It was prelinking.  Thanks for the tips!

Regards,
John 

-----Original Message-----
From: [email protected] [mailto:[EMAIL PROTECTED]
On Behalf Of Adriel Desautels
Sent: Friday, September 05, 2008 10:59 AM
To: [email protected]
Subject: [ossec-list] Re: Laundry list of binaries had their MD5 changed
?!

I've seen numerous false positives come from linux systems running
OSSEC. It has something to do with linking if I remember correctly. By
the way, how ya been?

Regards,
        Adriel T. Desautels
        Chief Technology Officer
        Netragard, LLC.
        Office : 617-934-0269
        Mobile : 617-633-3821
        http://www.linkedin.com/pub/1/118/a45

        Join the Netragard, LLC. Linked In Group:
        http://www.linkedin.com/e/gis/48683/0B98E1705142

---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com  -  "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security

Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j Three Things you
must know  : http://tinyurl.com/26pjsn


John Simone wrote:
> Hello,
> 
> I'm trying to determine if we're getting false positives on a recent 
> rash of alerts from only one of several RHEL 4 AS servers we have in 
> our farm.  We received a slew of warnings (100+) about the MD5 
> checksum changing for our binaries:
> 
> <code>
> OSSEC HIDS Notification.
> 2008 Sep 05 05:39:33
> 
> Received From: (hostname) XXX.XXX.XXX.XXX->syscheck
> Rule: 550 fired (level 7) -> "Integrity checksum changed."
> Portion of the log(s):
> 
> Integrity checksum changed for: '/usr/bin/ldapmodify'
> Old md5sum was: '923a6e19535fdf5bf6ebdaadd943b574'
> New md5sum is : '32d0f468d5f8fd564286f749d37c22b7'
> Old sha1sum was: '497e3e0ad4d3459d558991cf51883956c70d6e76'
> New sha1sum is : '858c5c67ea965685feeabd1193aef115e70a0b85'
> 
> 
> 
>  --END OF NOTIFICATION
> </code>
> 
> What would cause this?
> 
> Thanks,
> John

Reply via email to