Read

Module 10 · Putting it all together

Checksums: md5sum and sha256sum

Fingerprint files with md5sum and sha256sum, save the fingerprints, and verify later with -c that nothing was corrupted or changed.

What you will learn

  • Explain what a hash is and why any change produces a different one.
  • Create checksum lists with `md5sum` and `sha256sum`.
  • Verify files with `-c` and find the ones that fail.

A checksum (or hash) is a short fingerprint calculated from every byte of a file. The same content always gives the same fingerprint, and changing even one byte gives a completely different one. That makes checksums ideal to answer two questions: did this download arrive intact? and has this file changed since I last looked? You compare two short strings instead of two large files.

~% cd lab/l98
l98% echo hello > f1; echo world > f2
l98% md5sum f1 f2
b1946ac92492d2347c6235b4d2611184  f1
591785b794601e212b260e25925636fd  f2
l98% sha256sum f1
5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03  f1
l98% echo "hello" | sha256sum
5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03  -

Each line is the hash, two spaces and the file name (- when it came from standard input). Notice that echo "hello" | sha256sum matches the file: both contain hello plus a newline. printf hello without the newline would give a different hash, a classic source of confusion when you compare a hash of a typed string.

Which algorithm?

CommandLengthUse it for
md5sum32 hex charsDetecting accidental corruption; not safe against attackers
sha1sum40Legacy; also broken for security
sha256sum64The usual choice today: downloads, releases, backups
sha512sum128Same purpose, longer fingerprint

MD5 and SHA-1 still catch disk errors and truncated downloads perfectly well, but people have learned to build two different files with the same MD5 on purpose. When a website publishes a checksum so you can trust a file, it should be SHA-256 or longer.

Save now, verify later: -c

l98% sha256sum f1 f2 > SHA256SUMS
l98% sha256sum -c SHA256SUMS
f1: OK
f2: OK
l98% echo changed > f2
l98% sha256sum -c SHA256SUMS
f1: OK
f2: FAILED
sha256sum: WARNING: 1 of 2 computed checksums did NOT match
l98% echo $?
1

Redirect the output of sha256sum to a file and you have a manifest. sha256sum -c MANIFEST recalculates each hash and prints OK or FAILED per file; the exit status is 0 only when everything matched, so scripts can rely on it, and -s silences the output entirely. The names are stored exactly as you typed them: a manifest made with relative names must be checked from the same directory, one made with absolute paths works from anywhere. This is also how software projects publish a SHA256SUMS file next to their downloads: you fetch both and run sha256sum -c.

A practical routine: after making a backup archive, save its checksum next to it (sha256sum backup.tar > backup.tar.sha256). Before you restore, possibly months later and on another machine, run sha256sum -c backup.tar.sha256. If it says OK, the archive is byte for byte what you saved; if it says FAILED, you know not to trust it before extracting anything.

Commands in this lesson

CommandWhat it does
md5sum fileMD5 fingerprint (32 hex chars).
sha256sum fileSHA-256 fingerprint (64 hex chars).
sha256sum a b > SHA256SUMSSave a manifest.
sha256sum -c SHA256SUMSVerify; exit 0 only if all match.
sha256sum -c -s SHA256SUMSVerify silently (status only).
md5sum f | cut -d' ' -f1Just the hash.

Quiz

  1. You change one character in a 1 GB file. Its SHA-256 sum…

    • changes only slightly
    • becomes completely different
    • stays the same, since the size did not change
  2. What does `sha256sum -c SHA256SUMS` do?

    • Creates the manifest
    • Recalculates each listed file's hash and reports OK or FAILED
    • Compresses the files
  3. Why is MD5 not enough to prove a download was not tampered with?

    • Attackers can craft different files with the same MD5.
    • MD5 only reads the first kilobyte.
    • MD5 changes every day.
  4. `echo hello | md5sum` and `printf hello | md5sum` give different results. Why?

    • echo adds a newline, so the bytes differ.
    • md5sum is random.
    • printf uses another algorithm.

Practice

  1. Create `/root/lab/l98/dist/SHA256SUMS` with the SHA-256 sums of `app.bin`, `lib.bin` and `readme.txt` in that directory, so that `sha256sum -c SHA256SUMS` run inside `dist` passes.

  2. In `/root/lab/l98/dist` one of the files no longer matches the published `SHA256SUMS`. Verify them and save the `FAILED` line(s) into `/root/lab/l98/bad.txt`.

  3. Write only the MD5 hash (the 32 characters, no file name) of `/root/lab/l98/dist/readme.txt` into `/root/lab/l98/md5.txt`.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.