAM LISTENING 1776 public/flush
unix 2 [ ACC ] STREAM LISTENING 1784 public/showq
unix 2 [ ACC ] STREAM LISTENING 1670 private/rewrite
unix 2 [ ACC ] STREAM LISTENING 1768 private/bounce
unix 2 [ ACC ] STREAM LISTENING 1772 private/defer
unix 2 [ ACC ] STREAM LISTENING 1780 private/smtp
unix 2 [ ACC ] STREAM LISTENING 1788 private/error
unix 2 [ ACC ] STREAM LISTENING 1792 private/local
unix 2 [ ACC ] STREAM LISTENING 1796 private/virtual
unix 2 [ ACC ] STREAM LISTENING 1800 private/lmtp
unix 2 [ ACC ] STREAM LISTENING 1804 private/cyrus
unix 2 [ ACC ] STREAM LISTENING 1808 private/uucp
unix 2 [ ACC ] STREAM LISTENING 1812 private/ifmail
unix 2 [ ACC ] STREAM LISTENING 1816 private/bsmtp
unix 2 [ ACC ] STREAM LISTENING 1820 private/vscan
unix 2 [ ACC ] STREAM LISTENING 1824 private/procmail
unix 11 [ ] DGRAM 938 /dev/log
unix 2 [ ] DGRAM 1042377
unix 2 [ ] DGRAM 1016173
unix 2 [ ] DGRAM 285079
unix 3 [ ] STREAM CONNECTED 285050
unix 3 [ ] STREAM CONNECTED 285049
unix 3 [ ] STREAM CONNECTED 285048
unix 3 [ ] STREAM CONNECTED 285047
unix 3 [ ] STREAM CONNECTED 285046
unix 3 [ ] STREAM CONNECTED 285045
unix 3 [ ] STREAM CONNECTED 285044
unix 3 [ ] STREAM CONNECTED 285043
unix 3 [ ] STREAM CONNECTED 285042
unix 3 [ ] STREAM CONNECTED 285041
unix 3 [ ] STREAM CONNECTED 285040
unix 3 [ ] STREAM CONNECTED 285039
unix 3 [ ] STREAM CONNECTED 285038
unix 3 [ ] STREAM CONNECTED 285037
unix 3 [ ] STREAM CONNECTED 285036
unix 3 [ ] STREAM CONNECTED 285035
unix 3 [ ] STREAM CONNECTED 285034
unix 3 [ ] STREAM CONNECTED 285033
unix 3 [ ] STREAM CONNECTED 285030
unix 3 [ ] STREAM CONNECTED 285029
unix 3 [ ] STREAM CONNECTED 285028
unix 3 [ ] STREAM CONNECTED 285027
unix 3 [ ] STREAM CONNECTED 285026
unix 3 [ ] STREAM CONNECTED 285025
unix 3 [ ] STREAM CONNECTED 285024
unix 3 [ ] STREAM CONNECTED 285023
unix 3 [ ] STREAM CONNECTED 285022
unix 3 [ ] STREAM CONNECTED 285021
unix 3 [ ] STREAM CONNECTED 285020
unix 3 [ ] STREAM CONNECTED 285019
unix 3 [ ] STREAM CONNECTED 285018
unix 3 [ ] STREAM CONNECTED 285017
unix 3 [ ] STREAM CONNECTED 285016
unix 3 [ ] STREAM CONNECTED 285015
unix 3 [ ] STREAM CONNECTED 285014
unix 3 [ ] STREAM CONNECTED 285013
unix 3 [ ] STREAM CONNECTED 285012
unix 3 [ ] STREAM CONNECTED 285011
unix 3 [ ] STREAM CONNECTED 285010
unix 3 [ ] STREAM CONNECTED 285009
unix 3 [ ] STREAM CONNECTED 285008
unix 3 [ ] STREAM CONNECTED 285007
unix 2 [ ] DGRAM 239266
unix 2 [ ] DGRAM 3057
unix 2 [ ] DGRAM 1946
unix 2 [ ] DGRAM 1480
unix 2 [ ] DGRAM 1465
unix 2 [ ] DGRAM 1328
Vielen, Viele Danke
TO