Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 9 of 9

This is a discussion on rkhunter says: Incorrect MD5 checksums in the VPS & Dedicated forum
Hello I got my VPS little over a week ago, and one of the first things I installed was latest version of rkhunter. Every scan ...

  1. #1
    Banned
    Join Date
    Feb 2007
    Location
    At home
    Posts
    10

    rkhunter says: Incorrect MD5 checksums

    Hello

    I got my VPS little over a week ago, and one of the first things I installed was latest version of rkhunter.

    Every scan since this says that I have 4 files with Incorrect MD5 checksums:

    /bin/kill
    /sbin/insmod
    /sbin/lsmod
    /sbin/modprobe

    Support say this is because it's a VPS?

    I have had a VPS with another company for almost 2 years running FC2 and rkhunter, never any "Incorrect MD5 checksums".
    Before I got a VPS here, I tried another VPS with another company, with much the same specs as Jaguar with CentOS 4.4
    There I also installed rkhunter and did not have any errors like this.

    Any one else get the same errors on their VPS?

  2. #2
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Sounds like a cPanel/WHM thing to me...

    Were you running them at your last ASP?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  3. #3
    Banned
    Join Date
    Feb 2007
    Location
    At home
    Posts
    10
    Quote Originally Posted by Vin DSL View Post
    Sounds like a cPanel/WHM thing to me...

    Were you running them at your last ASP?
    Can you please ask using different words?
    You write ASP, I think Active Server Page or something like that which I'm not using

    But I'm also a little concerned that support "just" made conclusion that this is a "VPS thing" without even checking anything.
    I get mail if anyone logs in to SSH on my VPS, and no login was made when I opened ticket about this.
    Last edited by macern; 02-16-2007 at 03:55 AM.

  4. #4
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by macern View Post
    Can you please ask using different words?
    You write ASP, I think Active Server Page or something like that which I'm not using
    Sorry about that...

    I tend to use ISP (Internet Service Provider) when I'm talking about my ADSL carrier, and ASP (Application Service Provider) when I'm talking about web hosts.

    I was guessing that this problem might have something to do with the cPanel/WHM software. You said rkhunter was working at your previous web host.

    I was wondering if you were running cPanel/WHM at your previous VPS web host...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  5. #5
    Banned
    Join Date
    Feb 2007
    Location
    At home
    Posts
    10
    Yes I have been running same version of WHM/cPanel on 3 different VPS from 3 different companies.

    Only difference was hardware, and FC2 on one and CentOS 4.4 on two.
    The other VPS running CentOS, same version as Jaguar, did not have any errors reported by rkhunter.

  6. #6
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    You may like to follow up with rkhunter developers for more information about the false positives.

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

  7. #7
    Banned
    Join Date
    Feb 2007
    Location
    At home
    Posts
    10
    Quote Originally Posted by masood View Post
    You may like to follow up with rkhunter developers for more information about the false positives.
    Since support did nothing to check to see if this are false positives or not, I do not know if these are "false positives" as you say, so how can you say these are false, are you just assuming it?

    I do not at this time have the "know how" on how to check if these are false positives or not"

  8. #8
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    Please pm with your ticket # and I can look into it.

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

  9. #9
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    Thank you for the pm and giving me the opportunity to look into it with more details.

    I checked the md5 hash against the binaries distributed by CentOS and it matches with the file you have on the vps for

    /bin/kill

    So obviously rkhunter database is outdated for that.

    And all these three

    /sbin/insmod
    /sbin/lsmod
    /sbin/modprobe

    are part of virtuozzo package and not of OS provided binaries so they should NOT match. I have updated the KB.

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •