Module 10 · Putting it all together
Checksums: md5sum and sha256sum
Fingerprint files with md5sum and sha256sum, save the fingerprints, and verify later with -c that nothing was corrupted or changed.
What you will learn
- Explain what a hash is and why any change produces a different one.
- Create checksum lists with `md5sum` and `sha256sum`.
- Verify files with `-c` and find the ones that fail.
A checksum (or hash) is a short fingerprint calculated from every byte of a file. The same content always gives the same fingerprint, and changing even one byte gives a completely different one. That makes checksums ideal to answer two questions: did this download arrive intact? and has this file changed since I last looked? You compare two short strings instead of two large files.
~% cd lab/l98
l98% echo hello > f1; echo world > f2
l98% md5sum f1 f2
b1946ac92492d2347c6235b4d2611184 f1
591785b794601e212b260e25925636fd f2
l98% sha256sum f1
5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03 f1
l98% echo "hello" | sha256sum
5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03 -
Each line is the hash, two spaces and the file name (- when it came from standard input). Notice that echo "hello" | sha256sum matches the file: both contain hello plus a newline. printf hello without the newline would give a different hash, a classic source of confusion when you compare a hash of a typed string.
Which algorithm?
| Command | Length | Use it for |
|---|---|---|
md5sum | 32 hex chars | Detecting accidental corruption; not safe against attackers |
sha1sum | 40 | Legacy; also broken for security |
sha256sum | 64 | The usual choice today: downloads, releases, backups |
sha512sum | 128 | Same purpose, longer fingerprint |
MD5 and SHA-1 still catch disk errors and truncated downloads perfectly well, but people have learned to build two different files with the same MD5 on purpose. When a website publishes a checksum so you can trust a file, it should be SHA-256 or longer.
Save now, verify later: -c
l98% sha256sum f1 f2 > SHA256SUMS
l98% sha256sum -c SHA256SUMS
f1: OK
f2: OK
l98% echo changed > f2
l98% sha256sum -c SHA256SUMS
f1: OK
f2: FAILED
sha256sum: WARNING: 1 of 2 computed checksums did NOT match
l98% echo $?
1
Redirect the output of sha256sum to a file and you have a manifest. sha256sum -c MANIFEST recalculates each hash and prints OK or FAILED per file; the exit status is 0 only when everything matched, so scripts can rely on it, and -s silences the output entirely. The names are stored exactly as you typed them: a manifest made with relative names must be checked from the same directory, one made with absolute paths works from anywhere. This is also how software projects publish a SHA256SUMS file next to their downloads: you fetch both and run sha256sum -c.
A practical routine: after making a backup archive, save its checksum next to it (sha256sum backup.tar > backup.tar.sha256). Before you restore, possibly months later and on another machine, run sha256sum -c backup.tar.sha256. If it says OK, the archive is byte for byte what you saved; if it says FAILED, you know not to trust it before extracting anything.
Commands in this lesson
| Command | What it does |
|---|---|
md5sum file | MD5 fingerprint (32 hex chars). |
sha256sum file | SHA-256 fingerprint (64 hex chars). |
sha256sum a b > SHA256SUMS | Save a manifest. |
sha256sum -c SHA256SUMS | Verify; exit 0 only if all match. |
sha256sum -c -s SHA256SUMS | Verify silently (status only). |
md5sum f | cut -d' ' -f1 | Just the hash. |
Quiz
You change one character in a 1 GB file. Its SHA-256 sum…
- changes only slightly
- becomes completely different
- stays the same, since the size did not change
What does `sha256sum -c SHA256SUMS` do?
- Creates the manifest
- Recalculates each listed file's hash and reports OK or FAILED
- Compresses the files
Why is MD5 not enough to prove a download was not tampered with?
- Attackers can craft different files with the same MD5.
- MD5 only reads the first kilobyte.
- MD5 changes every day.
`echo hello | md5sum` and `printf hello | md5sum` give different results. Why?
- echo adds a newline, so the bytes differ.
- md5sum is random.
- printf uses another algorithm.
Practice
Create `/root/lab/l98/dist/SHA256SUMS` with the SHA-256 sums of `app.bin`, `lib.bin` and `readme.txt` in that directory, so that `sha256sum -c SHA256SUMS` run inside `dist` passes.
In `/root/lab/l98/dist` one of the files no longer matches the published `SHA256SUMS`. Verify them and save the `FAILED` line(s) into `/root/lab/l98/bad.txt`.
Write only the MD5 hash (the 32 characters, no file name) of `/root/lab/l98/dist/readme.txt` into `/root/lab/l98/md5.txt`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.