Re: chkrootkit V. 0.47

Running freeBSD 6.1

After changing chkrootkit to the latest version V. 0.47 and compiling it
then running it I get the following:
Checking `bindshell'... INFECTED (PORTS: 6667)

I do run an IRCd...

Such tools is known to trigger false positives sometimes. I'd recommend to
play with some additional utilities like lsof. In case of bindshell try to
find processes that was executed from world writable directories such
as /tmp. Try to shutdown httpd and other daemons and see if any of them
still running.

The bindshell is most probably a false positive - chkrootkit just
checks if anything is listening on "unusual" ports. Since 6667 is
one of the most often used well-known ports for IRC communication,
this is most probably a false positive.


