Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Registered User
    Join Date
    May 2005
    Posts
    1

    Default hackcheck problem

    In the daily update email I am getting the following message

    findutils fails checksum !!!
    send to CONTACTEMAIL (3) [3]
    warning: /var/tmp/rpm-xfer.lvcpwy: V3 DSA signature: NOKEY, key ID db42a60e
    Retrieving http://updates.cpanel.net/pub/hackch...1.7-9.i386.rpm
    Preparing... ##################################################
    findutils ##################################################
    error: unpacking of archive failed: cpio: lstat failed - Invalid argument

    and

    cvs: current version is 1.11.2-24.legacy, will be updated to 1.11.2-25.legacy.
    warning: /var/tmp/rpm-xfer.2Fz5Zq: V3 DSA signature: NOKEY, key ID 731002fa
    Retrieving http://updates.cpanel.net/redhat/upd...egacy.i386.rpm
    Preparing... ##################################################
    cvs ##################################################
    error: unpacking of archive failed: cpio: lstat failed - Invalid argument

    then i get an email from hackcheck telling me some files are missing


    IMPORTANT: Do not ignore this email.
    This message is to inform you that the rpm
    package findutils did not match the expected checksum. This could mean that
    your system was compromised (OwN3D). The offending files have been removed
    and replaced with the OS default. To be safe you should verify that your
    system has not be compromised.

    Modified Files:
    missing /usr/share/doc/findutils-4.1.7
    missing d /usr/share/doc/findutils-4.1.7/NEWS
    missing d /usr/share/doc/findutils-4.1.7/README

    My host hasn't seen this errors before and pointed me here, can anyone shed any light please

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Presuming that you've checked that your server has indeed not suffered a root hack and has a rootkit installed, it would help to know what OS you are running. A starting point would be to reinstall the findutils rpm.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    To be safe you should verify that your system has not be compromised.

    And that is exactly what you should do!

    Either yourself, your DC, or pay someone but at this point, I would say your Server has been compromised. The only question is to what extent.
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    This error message has only one meaning, your server has been compromised. It is very likely that your server will go offline soon, if no immediate action is taken.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  5. #5
    cPanelBilly
    Guest

    Default

    Quote Originally Posted by AndyReed
    This error message has only one meaning, your server has been compromised. It is very likely that your server will go offline soon, if no immediate action is taken.
    not quite true, it means that some base utilities are different from the RPM installs. This may happen if you chose to update them from source.

Similar Threads & Tags
Similar threads

  1. hackcheck immutable
    By aramazan in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-30-2007, 09:13 PM
  2. Problem with hackcheck on RHEL 3.0
    By Gliebster in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-30-2003, 08:34 PM
  3. hackcheck
    By areha in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-04-2003, 03:52 AM
  4. hackcheck...
    By bens in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-28-2002, 04:01 AM
  5. hackcheck
    By purplep in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 02-24-2002, 08:15 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube