↑ ↓ select, Enter open, Esc close

Detect modified files of installed packages

root@server
dpkg --verify

Compares the MD5 checksums of all files of installed packages with the values from the package database. Only deviations are printed: a 5 in the third position means changed content, a c marks configuration files. Changed configuration files are normal, changed programs under /usr/bin or /usr/sbin are not.

Note: The checksums are stored on the same system and could also have been modified by an attacker with root privileges. The run takes a few minutes.

Also searched as

  • verify package files debian
  • check system binaries for tampering
  • dpkg verify rootkit check

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.