home *** CD-ROM | disk | FTP | other *** search
/ The Hacker's Encyclopedia 1998 / hackers_encyclopedia.iso / hacking / general / cert0077.txt < prev    next >
Encoding:
Text File  |  2003-06-11  |  30.7 KB  |  580 lines

  1.  
  2. -----BEGIN PGP SIGNED MESSAGE-----
  3.  
  4. =============================================================================
  5. CERT(sm) Advisory CA-94:05                    
  6. Original issue date:  March 18, 1994
  7. Last revised: August 30, 1996
  8.               Information previously in the README was inserted
  9.               into the advisory. Updated URL format.
  10.  
  11.               A complete revision history is at the end of this file.
  12.                     
  13. Topic:  MD5 Checksums
  14. - -----------------------------------------------------------------------------
  15.  
  16. This advisory gives the MD5 checksums for a number of SunOS files, along
  17. with a tool for checking them.  The checksums can be used to assure the
  18. integrity of those files.
  19.  
  20. The CERT Coordination Center is distributing these checksums because of an
  21. increasing number of incidents in which intruders who gain root access
  22. are modifying system files to install Trojan horses.
  23.  
  24. Moreover, intruders are modifying files so that they have the same checksum
  25. as the original file.  This is possible because the standard "sum" program
  26. that comes with most UNIX systems was designed to detect accidental
  27. modifications to files and is not strong enough to prevent deliberate
  28. attempts to yield a specific checksum.  The MD5 algorithm by RSA Data
  29. Security, Inc. is specifically designed to provide checksums that cannot
  30. be deliberately spoofed.  We strongly recommend that sites install the
  31. MD5 software and use it to validate system software.  More information
  32. on obtaining MD5 is given below.
  33.  
  34. The list of checksums in Appendix B of this advisory is provided for
  35. your convenience.  In addition, we are providing a program that can assist
  36. you in checking your MD5 output against the values in the database.
  37. This checksum list is not complete.  We have begun with a number of
  38. the more common locations for Trojan horses that we have seen in
  39. connection with the continuing "sniffer" attacks reported in CA-94:01
  40. "Ongoing Network Monitoring Attacks."  We intend to work with
  41. all vendors to expand this list and make more MD5 checksums widely
  42. available for anonymous FTP.
  43.  
  44. Note: After we publish checksums in advisories, files are sometimes updated at
  45. individual locations because of system upgrades or patch installation. For
  46. current MD5 checksum values, we recommend that you check with your vendor.
  47.  
  48. We encourage sites to consider installing a more complete package for
  49. monitoring system integrity, such as Tripwire from the COAST project
  50.     ftp://ftp.cs.purdue.edu/
  51.  
  52. or the TIGER system from TAMU 
  53.     ftp://net.tamu.edu/pub/security/TAMU/
  54.  
  55. - -----------------------------------------------------------------------------
  56.  
  57. I.   Description
  58.  
  59.      Intruders are installing Trojan horses by modifying system files
  60.      often in such a way that a standard checksum on the file generates the
  61.      same checksum as the unaltered version.
  62.  
  63. II.  Impact
  64.  
  65.      The Trojan horses give the intruder continued access to a system
  66.      and/or hide the intruder's activities.
  67.  
  68. III. Solution
  69.  
  70.      1.  Obtain and install MD5.
  71.  
  72.          The MD5 algorithm is in the public domain, and there are several
  73.          programs available that implement it.  The algorithm is documented
  74.          in RFC 1321, which is available from many archives including
  75.          the "/rfc" directory in the anonymous FTP archive at ds.internic.net.
  76.          RFC 1321 itself includes source code for implementing the algorithm.
  77.          For convenience, that source has been extracted and made available
  78.          for anonymous FTP on info.cert.org in the "pub/tools/md5" directory.
  79.  
  80.      2.  Run the "md5check" program listed in Appendix A of this advisory.
  81.  
  82.          This program will check a number of system files and note for
  83.          each one whether the checksum did or did not match the checksum
  84.          of a legitimate version.
  85.  
  86.          If the checksum does match, you can be confident that particular
  87.          file has not been modified by an intruder.  Note this does not mean
  88.          the file is the most recent version for your system - only that
  89.          it was in fact distributed by Sun.
  90.  
  91.          If the checksum DOES NOT match, consider these possible reasons:
  92.  
  93.          1) The file may be legitimate but not included in this database.
  94.             (Remember, the database is not complete.)  To check this
  95.             possibility, compare the file against the original distribution
  96.             media.  You may want to add the correct checksum to your copy
  97.             of the database.
  98.  
  99.          2) You may have made local modifications to the file at your site.
  100.             To check this possibility, compare the file to a known good
  101.             version.  You may want to add the correct checksum to your copy
  102.             of the database.
  103.  
  104.          3) The file may be a Trojan horse installed by an intruder.
  105.             We encourage you to replace this file with a known good version,
  106.             and check for additional signs of compromise.
  107.  
  108. ..............................................................................
  109.  
  110. Appendix A: "md5check"
  111.  
