🧪 Lab 25 – Proving Two Identical-Looking Files Are Not the Same File
Lab Objective
Google Cybersecurity Certificate activity: “Create hash values.” Use sha256sum and cmp in Linux to generate and compare hash values for two files that look byte-for-byte identical when read with cat, and confirm whether they actually are.
Lab Environment
- Course: Google Cybersecurity Certificate
- Starting directory:
/home/analyst(useranalyst, already logged in) - Files present:
file1.txt,file2.txt— both reportedly containing “the same data”
Scenario
Investigate whether two files are truly identical or subtly different, using hash comparison instead of trusting a visual read of their contents.
Step 1 - Compare the Files by Eye
ls
cat file1.txt
cat file2.txt
Real output from my run:
file1.txt file2.txt
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Both files display the EICAR standard antivirus test string (a harmless, industry-standard string used to test that antivirus software correctly flags a “malicious” file without using real malware) — and they look completely identical by eye.
Step 2 - Generate Hash Values for Each File
sha256sum file1.txt
sha256sum file2.txt
Real output:
131f95c51cc819465fa1797f6ccacf9d494aaaff46fa3eac73ae63ffbdfd8267 file1.txt
2558ba9a4cad1e69804ce03aa2a029526179a91a5e38cb723320e83af9ca017b file2.txt
The two hash values are completely different, despite the files appearing identical under cat. This is the entire point of the lab: visual comparison is not proof of file integrity or equality — something differs between these files (whitespace, encoding, a trailing character, or similar) that a plain read doesn’t surface, but the hash catches immediately.
Step 3 - Write Hashes to Files and Compare
sha256sum file1.txt >> file1hash
sha256sum file2.txt >> file2hash
ls
cat file1hash
cat file2hash
Confirms the two hash files hold the differing values captured above.
cmp file1hash file2hash
Real output:
file1hash file2hash differ: char 1, line 1
cmp compares byte by byte and reports the exact location of the first difference — here, immediately, at the very first character, since the two hashes share no common prefix at all.
Command Reference
| Command | Purpose |
|---|---|
sha256sum <file> |
Generate a SHA-256 hash of a file’s contents |
sha256sum <file> >> <output> |
Append the generated hash to a new file |
cat <file> |
Display file contents (not proof of equality) |
cmp <file1> <file2> |
Byte-by-byte comparison, reporting the first difference found |
Security Takeaways
- Visual inspection is not integrity verification. Two files that look identical under
catproduced completely different SHA-256 hashes — appearance is not evidence. - A single-bit difference cascades into a completely different hash. This is intentional: hash functions are designed so that no partial similarity in output implies partial similarity in input, which is exactly why a hash mismatch is a reliable tamper signal.
cmppinpoints exactly where two files diverge. For debugging why two things differ (as opposed to just confirming that they differ), byte-level comparison tools are the next step after a hash mismatch.- SHA-256 is the appropriate modern choice for this kind of check. Unlike MD5, it isn’t practically vulnerable to collision attacks, making a hash mismatch here trustworthy evidence rather than a coincidence worth doubting.
- The EICAR test file is a reminder that “test” data still needs correct handling. Even a harmless, industry-standard test string benefits from the same integrity-checking discipline as real sensitive data — the habit matters more than the specific file.
Where This Applies Beyond the Lab
This is the exact workflow behind verifying a downloaded file against a publisher’s published hash, confirming a forensic disk image hasn’t been altered since acquisition, or catching a malicious file that’s been renamed or slightly modified to evade a naive “looks the same” check. cat-and-eyeball is how a casual user checks a file; sha256sum-and-compare is how a security analyst actually proves it.
