Hello

I am testing OSSEC and have discovered that Solaris servers running with
local zones are reporting odd messages:

2011 Feb 16 08:27:25 (first time detected: 2011 Feb 09 14:59:37)
System Audit: Port '779'(tcp) hidden. Kernel-level rootkit or trojaned
version of netstat.


How is it finding the open ports and reporting on them? I read if it sees
open ports and then notices that they are not open from a netstat it will
report this error.  Just not sure what command or script is reporting
ports listening on what seems like closed ports.

We have tested with netcat and nmap, confirmed with netstat and lsof that
nothing listening on the port and verified this remotely all results show
the port closed.

Thanks
-Gary

Reply via email to