Chkrootkit warning about infected port 600
3
votes
2
answers
1236
views
I run the Tiger Automatic Auditor on my Debian Linux system, and recently got emailed the following:
# Running chkrootkit (/usr/sbin/chkrootkit) to perform further checks...
OLD: --ALERT-- [rootkit005a] Chkrootkit has found a file which seems to be infected because of a rootkit
OLD: --ALERT-- [rootkit009a] A rootkit seems to be installed in the system
OLD: INFECTED (PORTS: 600)
I immediately ran chkrootkit manually, and didn't see any warnings or unusual results. How can I tell whether this was a false positive?
Asked by jrdioko
(860 rep)
Aug 31, 2011, 09:37 PM
Last activity: Feb 26, 2018, 10:03 PM
Last activity: Feb 26, 2018, 10:03 PM