CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A security analyst is performing a forensic investigation on a Linux server following a suspected rootkit infection. The analyst needs to identify any hidden or modified system binaries. Which of the following commands would be most effective for comparing the cryptographic hashes of installed packages against a known good baseline?
- Achkrootkit
- Brpm -Va
- Cdpkg -V
- Drkhunter
Show answer & explanationAnswer & explanation
Correct answer: B. rpm -Va
The 'rpm -Va' command (RPM package verification) is used on Red Hat-based Linux distributions to verify all installed packages. It checks file sizes, MD5 checksums, permissions, types, owners, and groups against the package's metadata, effectively comparing hashes against a known good baseline provided by the package manager. 'dpkg -V' serves a similar purpose for Debian-based systems.
Why the other options are wrong
- A. chkrootkit is a rootkit detection tool that looks for common rootkit signs, not primarily for package hash verification.
- C. dpkg -V is for Debian-based systems (like Ubuntu) to verify packages, not Red Hat.
- D. rkhunter (Rootkit Hunter) is a rootkit detection tool that performs various checks, including comparing file hashes, but 'rpm -Va' is specifically for package integrity against a baseline.
Linux Package Integrity Check (RPM)
A method to verify the integrity of installed software packages on Red Hat-based Linux systems by comparing their current state (including cryptographic hashes) against the original package metadata.
- Uses the 'rpm -Va' command.
- Checks file sizes, permissions, checksums, etc.
- Helps detect unauthorized modification of system binaries.
Memory trick: Packages, Rootkits, Logs