  112.    The following program is a "nawk" script that can be run against
  113.    the list of checksums "md5_sun.v1" in Appendix B:
  114.  
  115.         % nawk -f md5check md5_sun.v1
  116.  
  117.    This program along with a man page and the database below,
  118.    are available by anonymous FTP from info.cert.org in the
  119.    "pub/tools/md5check" directory.
  120.  
  121.          Filename          MD5 Checksum
  122.          --------          -----------------------------
  123.          md5check          99108ab5a6007164a910626bbcc5888f
  124.          md5_sun.v1        780a0f1f3717819c59135716e5f6a1ce
  125.  
  126.  
  127. - ------- Cut Here -------
  128. # "md5check" version 1 (3/17/94)
  129. BEGIN { FS = "[ \t]*:[ \t]*"; }
  130.  
  131. # Print notices from the configuration file
  132. /^##/ { print substr ($0, 3); next; }
  133.  
  134. # Only handle MD5 checksums currently
  135. /^md5/ {
  136.         source = sprintf("%-7s %-8s %-6s %s", $2, $3, $5, $4);
  137.         file = $6;
  138.         sum = hex_lower($7);
  139.         if (md5[file] == "") {
  140.                 print "Checking", file;
  141.                 testcmd = "test -r " file;
  142.                 if ( system(testcmd) != 0 ) {
  143.                         print " Could not open", file;
  144.                         md5[file] = "x";
  145.                         next;
  146.                 } else {
  147.                         md5cmd = "md5 " file
  148.                         md5cmd | getline md5[file];
  149.                         close (md5cmd);
  150.  
  151.                         # Strip off any leading text and set to lowercase
  152.                         sub(".*[ \t]", "", md5[file]);
  153.                         md5[file] = hex_lower(md5[file]);
  154.                 }
  155.         }
  156.         if (md5[file] == "x" || file in matched) {
  157.                 # Could not open or already matched
  158.                 next;
  159.         }
  160.         if (md5[file] == sum) {
  161.                 # We have a match - remember which one
  162.                 matched[file] = source;
  163.                 num_match++;
  164.                 if (file in not_matched) {
  165.                         num_no_match--;
  166.                         delete not_matched[file];
  167.                 }
  168.         } else {
  169.                 if (! (file in not_matched)) {
  170.                         num_no_match++;
  171.                         not_matched[file] = 1;
  172.                 }
  173.         }
  174. }
  175.  
  176. END {
  177.         printf "\n%d files DID NOT MATCH a known checksum\n", num_no_match;
  178.         printf "%d files did match a known checksum\n", num_match;
  179.  
  180.         print "\nThe following files DID NOT MATCH a known checksum";
  181.         for (filename in not_matched) {
  182.                 printf "\t%s\n", filename;
  183.         }
  184.  
  185.         print "\nThe following files did match a known checksum";
  186.         for (filename in matched) {
  187.                 printf "\t%s\n\t\t%s\n", filename, matched[filename];
  188.         }
  189.  
  190. }
  191. function hex_lower(s) {
  192.      gsub("A","a",s); gsub("B","b",s); gsub("C","c",s);
  193.      gsub("D","d",s); gsub("E","e",s); gsub("F","f",s);
  194.      return s
  195. }
  196. - ------- Cut Here -------
  197.  
  198. ..............................................................................
  199.  
  200. Appendix B: Checksums from Vendors
  201.  
  202. Note: After we publish checksums in advisories, files are sometimes updated at
  203. individual locations because of system upgrades or patch installation. For
  204. current MD5 checksum values, we recommend that you check with your vendor.
  205.  
  206. Hewlett-Packard Company
  207. =======================
  208. To obtain a copy of the HP SupportLine mail service user's guide, send the
  209. following (in the TEXT PORTION OF THE MESSAGE to) to the HP SupportLine mail
  210. service.
  211.  
  212.      To: support@support.mayfield.hp.com
  213.  
  214.      Message Text:
  215.  
  216.       send guide.txt
  217.  
  218. To obtain a patch identified within this Security Bulletin, send the following
  219. (in the TEXT PORTION OF THE MESSAGE) to the HP SupportLine mail service.
  220.  
  221.     To: support@support.mayfield.hp.com
  222.  
  223.     Message Text:
  224.  
  225.      send xxxxxxxxxxxx
  226.  
  227.     (where xxxxxxxxxxxx represents the specified patch name).
  228.  
  229. If you have concerns about security issues, please forward them to:
  230.  
  231.                    security-alert@hp.com
  232.  
  233. The security-alert node is monitored during working hours Pacific Daylight
  234. Time by multiple HP Security Response Team personnel. We reply to your message
  235. only if necessary to obtain additional information.
  236.  
  237.  
  238. Solbourne (Grumman Systems Support)
  239. ===================================
  240.  
  241. A list of MD5 checksums for Solbourne (Grumman Systems Support)
  242. executables under 4.1C is available via anonymous ftp from
  243. ftp.nts.gssc.com in directory /pub/docs/, files usr.etc.md5 and
  244. bin.md5. These include the files referred to in the advisory.
  245.  
  246. The MD5 checksums for these executables are included below:
  247.  
  248.      MD5 (bin.md5) = cf3b3d8447ae19fa7e1741939fe82ea9
  249.      MD5 (bin.md5.41b) = 7e0c1ae26eda72f1791e235ab244ae44
  250.      MD5 (usr.etc.md5) = 1727d1705cc7750b7848df60a4b5788e
  251.      MD5 (usr.etc.md5.41b) = 7e02c01cc47ec469c3210a8fabb012ff
  252.  
  253.  
  254.  
  255. Sun Microsystems, Inc.
  256. ======================
  257.  
  258. ## Checksum Table for Selected SunOS Binary Files (v1: 3/17/94)
  259. ##
  260. ## PLEASE NOTE:  The entries included in this table do not represent complete
  261. ##               coverage of all released versions of these files.
  262. ##               In particular, checksum data for outdated patch releases is
  263. ##               limited.
  264. ##
  265. ##               Failure to match a checksum for a given file does not
  266. ##               necessarily indicate the presence of a Trojan binary.
  267. ##               Failure indicates that the file's checksum did not match any
  268. ##               contained in this table.  The file's authenticity should be
  269. ##               verified against distribution media or local modifications.
  270. ##
  271. ##               Success at matching a file's checksum indicates that the 
  272. ##               corresponding file is free from tampering.
  273. ##
  274. # (MD5 is the RSA Data Security, Inc. Message Digest Algorithm)
  275. #
  276. # format of data
  277. #
  278. # XSUMTYPE:OSNAME:OSVERSION:SOURCE:ARCH:FILE:XSUM
  279.  
  280. #/bin/login
  281. md5:SunOS:4.1:100201-06:sun3:/bin/login:00d95a04ecce2193b9c6e16516d37855
  282. md5:SunOS:4.1:100201-06:sun4:/bin/login:e746fed42be0433a53cce082acfee23c
  283. md5:SunOS:4.1:100630-01:sun3:/bin/login:11d5ed4445face25642100ec0ab1ed3c
  284. md5:SunOS:4.1:100630-01:sun4:/bin/login:b6d013403c54949c0e476afd966ef261
  285. md5:SunOS:4.1.1:Original Dist:sun3:/bin/login:073d378264f25245c154be8a12f208e9
  286. md5:SunOS:4.1.1:Original Dist:sun4:/bin/login:92611eb1ef1f221c1e9c76db8da44a99
  287. md5:SunOS:4.1.1:100201-06:sun3:/bin/login:00d95a04ecce2193b9c6e16516d37855
  288. md5:SunOS:4.1.1:100201-06:sun4:/bin/login:e746fed42be0433a53cce082acfee23c
  289. md5:SunOS:4.1.1:100630-01:sun3:/bin/login:11d5ed4445face25642100ec0ab1ed3c
  290. md5:SunOS:4.1.1:100630-01:sun4:/bin/login:b6d013403c54949c0e476afd966ef261
  291. md5:SunOS:4.1.1:100632-06:sun4:/bin/login:12c4b39cb94b8dcdad0a10e1c59345c6
  292. md5:SunOS:4.1.1:100633-01:sun4:/bin/login:9634cda7a353d0043a22ad2b0eebaab2
  293. md5:SunOS:4.1.2:Original Dist:sun4:/bin/login:637503c0e2b46791820609d87629db91
  294. md5:SunOS:4.1.2:100630-01:sun4:/bin/login:b6d013403c54949c0e476afd966ef261
  295. md5:SunOS:4.1.2:100631-01:sun3:/bin/login:65d1e270fbb13984f5e0036b9e4a1011
  296. md5:SunOS:4.1.2:100631-01:sun4:/bin/login:976a0431dbd23ec1535c1679e215095b
  297. md5:SunOS:4.1.2:100632-06:sun4:/bin/login:12c4b39cb94b8dcdad0a10e1c59345c6
  298. md5:SunOS:4.1.2:100633-01:sun4:/bin/login:9634cda7a353d0043a22ad2b0eebaab2
  299. md5:SunOS:4.1.3:100630-02:sun3:/bin/login:11d5ed4445face25642100ec0ab1ed3c
  300. md5:SunOS:4.1.3:100630-02:sun4:/bin/login:b6d013403c54949c0e476afd966ef261
  301. md5:SunOS:4.1.3:100632-06:sun4:/bin/login:12c4b39cb94b8dcdad0a10e1c59345c6
  302. md5:SunOS:4.1.3:Original Dist:sun4:/bin/login:e88e84d228d05e8f54a0d57d62d0710d
  303. md5:SunOS:4.1.3c:Original Dist:sun4:/bin/login:e88e84d228d05e8f54a0d57d62d0710d
  304. md5:SunOS:4.1.3_u1:Original Dist:sun4:/bin/login:4e437a85e05f886ff5082ac58108d882
  305.  
  306.  
  307. #/usr/kvm/ps
  308. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/kvm/ps:ac96820499c2da78d65700e230f66df2
  309. md5:SunOS:4.1.1:Original Dist:sun3:/usr/kvm/ps:b4633eed82815a233d2ca8d8df8d655e
  310. md5:SunOS:4.1.1:Original Dist:sun4:/usr/kvm/ps:390ef406ba27b1d591ba6f281986369b
  311. md5:SunOS:4.1.1:Original Dist:sun4c:/usr/kvm/ps:cb58a8259ff580389b115b7861793b48
  312. md5:SunOS:4.1.2:Original Dist:sun4:/usr/kvm/ps:efca4ca10a088e557c6c69695dadcfa6
  313. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/kvm/ps:9d489c87d709a540aced718a04e38e11
  314. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/kvm/ps:e9e364f3936a5b16d7e2fb812d11e475
  315. md5:SunOS:4.1.2:100981-02:sun4:/usr/kvm/ps:86b8b5eb7212c94c9c570cd20c9af2ae
  316. md5:SunOS:4.1.2:100981-02:sun4c:/usr/kvm/ps:4871287498c0ab7b17d97848ebe34d15
  317. md5:SunOS:4.1.2:100981-02:sun4m:/usr/kvm/ps:97cc063bafa6aaf032cb1b67b444c5a8
  318. md5:SunOS:4.1.3:Original Dist:sun4:/usr/kvm/ps:226ab466429f5d4de4f6a108bae1c518
  319. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/kvm/ps:83b369e5d8c34db4d5d6725140d0b216
  320. md5:SunOS:4.1.3:100981-02:sun4:/usr/kvm/ps:a4809a70e66b415bae8a165dc4ffb185
  321. md5:SunOS:4.1.3:100981-02:sun4c:/usr/kvm/ps:cf10e206de67755e801e4c9d96c239a9
  322. md5:SunOS:4.1.3:100981-02:sun4m:/usr/kvm/ps:d6237550748855bee17ce96465cd1331
  323. md5:SunOS:4.1.3_u1:Original Dist:sun4m:/usr/kvm/ps:92c3b1495ab80446ddb6979c890cee58
  324. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/kvm/ps:b14b75017dfe75ea1b89d147c6b49cb7
  325. md5:SunOS:4.1.3_u1:Original Dist:sun4c:/usr/kvm/ps:e24eab973f1b1cfd6bf5b54310a2207f
  326. md5:SunOS:4.1.3_u1:101442-01:sun4:/usr/kvm/ps:174731efb18020dacde9f205ad04a4bf
  327.  
  328. #/usr/etc/in.telnetd
  329. md5:SunOS:4.0.3:100125-05:sun3:/usr/etc/in.telnetd:dce91901f9fd15f7f6f6c94fb7824428
  330. md5:SunOS:4.0.3:100125-05:sun4:/usr/etc/in.telnetd:2e67031ad7984c22cfacc8a0b4c3d6ee
  331. md5:SunOS:4.0.3c:100125-05:sun4c:/usr/etc/in.telnetd:943574a9befb9fac3fce2fc111f68d51
  332. md5:SunOS:4.1:100125-05:sun3:/usr/etc/in.telnetd:2544753907d24a699c9cdfddcab0d2e3
  333. md5:SunOS:4.1:100125-05:sun3x:/usr/etc/in.telnetd:3af506b9b02b6a299f5e081c3abfce1f
  334. md5:SunOS:4.1:100125-05:sun4:/usr/etc/in.telnetd:5448303462518cca8390a84b5f312abe
  335. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/in.telnetd:333ffc49f21e675f3099772661549b7d
  336. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/in.telnetd:7706ba7270a28f3470ccbe965f8fc7a1
  337. md5:SunOS:4.1.1:100125-05:sun3:/usr/etc/in.telnetd:c4dca8a653f60feaed63a25786aee2ed
  338. md5:SunOS:4.1.1:100125-05:sun3x:/usr/etc/in.telnetd:6c409bd315711aae29b8285ffc4bb90c
  339. md5:SunOS:4.1.1:100125-05:sun4:/usr/etc/in.telnetd:29f24e09ffebc36fb14f9fee4bf2d6fc
  340. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/in.telnetd:503be2c540d03281fdada476d5b0b247
  341. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/in.telnetd:333ffc49f21e675f3099772661549b7d
  342. md5:SunOS:4.1.1:Original Dist:sun4c:/usr/etc/in.telnetd:503be2c540d03281fdada476d5b0b247
  343. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/in.telnetd:913095f91bbf06e98635f964951e0e2d
  344. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/in.telnetd:503be2c540d03281fdada476d5b0b247
  345. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/in.telnetd:503be2c540d03281fdada476d5b0b247
  346. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/in.telnetd:b94ac90e4fe63f1c7a0199a27a7c4d80
  347. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/in.telnetd:503be2c540d03281fdada476d5b0b247
  348. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/in.telnetd:b94ac90e4fe63f1c7a0199a27a7c4d80
  349. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/in.telnetd:503be2c540d03281fdada476d5b0b247
  350. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/in.telnetd:831c59628b1197c612f19289a786eaeb
  351.  
  352. #/usr/etc/ifconfig
  353. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/ifconfig:c9fe06259a49a58edfc6f1fe68665990
  354. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/ifconfig:0da82be29c7173759316f51417fb420a
  355. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/ifconfig:c9fe06259a49a58edfc6f1fe68665990
  356. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/ifconfig:47d6e495207cc2b7037bd94a12cf565b
  357. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/ifconfig:c9fe06259a49a58edfc6f1fe68665990
  358. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/ifconfig:c9fe06259a49a58edfc6f1fe68665990
  359. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/ifconfig:de44e217c94fa4f4c6fdfbcae419cb8b
  360. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/ifconfig:c9fe06259a49a58edfc6f1fe68665990
  361. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/ifconfig:de44e217c94fa4f4c6fdfbcae419cb8b
  362. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/ifconfig:c9fe06259a49a58edfc6f1fe68665990
  363. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/ifconfig:22d9340368aec82ebdd63518613bc6ab
  364.  
  365. #/usr/lib/libc.a
  366. md5:SunOS:4.1.1:100267-09:sun3:/usr/5lib/libc.a:af8a721ca332754cdff2a1f1b74b8e8f
  367. md5:SunOS:4.1.1:100267-09:sun3:/usr/5lib/libc_p.a:1b930986afb11494b4e1e0fd4f9540b0
  368. md5:SunOS:4.1.1:100267-09:sun3:/usr/lib/libc.a:6b0ff2e11f3042d453ee502787ac29d7
  369. md5:SunOS:4.1.1:100267-09:sun3:/usr/lib/libc_p.a:ad9bd3c42db06fb0c45674eaafc5c4f8
  370. md5:SunOS:4.1.1:100267-09:sun4:/usr/5lib/libc.a:8c396b0695abb59fea66bc6615d9f101
  371. md5:SunOS:4.1.1:100267-09:sun4:/usr/5lib/libc_p.a:d98a993e3f6c308f3679690dd4f5e8d7
  372. md5:SunOS:4.1.1:100267-09:sun4:/usr/lib/libc.a:da7c2504a1cb5073d7e9bb7de580db32
  373. md5:SunOS:4.1.1:100267-09:sun4:/usr/lib/libc_p.a:9879d72df71d9956f62f058ddf70d0f8
  374. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/5lib/libc.a:4daced1b11335f613bf7a5792bfeff77
  375. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/5lib/libc_p.a:bd2037193776678e48324f523064b95b
  376. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/lib/libc.a:ae4bcb481e7267c1def082ed6acf4bd9
  377. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/lib/libc_p.a:696c03eb30c696b712f38907d3c2ee45
  378. md5:SunOS:4.1.1:Original Dist:sun4:/usr/5lib/libc.a:68686e4ed99b5dcf98ac4e3350ff6645
  379. md5:SunOS:4.1.1:Original Dist:sun4:/usr/lib/libc.a:cbba2b6e294f0087a0b9116290946d46
  380. md5:SunOS:4.1.1:Original Dist:sun3:/usr/5lib/libc.a:89b9040707c28810554dfaca6993e7d0
  381. md5:SunOS:4.1.1:Original Dist:sun3:/usr/lib/libc.a:15d385b850be70a30077e66b67dc5f09
  382. md5:SunOS:4.1.2:Original Dist:sun4:/usr/5lib/libc.a:e7ab3d2658611114833f25a4279db158
  383. md5:SunOS:4.1.2:Original Dist:sun4:/usr/lib/libc.a:f95fabcdbaaf34ac3da6174e635724e3
  384. md5:SunOS:4.1.3:Original Dist:sun4:/usr/5lib/libc.a:c6669804e4def2e1e49ad5628c52ee75
  385. md5:SunOS:4.1.3:Original Dist:sun4:/usr/lib/libc.a:ab06bfd723df7802d25291576736ce23
  386. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/5lib/libc.a:5ef2ccf958dc6734c3e412127884c559
  387. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/lib/libc.a:6f5d5c343b262c03a3f976d2830f4d06
  388. md5:SunOS:4.1.1:Original Dist:sun4:/usr/5lib/libc_p.a:21766ed7fdb431bb0435e48ea0764d42
  389. md5:SunOS:4.1.1:Original Dist:sun4:/usr/lib/libc_p.a:709d9a093b637e64234a03f1c48583e7
  390. md5:SunOS:4.1.1:Original Dist:sun3:/usr/5lib/libc_p.a:3e3fcdfeb1636c708f1a2fec14c13b9f
  391. md5:SunOS:4.1.1:Original Dist:sun3:/usr/lib/libc_p.a:18f6043209f019ec58e50ab4f4771d40
  392. md5:SunOS:4.1.2:Original Dist:sun4:/usr/5lib/libc_p.a:c0b13f61038a198e6be3c09e137dee0e
  393. md5:SunOS:4.1.2:Original Dist:sun4:/usr/lib/libc_p.a:a40b2af6cde4734289f06d8325c8cf2e
  394. md5:SunOS:4.1.3:Original Dist:sun4:/usr/5lib/libc_p.a:bb06ddd972dd5549a3d6cc38a9537893
  395. md5:SunOS:4.1.3:Original Dist:sun4:/usr/lib/libc_p.a:72c8bee2000b2562225077784ea61bac
  396. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/5lib/libc_p.a:8ccee0cc285a298c713b8bace38da815
  397. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/lib/libc_p.a:157a7dc7a8fc77f1a5a06a85d3bab16c
  398.  
  399. #/usr/kvm/pstat
  400. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/kvm/pstat:a131828d02092ab56e98ac8d63b1125d
  401. md5:SunOS:4.1.1:Original Dist:sun4:/usr/kvm/pstat:6de82bb539b54c2bd0be79dfc7712507
  402. md5:SunOS:4.1.1:Original Dist:sun4c:/usr/kvm/pstat:5e6058397f8e86df7456e36ad54f9b1e
  403. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/kvm/pstat:a1cfc4f23be423aede09e23bcbf6268a
  404. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/kvm/pstat:c2abc2313450cfd72ccd93448fef967b
  405. md5:SunOS:4.1.3:Original Dist:sun4:/usr/kvm/pstat:0076043c06cd24ae927128f02da9b935
  406. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/kvm/pstat:225d4542b70f15af39c96a4d3b48a631
  407. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/kvm/pstat:e3a519a93a8b6a02fd6c64a6b3db476d
  408. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/kvm/pstat:2a1cbf06988208179adf132349c3a403
  409. md5:SunOS:4.1.3_u1:Original Dist:sun4m:/usr/kvm/pstat:2f3af3afbfa5942575bbcb02b13ebac1
  410. md5:SunOS:4.1.3_u1:Original Dist:sun4c:/usr/kvm/pstat:d15776947e0d60fc7d5ae755f65e779b
  411.  
  412. #/usr/etc/in.ftpd
  413. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/in.ftpd:c95b40609c510cfcc65504972d1f3ae1
  414. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/in.ftpd:7ff869b0d0eeec61b08a81a085759681
  415. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/in.ftpd:7a17e92251d08c56d001a1f5654fcb35
  416. md5:SunOS:4.1.1:Original Dist:sun4c:/usr/etc/in.ftpd:c95b40609c510cfcc65504972d1f3ae1
  417. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/in.ftpd:8b1bfb5ba15d2898fffa373b1005e7ff
  418. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/in.ftpd:c95b40609c510cfcc65504972d1f3ae1
  419. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/in.ftpd:c95b40609c510cfcc65504972d1f3ae1
  420. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/in.ftpd:79a29ae3f1deb02efb743d9cd39f6f2f
  421. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/in.ftpd:c95b40609c510cfcc65504972d1f3ae1
  422. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/in.ftpd:79a29ae3f1deb02efb743d9cd39f6f2f
  423. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/in.ftpd:c95b40609c510cfcc65504972d1f3ae1
  424. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/in.ftpd:3e8f757252dd562ad80ae79e78d06fb7
  425.  
  426. #/usr/etc/in.rexecd
  427. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/in.rexecd:fd51458be842565c712f8d57cf5a6f28
  428. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/in.rexecd:4d9811877f622348dd454172fbb40a66
  429. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/in.rexecd:fd51458be842565c712f8d57cf5a6f28
  430. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/in.rexecd:6d9f39193ac39bc9680a4fb44fdfb50f
  431. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/in.rexecd:fd51458be842565c712f8d57cf5a6f28
  432. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/in.rexecd:fd51458be842565c712f8d57cf5a6f28
  433. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/in.rexecd:37316f4d63faa445ea448ec7c670f94f
  434. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/in.rexecd:fd51458be842565c712f8d57cf5a6f28
  435. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/in.rexecd:37316f4d63faa445ea448ec7c670f94f
  436. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/in.rexecd:fd51458be842565c712f8d57cf5a6f28
  437. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/in.rexecd:be66f45bb60f31aaa23377f23c66caca
  438.  
  439. #/usr/etc/in.rshd
  440. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/in.rshd:3d81a586add92ef033088d928c7ae7dc
  441. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/in.rshd:17f91e72bbf70d5cf3e75a3068d5c461
  442. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/in.rshd:a4eb9385df064b9a751ede87fd0804a2
  443. md5:SunOS:4.1.1:Original Dist:sun4c:/usr/etc/in.rshd:3d81a586add92ef033088d928c7ae7dc
  444. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/in.rshd:e45ab7d2dc4c3e7346292f85259c0432
  445. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/in.rshd:3d81a586add92ef033088d928c7ae7dc
  446. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/in.rshd:3d81a586add92ef033088d928c7ae7dc
  447. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/in.rshd:3d81a586add92ef033088d928c7ae7dc
  448. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/in.rshd:686c2bb25752e6bec5090e2732a46207
  449. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/in.rshd:686c2bb25752e6bec5090e2732a46207
  450. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/in.rshd:3d81a586add92ef033088d928c7ae7dc
  451. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/in.rshd:e5ca89c51427d917690fbcc1395507b4
  452.  
