Lab Objective

Google Cybersecurity Certificate activity: “Create hash values.” Use sha256sum and cmp in Linux to generate and compare hash values for two files that look byte-for-byte identical when read with cat, and confirm whether they actually are.


Lab Environment

  • Course: Google Cybersecurity Certificate
  • Starting directory: /home/analyst (user analyst, already logged in)
  • Files present: file1.txt, file2.txt — both reportedly containing “the same data”

Scenario

Investigate whether two files are truly identical or subtly different, using hash comparison instead of trusting a visual read of their contents.


Step 1 - Compare the Files by Eye

ls
cat file1.txt
cat file2.txt

Real output from my run:

file1.txt  file2.txt
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Both files display the EICAR standard antivirus test string (a harmless, industry-standard string used to test that antivirus software correctly flags a “malicious” file without using real malware) — and they look completely identical by eye.


Step 2 - Generate Hash Values for Each File

sha256sum file1.txt
sha256sum file2.txt

Real output:

131f95c51cc819465fa1797f6ccacf9d494aaaff46fa3eac73ae63ffbdfd8267  file1.txt
2558ba9a4cad1e69804ce03aa2a029526179a91a5e38cb723320e83af9ca017b  file2.txt

The two hash values are completely different, despite the files appearing identical under cat. This is the entire point of the lab: visual comparison is not proof of file integrity or equality — something differs between these files (whitespace, encoding, a trailing character, or similar) that a plain read doesn’t surface, but the hash catches immediately.


Step 3 - Write Hashes to Files and Compare

sha256sum file1.txt >> file1hash
sha256sum file2.txt >> file2hash
ls
cat file1hash
cat file2hash

Confirms the two hash files hold the differing values captured above.

cmp file1hash file2hash

Real output:

file1hash file2hash differ: char 1, line 1

cmp compares byte by byte and reports the exact location of the first difference — here, immediately, at the very first character, since the two hashes share no common prefix at all.


Command Reference

Command Purpose
sha256sum <file> Generate a SHA-256 hash of a file’s contents
sha256sum <file> >> <output> Append the generated hash to a new file
cat <file> Display file contents (not proof of equality)
cmp <file1> <file2> Byte-by-byte comparison, reporting the first difference found

Security Takeaways

  1. Visual inspection is not integrity verification. Two files that look identical under cat produced completely different SHA-256 hashes — appearance is not evidence.
  2. A single-bit difference cascades into a completely different hash. This is intentional: hash functions are designed so that no partial similarity in output implies partial similarity in input, which is exactly why a hash mismatch is a reliable tamper signal.
  3. cmp pinpoints exactly where two files diverge. For debugging why two things differ (as opposed to just confirming that they differ), byte-level comparison tools are the next step after a hash mismatch.
  4. SHA-256 is the appropriate modern choice for this kind of check. Unlike MD5, it isn’t practically vulnerable to collision attacks, making a hash mismatch here trustworthy evidence rather than a coincidence worth doubting.
  5. The EICAR test file is a reminder that “test” data still needs correct handling. Even a harmless, industry-standard test string benefits from the same integrity-checking discipline as real sensitive data — the habit matters more than the specific file.

Where This Applies Beyond the Lab

This is the exact workflow behind verifying a downloaded file against a publisher’s published hash, confirming a forensic disk image hasn’t been altered since acquisition, or catching a malicious file that’s been renamed or slightly modified to evade a naive “looks the same” check. cat-and-eyeball is how a casual user checks a file; sha256sum-and-compare is how a security analyst actually proves it.