LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-17-2004, 07:28 PM   #1
Scarpa
LQ Newbie
 
Registered: Feb 2003
Location: Sydney, Australia.
Posts: 13

Rep: Reputation: 0
Question RKHUNTER: Bad MD5 Checksums


Hey guys,

I have a small querry for you all and would appreciate any advice/comments.

I have done a fresh install of Fedora Core 2 (minimal programs needed as per security). I then installed Firestarter for the firewall (and started it straight away). Installed RKHUNTER for rootkit check etc. Ran RKHUNTER for first check (everything fine). Then connected cable modem and went to RedHat Live Update (up2date) service and downloaded and installed required packages etc (including kernel - I think that was the wrong thing to do with regards to kenel but anyway).

Now, after up2date and install (including Kernel) I ran RKHUNTER again and recieved the following:

1) ifconfig [BAD]
2) netstat [BAD]
Your MD5 checksums do not match

Thats pretty much it. What does this all mean? What action is to be taken?

As a footnote the only services I have running when doing a netstat -tul is: *bootpc*. Is this a good start also?

Anyway look forward to your help. Thanks in advance guys.
 
Old 06-18-2004, 02:54 AM   #2
iainr
Member
 
Registered: Nov 2002
Location: England
Distribution: Ubuntu 9.04
Posts: 631

Rep: Reputation: 30
When rkhunter is updated with new versions, md5 checksums/hashes of key binary files that are likely to be trojaned are added. The exact hash value will vary from version to version so, for example, there might be some small change between the ifconfig binary on SuSE 8.2 and on SuSE 9.0.

Rkhunter figures out what version of Linux you are running and, if it knows the "correct" hashes for that, it checks them. Keeping all those hashes up to date is a pretty thankless task and, of course, if you update something that rolls out a new version of one of those binaries, the hash is going to be wrong.

This is almost certainly a false positive, which you should be able to safely ignore.

You could also contact the maintainer (Michael) at www.rkhunter.org/contact/ and let him know the details. He puts out new versions of rkhunter ever few weeks so an update should get in pretty quickly.
 
Old 06-18-2004, 05:56 AM   #3
Scarpa
LQ Newbie
 
Registered: Feb 2003
Location: Sydney, Australia.
Posts: 13

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by iainr
Rkhunter figures out what version of Linux you are running and, if it knows the "correct" hashes for that, it checks them. Keeping all those hashes up to date is a pretty thankless task and, of course, if you update something that rolls out a new version of one of those binaries, the hash is going to be wrong.
Hi Iain

Thanks very much for your reply.

I wasnt too sure what was happening and when I downloaded from up2date and saw this change (in rkhunter) the box was taken offline straight away...anyway will send the changes to (Michael) at www.rkhunter.org/contact/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Bad Checksums In Rkhunter sovietpower Linux - Security 3 09-07-2004 07:11 PM
Is there a way to use MD5 checksums in Windows? Zakalidas Linux - Newbie 2 07-05-2004 10:12 PM
Error in MD5 checksums: ryedunn Linux - Newbie 2 04-20-2004 08:14 PM
checksums.md5 whitefox Slackware 2 04-18-2003 01:53 PM
MD5 Checksums for ISOs in Windows? TruckStuff Linux - General 5 05-17-2002 03:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration