Answer the question
In order to leave comments, you need to log in
Rootkit or still postfix? If postfix, how to close "extra" ports?
I installed chkrootkit on the server and scanned it.
He cursed at port 465: Checking `bindshell'... INFECTED (PORTS: 465)
Here is the output of some commands:
netstat -an|grep 465
tcp 0 0 0.0.0.0:465 0.0.0.0:* LISTEN
tcp6 0 0 :::465 :::* LISTEN
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
master 31549 root 106u IPv4 255217 0t0 TCP *:urd (LISTEN)
master 31549 root 107u IPv6 255218 0t0 TCP *:urd (LISTEN)
PID TTY STAT TIME COMMAND
31549 ? Ss 0:32 /usr/lib/postfix/master
Answer the question
In order to leave comments, you need to log in
asked and answered
It looks like this port is used by postfix for smtp.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question