On Friday 19 November 2010 14:02:45 Justin Redman wrote:
> I am seeing this too.  In our case I believe it is related to our Oracle
> cluster's heartbeat since it is only occurring on those servers.  Not sure
> if that helps you any though.
> 

Just to confirm that. I've seen it a few times over the past few months but 
only on one server and that is running Oracle 11. I'v checked out the netstat 
executable even reinstalled it. So I assume it's a false positive.

Tony

> 
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On
> Behalf Of x509v3 Sent: Friday, November 19, 2010 12:08 AM
> To: ossec-list
> Subject: [ossec-list] Anyone seeing false positives like this? : Port
> '60256'(tcp) hidden. Kernel-level rootkit or trojaned version of netstat.
> 
> Hi,  been running ossec for about a month now, after testing for
> another month. Tonight I received the following from one my production
> machines:
> 
> OSSEC HIDS Notification.
> 2010 Nov 18 19:36:56
> 
> Received From: (host) 10.1.1.1->rootcheck
> Rule: 510 fired (level 7) -> "Host-based anomaly detection event
> (rootcheck)."
> Portion of the log(s):
> 
> Port '60256'(tcp) hidden. Kernel-level rootkit or trojaned version of
> netstat.
> 
> --END OF NOTIFICATION
> 
> Host 10.1.1.1 is an IBM PowerPC host running AIX.  I've seen this type
> of alert on my mac at home (PowerPC running 10.4), every once in a
> while. I confirmed from the Mac install DVD that the latter was a
> false positive.
> 
> It's likely that this alert is a false positive too, but taking it
> offline isn't really an option unless we're sure there's an issue.
> Unfortunately, alerts like this trigger a mandatory incident response
> and be disruptive, so many false alarms will not be good.
> 
> Anyone else seeing netstat-related false alarms list this?

Reply via email to