• [^] # Re: "chkrootkit" bien sûr et non "chksecurity" !!

    Posté par . En réponse au message checksecurity signale une "contagion" : conduite à tenir ?. Évalué à 1.

    Vite fait d'installer nmap (au passage, téléchargé tripwire par précaution pour le futur s'il s'agit ce coup-ci d'une fausse alerte !) et donc, ça donne ça :

    Starting nmap 3.81 ( http://www.insecure.org/nmap/ ) at 2005年07月15日 00:28 CEST
    Interesting ports on l05m-212-194-120-220.d4.club-internet.fr (212.194.120.220):
    (The 1660 ports scanned but not shown below are in state: closed)
    PORT STATE SERVICE
    22/tcp open ssh
    111/tcp open rpcbind
    606/tcp open urm

    Nmap finished: 1 IP address (1 host up) scanned in 0.317 seconds

    ****

    C'est qui rpcbind ??

    on le retrouve ci-dessous en plus...

    **

    Pour telnet, il n'y a rien qui passe (j'ai anonymisé mon IP en abc.def, si je suis peut-être vérolé, je ne suis pas non plus totalement moisi !) :

    telnet 212.194.abc.def
    Trying 212.194.abc.def...
    telnet: Unable to connect to remote host: Connection refused

    **

    Pour netstat, voilà ma sortie :

    Herissonodrome:/home/yoj# netstat -ltpn
    Connexions Internet actives (seulement serveurs)
    Proto Recv-Q Send-Q Adresse locale Adresse distante Etat PID/Program name
    tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 1859/portmap
    tcp 0 0 0.0.0.0:4662 0.0.0.0:* LISTEN 14481/amule
    tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 2105/sshd
    tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2091/exim4
    tcp 0 0 0.0.0.0:606 0.0.0.0:* LISTEN 2120/rpc.statd


    Bon, je vais fermer ma connexion et j'y reviendrai demain depuis un autre OS. mais tout celà m'ennuie bien...


    Yoj' pertubé mais baîllant !