It was prelinking. Thanks for the tips! Regards, John
-----Original Message----- From: [email protected] [mailto:[EMAIL PROTECTED] On Behalf Of Adriel Desautels Sent: Friday, September 05, 2008 10:59 AM To: [email protected] Subject: [ossec-list] Re: Laundry list of binaries had their MD5 changed ?! I've seen numerous false positives come from linux systems running OSSEC. It has something to do with linking if I remember correctly. By the way, how ya been? Regards, Adriel T. Desautels Chief Technology Officer Netragard, LLC. Office : 617-934-0269 Mobile : 617-633-3821 http://www.linkedin.com/pub/1/118/a45 Join the Netragard, LLC. Linked In Group: http://www.linkedin.com/e/gis/48683/0B98E1705142 --------------------------------------------------------------- Netragard, LLC - http://www.netragard.com - "We make IT Safe" Penetration Testing, Vulnerability Assessments, Website Security Netragard Whitepaper Downloads: ------------------------------- Choosing the right provider : http://tinyurl.com/2ahk3j Three Things you must know : http://tinyurl.com/26pjsn John Simone wrote: > Hello, > > I'm trying to determine if we're getting false positives on a recent > rash of alerts from only one of several RHEL 4 AS servers we have in > our farm. We received a slew of warnings (100+) about the MD5 > checksum changing for our binaries: > > <code> > OSSEC HIDS Notification. > 2008 Sep 05 05:39:33 > > Received From: (hostname) XXX.XXX.XXX.XXX->syscheck > Rule: 550 fired (level 7) -> "Integrity checksum changed." > Portion of the log(s): > > Integrity checksum changed for: '/usr/bin/ldapmodify' > Old md5sum was: '923a6e19535fdf5bf6ebdaadd943b574' > New md5sum is : '32d0f468d5f8fd564286f749d37c22b7' > Old sha1sum was: '497e3e0ad4d3459d558991cf51883956c70d6e76' > New sha1sum is : '858c5c67ea965685feeabd1193aef115e70a0b85' > > > > --END OF NOTIFICATION > </code> > > What would cause this? > > Thanks, > John
