False Positive: IRCDs running on port 6667

Bug #629723 reported by Thomas Ward
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
chkrootkit (Ubuntu)
Confirmed
Medium
Unassigned

Bug Description

Binary package hint: chkrootkit

This program detects falsely an infection on port 6667. This is the case with an IRCD running on port 6667 being detected as bindshell.

This is a bug, but also could the documentation on false positives be amended to include the info about ircds also triggering false positives?

System Info: Ubuntu 10.04 Lucid Lynx, both 32-bit and 64-bit server editions (multiple servers)

Thomas Ward (teward)
description: updated
Revision history for this message
Clint Byrum (clint-fewbar) wrote :

Hi TrekCaptainUSA, thanks so much for taking the time to report this bug and help us make Ubuntu better!

I tried this on a fresh install of lucid, indeed if you just do 'apt-get install ircd-hbrid chkrootkit' and run chkrootkit, bindshell is falsely detected. Marking Confirmed.

Setting Importance to Medium. While this is a bug, its only a problem for users who have installed an irc daemon, which is not a common use case.

Changed in chkrootkit (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Revision history for this message
Thomas Ward (teward) wrote :

Perhaps a separate optional -doc package for possible server-related false positives, or perhaps a chkrootkit.SERVER-FALSE-POSITIVES doc? Just an opinion.

Thank you though for quickly processing this bug report.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.