  453. #/usr/etc/in.tftpd
  454. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/in.tftpd:73ea84bdcff54ace0e601f5c3d2f90b0
  455. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/in.tftpd:ccec1773e5945a0b8397a74ec07112df
  456. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/in.tftpd:e6b495aec9b8a24f5e58ebc19fd1eec7
  457. md5:SunOS:4.1.1:Original Dist:sun4c:/usr/etc/in.tftpd:73ea84bdcff54ace0e601f5c3d2f90b0
  458. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/in.tftpd:4b924bda12c61674771c84caa0fa1e80
  459. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/in.tftpd:73ea84bdcff54ace0e601f5c3d2f90b0
  460. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/in.tftpd:73ea84bdcff54ace0e601f5c3d2f90b0
  461. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/in.tftpd:bfaf4492223126181ca9333220cbcf02
  462. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/in.tftpd:73ea84bdcff54ace0e601f5c3d2f90b0
  463. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/in.tftpd:bfaf4492223126181ca9333220cbcf02
  464. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/in.tftpd:73ea84bdcff54ace0e601f5c3d2f90b0
  465. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/in.tftpd:0ff3883f2b99f06d4f897347c58a79d9
  466.  
  467. #/usr/etc/inetd
  468. md5:SunOS:4.1.1:Original Dist:sun3x:/usr/etc/inetd:c3a0f2bb985babcd43a438ce53de54ae
  469. md5:SunOS:4.1.1:Original Dist:sun3:/usr/etc/inetd:0764c23ac95b4ea5a8683c8761337485
  470. md5:SunOS:4.1.1:Original Dist:sun4:/usr/etc/inetd:c3a0f2bb985babcd43a438ce53de54ae
  471. md5:SunOS:4.1.2:Original Dist:sun4:/usr/etc/inetd:e6054cbb343d21791c6457e78822d5f1
  472. md5:SunOS:4.1.2:Original Dist:sun4c:/usr/etc/inetd:c3a0f2bb985babcd43a438ce53de54ae
  473. md5:SunOS:4.1.2:Original Dist:sun4m:/usr/etc/inetd:c3a0f2bb985babcd43a438ce53de54ae
  474. md5:SunOS:4.1.3:Original Dist:sun4:/usr/etc/inetd:c3a923cbf5023b48ffdef3d043190a81
  475. md5:SunOS:4.1.3:Original Dist:sun4c:/usr/etc/inetd:c3a0f2bb985babcd43a438ce53de54ae
  476. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/etc/inetd:c3a923cbf5023b48ffdef3d043190a81
  477. md5:SunOS:4.1.3c:Original Dist:sun4m:/usr/etc/inetd:c3a0f2bb985babcd43a438ce53de54ae
  478. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/etc/inetd:722d3e46a2f8e52ffadd7450fbbd1438
  479.  
  480. #/usr/bin/newgrp
  481. md5:SunOS:4.1.1:Original Dist:sun3:/usr/bin/newgrp:e3d6e9d43345372f5aa0d5c96570b155
  482. md5:SunOS:4.1.1:Original Dist:sun4:/usr/bin/newgrp:d3749b2a6e99f14feede9430d1feee46
  483. md5:SunOS:4.1.2:Original Dist:sun4:/usr/bin/newgrp:875e7cf58cec91c6fb44ec6e5d89ef0f
  484. md5:SunOS:4.1.3:Original Dist:sun4:/usr/bin/newgrp:7c0aad251ccb8de9c050d53c823f334f
  485. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/bin/newgrp:7c0aad251ccb8de9c050d53c823f334f
  486. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/bin/newgrp:04edbbb4d06bf056c4959d3b85560fe6
  487.  
  488. #/usr/bin/passwd
  489. md5:SunOS:4.1.1:Original Dist:sun3:/usr/bin/passwd:11499df2dfc4f75c5466e09b64fe1097
  490. md5:SunOS:4.1.1:Original Dist:sun4:/usr/bin/passwd:d4e3ee198d6e3934bc2356ce495e77c7
  491. md5:SunOS:4.1.2:Original Dist:sun4:/usr/bin/passwd:2dcec1f0e106354a85058f4c2c66e2bd
  492. md5:SunOS:4.1.3:Original Dist:sun4:/usr/bin/passwd:6fdb875b621de4dbffab6f6782ec2ba3
  493. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/bin/passwd:6fdb875b621de4dbffab6f6782ec2ba3
  494. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/bin/passwd:97f3231b48d6e29b829357b72043aadc
  495.  
  496. #/usr/bin/su
  497. md5:SunOS:4.1.1:Original Dist:sun3:/usr/bin/su:829e4e39edc3a8d299f5525c866dc324
  498. md5:SunOS:4.1.1:Original Dist:sun4:/usr/bin/su:94b0bc99dcb9dcdbc3e8ece7e127a906
  499. md5:SunOS:4.1.2:Original Dist:sun4:/usr/bin/su:23fe0a40ec522c5add89cd6ab2731170
  500. md5:SunOS:4.1.3:Original Dist:sun4:/usr/bin/su:0d2f5665c9befdf2f7aeafa4d77266bb
  501. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/bin/su:0d2f5665c9befdf2f7aeafa4d77266bb
  502. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/bin/su:c49812d55df4712194f832f099d40aa7
  503.  
