Zabbix going crazy with modified /etc/passwd

Posted August 4, 2020 2.4k views
DigitalOceanDebian 9

This morning i was awakened by multiple alarm emails sent by our zabbix agent monitoring system, telling us that /etc/passwd was being modified. The agent sent us an email for every one of our droplets (debian 9 stretch).

After the initial scare, i checked the apt logs and it seems that do-agent service was upgraded silently:

apt-get -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold -qq install -y --only-upgrade do-agent

No other alarms were going off, and everything seems to be working nominal.

I think the changes to /etc/passwd were made to the do-agent user during the upgrade process, but i would like to know from you guys if this is actually the case.

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

Submit an Answer
1 answer

Hi there @andreagolin,

Yes, indeed this seems to be the case. I checked this on one of my Droplets and I noticed the same thing.

You could check it as well with the following command:

  • sudo sdiff /etc/passwd /etc/passwd-

The /etc/passwd- file is basically a ‘backup’ of the /etc/passwd file, so with the sdiff command you will be able to see what exactly changed last night.