From owner-freebsd-questions@FreeBSD.ORG Fri Feb 8 11:08:22 2013 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by hub.freebsd.org (Postfix) with ESMTP id 7B5C8908 for ; Fri, 8 Feb 2013 11:08:22 +0000 (UTC) (envelope-from guru@unixarea.de) Received: from ms16-1.1blu.de (ms16-1.1blu.de [89.202.0.34]) by mx1.freebsd.org (Postfix) with ESMTP id 43FBBCF6 for ; Fri, 8 Feb 2013 11:08:22 +0000 (UTC) Received: from [82.113.98.34] (helo=tiny.Sisis.de) by ms16-1.1blu.de with esmtpsa (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from ) id 1U3loU-0001OC-5B for freebsd-questions@freebsd.org; Fri, 08 Feb 2013 12:08:14 +0100 Received: from tiny.Sisis.de (localhost [127.0.0.1]) by tiny.Sisis.de (8.14.5/8.14.3) with ESMTP id r18B8CES066190 for ; Fri, 8 Feb 2013 12:08:12 +0100 (CET) (envelope-from guru@unixarea.de) Received: (from guru@localhost) by tiny.Sisis.de (8.14.5/8.14.3/Submit) id r18B8B39066189 for freebsd-questions@freebsd.org; Fri, 8 Feb 2013 12:08:11 +0100 (CET) (envelope-from guru@unixarea.de) X-Authentication-Warning: tiny.Sisis.de: guru set sender to guru@unixarea.de using -f Date: Fri, 8 Feb 2013 12:08:11 +0100 From: Matthias Apitz To: freebsd-questions@freebsd.org Subject: warnings is rkhunter(8) about ports usage Message-ID: <20130208110810.GA66174@tiny.Sisis.de> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Operating-System: FreeBSD 10.0-CURRENT r226986 (i386) User-Agent: Mutt/1.5.21 (2010-09-15) X-Con-Id: 51246 X-Con-U: 0-guru X-Originating-IP: 82.113.98.34 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list Reply-To: Matthias Apitz List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 08 Feb 2013 11:08:22 -0000 Hello, I run rkhunter from time to time and have warnings about the diff between sockstat and netstat like this: [11:33:31] Warning: Differences found between sockstat and netstat output: [11:33:31] Sockstat output (ports in use): 0 1124 22 25 514 587 [11:33:31] Netstat output (ports in use): 22 25 514 587 the diff ports in sockstat are: $ sockstat | fgrep ' 0 ' root ipmon 695 0 dgram -> /var/run/logpriv $ sockstat | fgrep 1124 guru ssh-agent 1125 3 stream /tmp/ssh-KldJtKCKwQMi/agent.1124 Why is rkhunter complaining about them? Thx matthias -- Sent from my FreeBSD netbook Matthias Apitz | - No system with backdoors like Apple/Android E-mail: guru@unixarea.de | - No HTML/RTF in E-mail WWW: http://www.unixarea.de/ | - No proprietary attachments phone: +49-170-4527211 | - Respect for open standards