LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-09-2012, 06:50 PM   #1
yesandno
LQ Newbie
 
Registered: Aug 2012
Posts: 2

Rep: Reputation: Disabled
Altered files indicative of a intrusion?


Hello!

I have just ran a rkhunter scan. Some results were not clear and might be indicative of a possible prior intrusion. I search the hash codes provided in the report; but, could not find anything apart from similar questions about their origin. Thank you.

Code:
[15:51:07] Warning: The file properties have changed:
[15:51:07]          File: /usr/bin/killall
[15:51:07]          Current hash: f1ca3ee43d914964d22b7e3b0dff404fa55c2c61
[15:51:07]          Stored hash : 87828fcc6f7e270e6c9dd61746dd58bee60d9be8
[15:51:07]          Current inode: 263451    Stored inode: 262529
[15:51:07]          Current file modification time: 1342483144 (16-Jul-2012 16:59:04)
[15:51:07]          Stored file modification time : 1333155793 (30-Mar-2012 18:03:13)
[15:51:07]   /usr/bin/last                                   [ Warning ]
[15:51:07] Warning: The file properties have changed:
[15:51:07]          File: /usr/bin/last
[15:51:07]          Current hash: 2625728968b194b87e9f77a58d990c9294b4017d
[15:51:07]          Stored hash : 5d7607a22352108c4bf0568998c9bdd9e874d558
[15:51:07]          Current inode: 262862    Stored inode: 262532
[15:51:07]          Current file modification time: 1343327018 (26-Jul-2012 11:23:38)
[15:51:07]          Stored file modification time : 1334395587 (14-Apr-2012 02:26:27)
..........................................
[15:51:09] Warning: The file properties have changed:
[15:51:09]          File: /usr/bin/pstree
[15:51:09]          Current hash: 513387a0aa8864bf0e7a45691966f2ae38ac0adf
[15:51:09]          Stored hash : 0b6ad87752ff24d708c133dfaeb3abb57d7bb124
[15:51:09]          Current inode: 263452    Stored inode: 262774
[15:51:09]          Current file modification time: 1342483144 (16-Jul-2012 16:59:04)
[15:51:09]          Stored file modification time : 1333155793 (30-Mar-2012 18:03:13)
...........................................
[15:51:17] Warning: The file properties have changed:
[15:51:17]          File: /sbin/sulogin
[15:51:17]          Current hash: d6b62b44207847e92418b10dd88ebe23fb597bd7
[15:51:17]          Stored hash : 83a221fa0ac64fb86f7e01f388cc018f63c8c47e
[15:51:17]          Current inode: 7471239    Stored inode: 7471266
[15:51:17]          Current file modification time: 1343327018 (26-Jul-2012 11:23:38)
[15:51:17]          Stored file modification time : 1334395587 (14-Apr-2012 02:26:27)
...........................................
[15:51:20] Warning: The file properties have changed:
[15:51:20]          File: /bin/fuser
[15:51:20]          Current hash: 6d321869dd7e5cfaf3867339708ae00599d2e911
[15:51:20]          Stored hash : e506c975c2160bcfa7bdeb8fd60fc14482f43e9a
[15:51:20]          Current inode: 7340082    Stored inode: 7340080
[15:51:20]          Current file modification time: 1342483144 (16-Jul-2012 16:59:04)
[15:51:20]          Stored file modification time : 1333155793 (30-Mar-2012 18:03:13)
...........................................
For some reason the date on which the files were changed is the same. Might mean something? Thanks

I'm also wondering if this last entry is any good:
Code:
[15:54:06] Warning: Hidden file found: /dev/.initramfs: symbolic link to `/run/initramfs'
Thanks.
 
Old 08-09-2012, 07:28 PM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
I'd guess not... if you look at the modified times they probably line up with 2 package updates - psmisc and sysvinit-tools (at least that's the names on my system, yours should be similar)
 
Old 08-10-2012, 07:56 AM   #3
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Sample from my system following an update:
Quote:
Warning: The file properties have changed:
File: /bin/kill
Current hash: b154403c90e825e308b9b6d5f88ae454dd435f8d
Stored hash : e2ab682066dd660bc2afdb98ea3ccb4bde84926c
Current inode: 6199 Stored inode: 5091
Current file modification time: 1342492305 (16-Jul-2012 22:31:45)
Stored file modification time : 1324309315 (19-Dec-2011 10:41:55)
Warning: The file properties have changed:
File: /bin/ps
Current hash: fc4db2fcb074c0961232c71a6cad1cdfeed37b6d
Stored hash : da75b80fa56f6e9d8055e1e2092392f0e539e2bb
Current inode: 6206 Stored inode: 5092
Current file modification time: 1342492305 (16-Jul-2012 22:31:45)
Stored file modification time : 1324309315 (19-Dec-2011 10:41:55)
If in doubt, check your apt logs and verify the date-time and md5sum of these utilities against the current package versions.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How is Linux altered to run as a live CD? Ramune Linux - General 5 04-24-2009 11:30 PM
use apt-get to check for altered files? leapy Linux - Security 4 08-05-2007 05:41 PM
XF86Config-4 altered after reboot (no glx) Cyrus XIII Mandriva 2 12-02-2004 03:46 AM
Is this indicative of an open relay? mcleodnine Linux - Security 5 10-07-2004 08:09 PM
Find all system files altered or added by me suguru Linux - Newbie 3 09-19-2004 01:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration