Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 29
  1. #1
    Member
    Join Date
    Sep 2001
    Posts
    189

    Default [hackcheck] fileutils failed checksum test

    Did you receive this? (I have such emails from 2 servers)
    ----------------------------

    IMPORTANT: Do not ignore this email.
    This message is to inform you that the rpm
    package fileutils did not match the expected checksum. This could mean that
    your system was compromised (OwN3D). The offending files have been removed
    and replaced with the OS default. To be safe you should verify that your
    system has not be compromised.

    Modified Files:
    .......T c /etc/DIR_COLORS
    .......T c /etc/profile.d/colorls.csh
    .......T c /etc/profile.d/colorls.sh
    Alex Andreyev,
    http://www.WHost.INFO - NEW web hosting directory.

  2. #2
    Member
    Join Date
    Aug 2001
    Location
    Sarasota, FL
    Posts
    64

    Default

    I got that as well about 1/2 hour ago...

  3. #3
    Member
    Join Date
    Oct 2002
    Posts
    94

    Default

    just got right now as well.

    Is this something to worry about?

  4. #4
    Member
    Join Date
    May 2002
    Posts
    152

    Default Same here

    But only on the RedHat 7.2 boxes. The 7.3 ones had no problem.

    It appears that upcp downloaded the latest version of fileutils tonight. No reason to think this is an intrusion.


    Downloading fileutils-4.1-10.1.i386.rpm
    Retrieving http://updates.cpanel.net/pub/rpmup/redhat/7.3/x86/updates/fileutils-4.1-10.1.i386.rpm
    Preparing... ##################################################
    fileutils ##################################################

    - Jason
    Ecoutez! Ltd.
    www.ecoutez.com
    Our new Theme: www.MaxPanel.com

  5. #5
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064

    Default Same here !

    same for me on my red hat 7.2 :-O !!!
    I forced to reinstall the fileutils rpm , and I rebuilded the rpm
    database , today I received again that advice .
    What's happening ?
    Look the modification on /sbin/nologin too ...
    (file Size , 5 MD5 sum and mTime differ.... )

    have we to be worried ?

    [b:04bfbf1282]
    ==================
    # rpm -V util-linux net-tools procps fileutils

    .......T c /etc/fdprm
    .......T c /etc/pam.d/chfn
    .......T c /etc/pam.d/chsh
    .......T c /etc/pam.d/login
    S.5....T /sbin/nologin
    .......T c /etc/DIR_COLORS
    .......T c /etc/profile.d/colorls.csh
    .......T c /etc/profile.d/colorls.sh
    ==================
    [/b:04bfbf1282]
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

  6. #6
    kt
    kt is offline
    Member
    Join Date
    May 2002
    Posts
    40

    Default got the same here

    Only my system was hacked =o(

  7. #7
    Member
    Join Date
    Aug 2002
    Posts
    111

    Default

    I got the same email

    how do tell if my system was hacked?

    Thanks
    Ivaserver

  8. #8
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    One way to tell is a trojan horse.

    look in /usr/share/locale/sk/.sk

    use ls -la

    It is a trojan that causes the following

    Hidden Pid detected! [pid 1455]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/share/locale/sk/.sk/sk]

    It is a sniffer program trying to get info on the system.
    Regards,
    David
    Forum Moderator

  9. #9
    Member
    Join Date
    Aug 2002
    Location
    Huntington Beach, Ca
    Posts
    232

    Default

    I have looked in /usr/share/locale/sk and there does not seem to be any .sk and I am getting the message.

  10. #10
    Member
    Join Date
    Mar 2002
    Posts
    10

    Default

    Hi guys,
    I am also gettin the same Warning e-mail since 2 days now
    Would this be a C-panel WHM error ?????

    Sanuk

  11. #11
    ozzi4648
    Guest

    Default

    Another night of receiving this msg. Will they not fix this? 3 or 4 nights and counting. Get it together Cpanel!!!!!!!!!!!!!!!!!!!!!!

  12. #12
    Member
    Join Date
    Jan 2003
    Posts
    5

    Default

    I am seeing this on all our 7.2 boxen but not our 8.0 ones.

    Looks like a minor CP bug at this time.
    Mark Porterfield
    DPS Systems, Inc.
    A CPanel Partner NOC

  13. #13
    Member
    Join Date
    May 2002
    Posts
    152

    Default This issue is resolved

    Nick took a look at one of my RedHat 7.2 boxes exhibiting this behavior and found the problem.

    Run /scripts/updatenow and it should be fixed.

    - Jason
    Ecoutez! Ltd.
    www.ecoutez.com
    Our new Theme: www.MaxPanel.com

  14. #14
    Member
    Join Date
    Mar 2002
    Posts
    10

    Default

    Hello,

    Please informme how to:
    Run /scripts/updatenow and it should be fixed.

    Or will the error also be fixed by the next-days C-panel update

    Thanks & Regards
    Sanuk

  15. #15
    Member
    Join Date
    Aug 2002
    Location
    Huntington Beach, Ca
    Posts
    232

    Default

    SSH into you box, move into the scripts directory /scripts and ./updatenow

Similar Threads & Tags
Similar threads

  1. [hackcheck] tcp_wrappers failed checksum test
    By Joost34 in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 02-28-2008, 02:04 AM
  2. [hackcheck] findutils failed checksum test
    By Daemon1 in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 08-09-2006, 10:11 AM
  3. [hackcheck] fileutils failed checksum test
    By wimp in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-01-2003, 09:08 AM
  4. fileutils failed checksum test
    By mitul in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-08-2003, 02:48 PM
  5. fileutils failed checksum test
    By dandanfireman in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-02-2002, 03:20 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube