LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-20-2017, 03:10 AM   #31
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217

you said you were seeing changes in the md5 checksum results. So showing the difference from one day to the next in the checksum.
 
Old 02-20-2017, 03:37 AM   #32
gbcbooks
Member
 
Registered: Aug 2014
Posts: 199

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by r3sistance View Post
you said you were seeing changes in the md5 checksum results. So showing the difference from one day to the next in the checksum.
ok, i'll check it tomorrow , i just replace it again.
 
Old 02-20-2017, 03:39 AM   #33
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,842

Rep: Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309Reputation: 7309
still would be nice to know if the "other" version belongs to the official package.
 
1 members found this post helpful.
Old 02-20-2017, 07:21 AM   #34
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
I feel compelled to offer
Sudo: you're doing it wrong - PDF @ 171 pages.
Sudo: you're doing it wrong - YouTubeVid @ 1h:11m

I likely need a refresher my damn self.
 
Old 02-20-2017, 07:45 PM   #35
gbcbooks
Member
 
Registered: Aug 2014
Posts: 199

Original Poster
Rep: Reputation: Disabled
good news ,i add "chattr +i /usr/bin/sudo and /bin/su", and no changed happen today.
 
Old 02-21-2017, 12:05 AM   #36
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217
making the files immutable means they can't be updated either, which is also a security risk... also if something was changing sudo and su, it could still be changing other things...
 
Old 02-22-2017, 09:01 AM   #37
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Yes, you definitely have some rogue code operating, and it might be attached to a crontab or to a privileged service script. It could be changing anything, anywhere. You've got to find it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Change executable file color in Bash casela Linux - Newbie 1 03-18-2012 07:30 PM
sudo and providing rights to executable. tank junior Linux - Newbie 5 05-12-2011 08:57 PM
Change the image of an executable file from commandline. udaypratapyati Linux - Newbie 3 02-15-2011 03:18 PM
Can't execute an executable, even as sudo. davemar SUSE / openSUSE 2 06-25-2008 06:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration