Skip to main content

Passwd Infected Chkrootkit

Comments

6 comments

  • HostNoc
    an you run the following commands and let us know the output? sha256sum /bin/passwd sha256sum /usr/bin/passwd Regards HostNoc
    0
  • net@work
    Thank you @HostNoc
    0
  • cPanelAnthony
    The passwd INFECTED warning you see from chkrootkit is a common false-positive on cPanel servers. This is because cPanel has modified that binary so it can be used with JailShell. I would suggest opening a support ticket using the link in my signature (or asking your provider to open one for you) so we can investigate for any potential issues. Provide me with the ID once open if you can.
    0
  • net@work
    Hello @cPanelAnthony Is possible to make a test server with the latest enviroment of centos 7, x86_64 and WHM 11.98.0.11 and compare the MD5 and SHA256 checksums as this old thread from @cPanelMichael here: Thank you.
    0
  • cPanelAnthony
    [QUOTE="net@work, post: 2886005, member: 813191"] Hello @cPanelAnthony Is possible to make a test server with the latest enviroment of centos 7, x86_64 and WHM 11.98.0.11 and compare the MD5 and SHA256 checksums as this old thread from @cPanelMichael here:
    0
  • cPanelAnthony
    Hello again! It looks like this should be possible. However, it might be best if you open a ticket so we can review the issue briefly. Are you able to do so using the link in my signature?
    0

Please sign in to leave a comment.