Hi all,
I`ve updated rkhunter yesterday the new port deleted my old configuration and now I`m getting some strange reports:
I looked into this "new" port 47763 and found it was not even a port
Is that issue observed only by me, maybe I missconfigured something? Is it normal portupgrade to delete the old configuration file?
I`ve updated rkhunter yesterday the new port deleted my old configuration and now I`m getting some strange reports:
Code:
FreeBSD wolfdale 8.1-RELEASE-p1 FreeBSD 8.1-RELEASE-p1 #0: Sun Oct 10 15:57:09 EEST 2010
Rootkit Hunter 1.3.8
Code:
Warning: Differences found between sockstat and netstat output:
Sockstat output (ports in use): 139 2094 2095 21 22 25 3306 445 47763 80
Netstat output (ports in use): 139 2094 2095 21 22 25 3306 445 80
I looked into this "new" port 47763 and found it was not even a port
Code:
[root@wolfdale ~/scripts]# netstat -an | grep 47763
ffffff005e78db40 stream 0 0 ffffff000b6e9000 0 0 0 /tmp/ssh-kbxohRioPN/agent.47763
[root@wolfdale ~/scripts]# sockstat -p 47763
USER COMMAND PID FD PROTO LOCAL ADDRESS FOREIGN ADDRESS
click sshd 47763 4 stream -> ??
click sshd 47763 9 stream /tmp/ssh-kbxohRioPN/agent.47763
root sshd 47761 5 stream -> ??
root cron 15312 4 dgram -> /var/run/logpriv
root syslogd 15167 4 dgram /var/run/log
root syslogd 15167 5 dgram /var/run/logpriv
88 mysqld 15088 14 stream /tmp/mysql.sock
root cron 14818 4 dgram -> /var/run/logpriv
root syslogd 14621 4 dgram /var/run/log
root syslogd 14621 5 dgram /var/run/logpriv
root cron 14475 4 dgram -> /var/run/logpriv
root syslogd 14338 4 dgram /var/run/log
root syslogd 14338 5 dgram /var/run/logpriv
root cron 14189 4 dgram -> /var/run/logpriv
root syslogd 14044 4 dgram /var/run/log
root syslogd 14044 5 dgram /var/run/logpriv
root cron 13896 4 dgram -> /var/run/logpriv
root syslogd 13756 4 dgram /var/run/log
root syslogd 13756 5 dgram /var/run/logpriv
root cron 3173 5 dgram -> /var/run/logpriv
smmsp sendmail 3166 3 dgram -> /var/run/log
root sendmail 3162 3 dgram -> /var/run/logpriv
root monit 1184 3 dgram -> /var/run/logpriv
root syslogd 1042 4 dgram /var/run/log
root syslogd 1042 5 dgram /var/run/logpriv
root devd 859 6 stream /var/run/devd.pipe
_pflogd pflogd 557 5 stream -> ??
root pflogd 554 4 stream -> ??
root pflogd 554 5 dgram -> /var/run/logpriv
Is that issue observed only by me, maybe I missconfigured something? Is it normal portupgrade to delete the old configuration file?