LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-12-2007, 08:53 AM   #1
m2azer
Member
 
Registered: Sep 2004
Location: USA
Distribution: red hat, fedora & centos
Posts: 202

Rep: Reputation: 30
Checksum for /etc/passwd changed


Hello,

While checking my logs i found :

SECURITY ALERT: Checksum for /etc/passwd changed!



How would i know what changed in the passwd file?

Thanks
 
Old 12-12-2007, 09:19 AM   #2
bhaslinux
Member
 
Registered: Oct 2003
Location: UnitedKingdom
Distribution: Debian Bullseye
Posts: 357

Rep: Reputation: 49
What is the version and name of Unix you are using ?
The change to /etc/passwd file is not possible unless done by root.
But there is a very good chance that the checksum changes if

1. any user is added to the system
(this need not be the sys-admin known one. Some of the applications like imap, ssh, mail
etc., creates its own login for previlidge seperation)
2. Any user's primary group changes
3. Anyone's GECOS field has changed
4. Anyone's shell has changed
 
Old 12-12-2007, 09:27 AM   #3
m2azer
Member
 
Registered: Sep 2004
Location: USA
Distribution: red hat, fedora & centos
Posts: 202

Original Poster
Rep: Reputation: 30
Thanks for the reply - I understand that something has changed. My question - is there anyway to find out what changed? what new user has been added or what user group has been modified? etc

OS is rhel4
 
Old 12-12-2007, 10:58 AM   #4
forrestt
Senior Member
 
Registered: Mar 2004
Location: Cary, NC, USA
Distribution: Fedora, Kubuntu, RedHat, CentOS, SuSe
Posts: 1,288

Rep: Reputation: 99
ANY user can change the passwd file with chsh (and probably a list of other tools). Also, if you install some software it will generate password entries (MySQL and Apache come to mind, but there are MANY more). There isn't a way to know what changed by just looking at the password file (unless you have backup copies from before the change to compare), but if you see something wierd (a non-root user at the top of the list, a non-root user with UID 0, users you don't know, etc.) then there is a problem. The log entry is your IDS telling you that something changed. If you changed something, double check the password file and create a new checksum for that file. If you didn't change anything, it doesn't mean someone broke in, it just means you need to check the file for anomalies. Think of it like your car alarm going off. Just because it goes off doesn't mean someone is trying to steal it, but it does mean you should check things out and reset the alarm when you are satisfied everything is ok.

HTH

Forrest
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to protect root passwd from being changed somnathlinux General 5 08-27-2007 02:13 PM
Upgrade to DD and it changed passwd. ty13 Ubuntu 2 08-20-2006 06:49 PM
changed passwd doesn't unlock the screen cheez_m Ubuntu 1 11-13-2005 07:40 AM
Root passwd changed Tinku Linux - Security 9 10-22-2004 12:52 AM
changed the login shell in /etc/passwd to the wrong path infamous41md Solaris / OpenSolaris 3 07-03-2004 07:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration