This isn't really the forum for it, but I'm getting no reply on the CSF forums. Someone here might know what to do
I'm running Directadmin on a CentOS VPS with csf installed. Every now and then I'll receive an email where csf has detected a modified system file. Up until now, that only occured when one of my packages updated itself, which makes sense to me.
Today*, I received a mail while no update was run that I'm aware of, so that has me a bit concerned. Here's the files in todays email that failed the integrity check:
/usr/sbin/exim_dbmbuild: FAILED
/usr/sbin/exim_dumpdb: FAILED
/usr/sbin/exim_fixdb: FAILED
/usr/sbin/exim_lock: FAILED
/usr/sbin/exim_tidydb: FAILED
I have made a few changes to my server a few days ago, including activating sa-learn and updating exim itself, but I dont know if any of those changes could be related to this. I'm hoping they are, but if someone could point me in the right direction on how to make sure these listed files weren't tampered with, I'd be most grateful.
*(I copied my post from the CSF forum, its actually been 4 days by now)
I'm running Directadmin on a CentOS VPS with csf installed. Every now and then I'll receive an email where csf has detected a modified system file. Up until now, that only occured when one of my packages updated itself, which makes sense to me.
Today*, I received a mail while no update was run that I'm aware of, so that has me a bit concerned. Here's the files in todays email that failed the integrity check:
/usr/sbin/exim_dbmbuild: FAILED
/usr/sbin/exim_dumpdb: FAILED
/usr/sbin/exim_fixdb: FAILED
/usr/sbin/exim_lock: FAILED
/usr/sbin/exim_tidydb: FAILED
I have made a few changes to my server a few days ago, including activating sa-learn and updating exim itself, but I dont know if any of those changes could be related to this. I'm hoping they are, but if someone could point me in the right direction on how to make sure these listed files weren't tampered with, I'd be most grateful.
*(I copied my post from the CSF forum, its actually been 4 days by now)