  504. #Shared Libraries
  505. md5:SunOS:4.1.1:Original Dist:sun4:/usr/5lib/libc.so.2.6:1d66abbac68785d6f8fa8ff53200845e
  506. md5:SunOS:4.1.1:Original Dist:sun4:/usr/lib/libc.so.1.6:d4dc2514248834d95ee6b5c77a7eda86
  507. md5:SunOS:4.1.1:Original Dist:sun3:/usr/5lib/libc.so.1.15:26c5c2e8b147f3f6d96bdff369853cad
  508. md5:SunOS:4.1.1:Original Dist:sun3:/usr/lib/libc.so.0.15:2262f263e711bff2bd4d9d6f87ea5edd
  509. md5:SunOS:4.1.2:Original Dist:sun4:/usr/5lib/libc.so.2.7:b1e624d4293907511e4ee9e8e77e74dd
  510. md5:SunOS:4.1.2:Original Dist:sun4:/usr/lib/libc.so.1.7:76c095597088ee5bc82a2c1ce0a419ce
  511. md5:SunOS:4.1.3:Original Dist:sun4:/usr/5lib/libc.so.2.8:d3c8366dca51488864cc8d80c106f190
  512. md5:SunOS:4.1.3:Original Dist:sun4:/usr/lib/libc.so.1.8:aabfb3300f2d872cdc6d9fb10514e246
  513. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/5lib/libc.so.2.8:af3584319d80525c2ca8e8ea8920d131
  514. md5:SunOS:4.1.3c:Original Dist:sun4:/usr/lib/libc.so.1.8:91a8dde1c328e474ec08557c211a4dcb
  515. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/5lib/libc.so.2.9:722852b7e5df15de70e3c1a1f96c04d9
  516. md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/lib/libc.so.1.9:2d5bc65422472f7d4119712ccf795bf3
  517.  
  518. - ---------------------------------------------------------------------------
  519. The CERT Coordination Center gratefully acknowledges the help of CIAC
  520. and, in particular, Steve Weeber of CIAC for providing us with an initial
  521. version of the "md5check" script and Tony Bartoletti for an initial
  522. checksum database.  We also wish to thank SUN Microsystems for supplying
  523. checksum information.
  524. - ---------------------------------------------------------------------------
  525.  
  526. If you believe that your system has been compromised, contact the CERT
  527. Coordination Center or your representative in Forum of Incident
  528. Response and Security Teams (FIRST).
  529.  
  530. Internet E-mail: cert@cert.org
  531. Telephone: 412-268-7090 (24-hour hotline)
  532.            CERT personnel answer 8:30 a.m.-5:00 p.m. EST(GMT-5)/EDT(GMT-4),
  533.            and are on call for emergencies during other hours.
  534.  
  535. CERT Coordination Center
  536. Software Engineering Institute
  537. Carnegie Mellon University
  538. Pittsburgh, PA 15213-3890
  539.  
  540. Past advisories, information about FIRST representatives, and other
  541. information related to computer security are available for anonymous
  542. FTP from info.cert.org.
  543.  
  544. Copyright 1994, 1995, 1996 Carnegie Mellon University
  545. This material may be reproduced and distributed without permission provided
  546. it is used for noncommercial purposes and the copyright statement is
  547. included.
  548.  
  549. CERT is a service mark of Carnegie Mellon University.
  550.  
  551. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  552. Revision history
  553.  
  554. Aug. 30, 1996  Information previously in the README was inserted
  555.                    into the advisory. Updated URL format.
  556. Sep. 18, 1995  Intro. and Appendix B - Added note about checking with
  557.             vendors for current checksum values.
  558. (as received)  Appendix B, Hewlett-Packard & Solbourne - added checksums
  559.                        Sun - corrected one line of Sun entry:
  560.                    "md5:SunOS:4.1.3_u1:Original Dist:sun4:/usr/bin/login"
  561.                    is now "md5:SunOS:4.1.3_u1:Original
  562.                    Dist:sun4:bin/login" and has a new checksum
  563. Sept. 18, 1995 - Intro. - Updated the URL for Tripwire.
  564.  
  565.  
  566.  
  567.  
  568.  
  569.  
  570. -----BEGIN PGP SIGNATURE-----
  571. Version: 2.6.2
  572.  
  573. iQCVAwUBMiSTA3VP+x0t4w7BAQFUrAQAiihlFyeGUxOd5xjSVd77JjCoEB+HSkj1
  574. SEwokeqIv3lrvcTRN5Q1bJ2VaJJWEyD4kLkMuVUElK6j56yMnUK7CquaYATaLehH
  575. he96t/pY0rUQJ1VnuPQZbBmNMeNvPuBslk+sTXCJnU1EtXM0fqHj+RtcmlJ2smWo
  576. Hxcx5+qT7zo=
  577. =1bwk
  578. -----END PGP SIGNATURE-----
  579.  
  580.