UPDATE!! (was Re: Have I been compromised? chkrootkit: "Warning: Possible LKM Trojan installed" - nmap: "port 1313 open")

From: Tom (northofthecold_at_yahoo.com)
Date: 11/14/03


Date: 14 Nov 2003 11:26:02 -0800

Update:

OK, I don't have portsentry installed.

Today, after getting a full night's rest, and finding the referrenced
posting on uk.comp.os.linux, I did a ps.

Part of it shows:

root 1 0.0 0.0 84 52 ? S Oct30 0:20 init [5]
root 2 0.0 0.0 0 0 ? SW Oct30 0:14 [keventd]
root 0 0.0 0.0 0 0 ? SWN Oct30 0:01 [ksoftirqd_CPU0]
root 0 0.0 0.0 0 0 ? SW Oct30 2:32 [kswapd]
root 0 0.0 0.0 0 0 ? SW Oct30 0:05 [bdflush]
root 0 0.0 0.0 0 0 ? SW Oct30 2:50 [kupdated]
root 8 0.0 0.0 0 0 ? SW Oct30 0:01 [kreiserfsd]
root 65 0.0 0.0 0 0 ? SW Oct30 0:00 [khubd]
root 136 0.0 0.0 0 0 ? SW Oct30 0:05 [pagebufd]
root 137 0.0 0.0 0 0 ? SW Oct30 0:00 [xfslogd/0]
root 138 0.0 0.0 0 0 ? SW Oct30 0:00 [xfsdatad/0]

I count four processes there. That's how many chkrootkit is
complaining about.

Why wouldn't I have chkproc? I have chkrootkit installed...

However, one unsettling thing is that when I open a 'virtual terminal'
by pressing control+alt+f2 or f3, and I do ifdown and ifup, I get the
following strange results:
ifdown -a says "eth0: Promiscuous mode enabled.", which doesn't make
sense, cuz the interface is going down... and ifup -a says "eth0:
Setting half-duplex based on auto-negotiated partner ability 0000",
Followed by *six* lines of eth0: Promiscuous mode enabled.

So, I feel like I'm clean, but then what the heck is running on port
1313?



Relevant Pages

  • Re: Suse 9.0 and Wireless Issues
    ... Using your tip (ifdown ... eth0, ifup wlan0), the card worked. ... I know that only one network connection can use dhcp, ... Maybe eth0 needed a difference configuration? ...
    (alt.os.linux.suse)
  • Re: How to temp diable a NIC
    ... >>As root ... > You can use ifup and ifdown to turn it on and off, ...
    (alt.os.linux.suse)
  • Re: FC8 how to get static IP working
    ... however it always boot up using DHCP. ... Here's my config files and I have tried ifdown and ifup on eth0 on ...
    (Fedora)
  • Re: I got hacked!!!
    ... >]wu-FTP, telnet, and ssh running on one of my linux boxes. ... >]PCI: Using configuration type 1 ... >]eth0: Promiscuous mode enabled. ...
    (comp.os.linux.security)
  • Re: Uninstalling Network Manager -> No More WiFi (Dapper)
    ... I assume eth0 is your wireless card. ... UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 ... PING 192.168.1.1 56bytes of data. ... I also note that I cannot ifdown the ethernet connection without ...
    (Ubuntu)