Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




basics logo Security Basics mailing list archives

bash_history
From: Alejandro Flores <alejandro.flores () triforsec com br>
Date: Fri, 08 Apr 2005 18:50:51 -0300

Hey there,

I was googling about a way to protect the bash_history file from user
removal or UNSET the HISTFILE variable and all I found was papers about
disabling this file for security reasons. Weird! Why it's recommended to
disable this file, when it contains the history of typed commands from
all users? Ok, ok, you can tell me that users may have typed passwords
in a bash session to gain access to a mysql database for example. 
But, if you need to do some forensics in your compromised server, this
file is the first place to know what the 'malicious dude' did to gain
root privileges, the server where he downloaded his craps, etc...
I started 'chown'ing the .bash_profile and .bashrc files to root, and
removed the 'wx' from group and others. The user has only read
permission.
But I can't prevent him from changing the HISTFILE variable. Like:
export HISTFILE=/dev/null
With this command, all my steps from now aren't recorded.

Ideas?

Regards,
Alejandro Flores


---------------------------------------------------------------------------
Earn your MS in Information Security ONLINE
Organizations worldwide are in need of highly qualified information security 
professionals.  Norwich University is fulfilling this demand with its MS in 
Information Security offered online.  Recognized by the NSA as an 
academically excellent program, NU offers you the opportunity to earn your 
degree without disrupting your home or work life.

http://www.msia.norwich.edu/secfocus_en
----------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]