LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-04-2007, 02:50 PM   #1
slackamp
Member
 
Registered: Dec 2005
Distribution: slackware-current
Posts: 86

Rep: Reputation: 16
file utility md5sum


Can someone please provide me their /usr/bin/file md5sum.

rkhunter is detecting that this file is BAD.

Here is mine.
# md5sum /usr/bin/file
604cc461f8b8ef332ff2b8b693cd4595 /usr/bin/file


.
 
Old 06-04-2007, 02:53 PM   #2
slackamp
Member
 
Registered: Dec 2005
Distribution: slackware-current
Posts: 86

Original Poster
Rep: Reputation: 16
i downloaded the file package from one of the slackware mirrors (tds) and verified that the md5sum matches.
 
Old 06-04-2007, 03:05 PM   #3
dive
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Slackware
Posts: 3,467

Rep: Reputation: Disabled
a4f5bae7ed7940c6a829cb6eb9767b08 /usr/bin/file

from -current
 
Old 06-04-2007, 03:40 PM   #4
Road_map
Member
 
Registered: Jan 2007
Distribution: Slackware
Posts: 341

Rep: Reputation: 31
604cc461f8b8ef332ff2b8b693cd4595 /usr/bin/file

from Slackware-stable

"unknown hashes", because I installed rkhunter before file-4.20-i486-1_slack11.0.tgz. This package was not in initial install, was added in /patches (0a9109c5f0a8d44e018b70b140c77a46 file-4.20-i486-1_slack11.0.tgz is the correct md5sum for downloaded package).
 
Old 06-04-2007, 03:54 PM   #5
pwc101
Senior Member
 
Registered: Oct 2005
Location: UK
Distribution: Slackware
Posts: 1,847

Rep: Reputation: 128Reputation: 128
604cc461f8b8ef332ff2b8b693cd4595 /usr/bin/file

I also installed the new file from /patches.
 
Old 06-04-2007, 03:59 PM   #6
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Do 'rkhunter --update', that should fix it.
 
Old 06-04-2007, 04:02 PM   #7
dive
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Slackware
Posts: 3,467

Rep: Reputation: Disabled
file --version
file-4.20
 
Old 06-04-2007, 04:24 PM   #8
Road_map
Member
 
Registered: Jan 2007
Distribution: Slackware
Posts: 341

Rep: Reputation: 31
Code:
# rkhunter --update
Running updater...

Mirrorfile /usr/local/rkhunter/lib/rkhunter/db/mirrors.dat rotated
Using mirror http://rkhunter.sourceforge.net
[DB] Mirror file                      : Up to date
[DB] MD5 hashes system binaries       : Up to date
[DB] Operating System information     : Update available
  Action: Database updated (current version: 2006111400, new version 2007060301)
[DB] MD5 blacklisted tools/binaries   : Up to date
[DB] Known good program versions      : Update available
  Action: Database updated (current version: 2007040501, new version 2007051701)
[DB] Known bad program versions       : Up to date
Then again:
Quote:
/usr/bin/file [ BAD ]
 
Old 06-04-2007, 04:39 PM   #9
pwc101
Senior Member
 
Registered: Oct 2005
Location: UK
Distribution: Slackware
Posts: 1,847

Rep: Reputation: 128Reputation: 128
Perhaps unSpawn (or the rkhunter devel team) haven't got the new md5sum for this version of file in their database. I emailed one the other day, and they promptly added it, so it might be worth an email to check...
 
Old 06-04-2007, 04:52 PM   #10
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Either way, 'file' is just fine ... I mean if the md5sum matches the mirror, then it should be fine. The rkhunter devs must update their md5sums.
 
Old 06-04-2007, 08:00 PM   #11
slackamp
Member
 
Registered: Dec 2005
Distribution: slackware-current
Posts: 86

Original Poster
Rep: Reputation: 16
Talking

thanks for all the replies. yah i thought it was ok i just wanted to verify. i did do an rkhunter --update before running the check. i also have file installed from /patches. again thanks for the replies, i was just a little paranoid.
 
Old 06-04-2007, 08:36 PM   #12
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
You can download hashupd.sh from the rkhunter site and use it to update the hash from the new version of file. I went through the same thing here...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
md5sum different on gzipped file, but same when gunzipped jim-j Linux - Software 2 12-07-2006 09:41 PM
md5sum file satimis Fedora 2 02-24-2006 10:46 AM
Find File broken, need search utility, where does WineX install, KDE file roller? Ohmn Mandriva 6 07-05-2004 10:34 PM
md5sum how do you check a file with it ? Joe47 Linux - Newbie 6 11-30-2003 08:02 PM
Good File Comparison Utility Witch-King Linux - Software 4 01-01-2003 10:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 11:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration