Skip to main content

System Integrity checking detected a modified system file

Comments

6 comments

  • cPanelWilliam
    Hi! Does the yum log show that those packages were recently updated or changed? You can run a command similar to the following to see whether the Imunify packages were updated recently: grep imunify /var/log/yum.log
    We have more information about these types of notifications here:
    0
  • ljj3
    No. There are vastly more notifications than uucp updates. Sometimes one per hour for days at a time. My suspicion has been hardware failure but the host, who has been quite good insists it's nothing - which makes no sense. Security is very tight.
    0
  • ljj3
    As another example, all of our VPS' reported file changes last night consistent with uucp running. Including the system in question. But it also reported a different set of changes multiple times with no uucp. This has been going on for months, btw. Just trying to get to the bottom of it, since I'm barely using this system since I don't trust it with an odd problem no one seems to understand.
    0
  • cPanelWilliam
    Hi, [QUOTE]As another example, all of our VPS' reported file changes last night consistent with uucp running. Including the system in question. But it also reported a different set of changes multiple times with no uucp. This has been going on for months, btw.
    It would be difficult to say what is modifying those system files without access to the server to review the complete bash history, logs, and server configuration. It would be normal to receive these alerts during cPanel updates, but what you said indicates something outside of cPanel is modifying system files. Typically these types of investigations should be handled by a security administrator. I'd suggest opening a ticket to see if our team can shed some light on the issue, although we may not be able to resolve it directly as it does not appear to be caused by cPanel.
    0
  • ljj3
    I'm sure its not a cPanel problem and I appreciate you taking a look. I also doubt this is security related, we are exceptionally cautious in that regard and it makes no sense that some entity would be repeatedly changing one group of files hundreds of times a month. It looks to me like corruption of some sort especially when combined with altered packages and other warnings. cPanel has looked at the server when it was also dropping services randomly and had no conclusive answers. I am going to move the last couple of accounts off and deep six this VPS, as it has caused 1000 times more problems than all our others combined. Just wish someone could advise if corruption, bad disk, bad memory or alien space lasers could lead to this problem! :)
    0
  • cPRex Jurassic Moderator
    I always go straight for the alien space lasers, personally.
    0

Please sign in to leave a comment.