I've seen numerous false positives come from linux systems running
OSSEC. It has something to do with linking if I remember correctly. By
the way, how ya been?
Regards,
Adriel T. Desautels
Chief Technology Officer
Netragard, LLC.
Office : 617-934-0269
Mobile : 617-633-3821
http://www.linkedin.com/pub/1/118/a45
Join the Netragard, LLC. Linked In Group:
http://www.linkedin.com/e/gis/48683/0B98E1705142
---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com - "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security
Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know : http://tinyurl.com/26pjsn
John Simone wrote:
> Hello,
>
> I'm trying to determine if we're getting false positives on a recent
> rash of alerts from only one of several RHEL 4 AS servers we have in
> our farm. We received a slew of warnings (100+) about the MD5
> checksum changing for our binaries:
>
> <code>
> OSSEC HIDS Notification.
> 2008 Sep 05 05:39:33
>
> Received From: (hostname) XXX.XXX.XXX.XXX->syscheck
> Rule: 550 fired (level 7) -> "Integrity checksum changed."
> Portion of the log(s):
>
> Integrity checksum changed for: '/usr/bin/ldapmodify'
> Old md5sum was: '923a6e19535fdf5bf6ebdaadd943b574'
> New md5sum is : '32d0f468d5f8fd564286f749d37c22b7'
> Old sha1sum was: '497e3e0ad4d3459d558991cf51883956c70d6e76'
> New sha1sum is : '858c5c67ea965685feeabd1193aef115e70a0b85'
>
>
>
> --END OF NOTIFICATION
> </code>
>
> What would cause this?
>
> Thanks,
> John
begin:vcard
fn:Adriel T Desautels
n:Desautels;Adriel T
org:Netragard, LLC.
adr:;;17 Sheldon Road;Mendham ;NJ;;USA
email;internet:[EMAIL PROTECTED]
title:Chief Technology Officer
tel;work:617-934-0269
tel;cell:617-633-3821
x-mozilla-html:FALSE
url:http://www.netragard.com
version:2.1
end:vcard