Research Menu

.
Skip Search Box

SELinux Mailing List

shell history task

From: Hacko <toltec_at_karai.net>
Date: Fri, 8 Feb 2002 19:32:18 +0200 (EET)


Hi all,

let's take for example bash,

shell user have an .bash_history,
the first thing to do for unauthorized user is:

unset HISTFILE,
ln -s /dev/null .bash_history
or something like that

from the other side:
- .bash_history often reveals what for example root wrote or
connect, if you become root.
- even from typing of the hacker you can know what he knows.

  • etc.

so my task is:

user_ can't read, link, write, etc his own .bash_history,

		but append works ;),
                from the shell level, not from the user_ level

user_ becomming root       --- same ---- (su-stuff)
unset HISTFILE, etc don't work

(all these are under auditdeny)

best regards,

Hacko

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 8 Feb 2002 - 12:53:10 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service