View Full Version : .bash_history gone > /dev/null
Xeno
2004-08-28, 11:32 PM CDT
Both root and normal users .bash_history have been linked to /dev/null.
I know i didn't do it. Anyone know of any software that does this when its installed.?
I'm pretty sure it wasent like that when i installed fedora from CD lol
Xeno
2004-08-29, 12:15 AM CDT
NVM i figured it out
SuperNu
2004-08-29, 10:35 AM CDT
When .bash_history is linked to /dev/null it can be from a cracker trying to cover their tracks. I don't think that any legitimate sofware would ever link .bash_history to /dev/null for any reason. Is this a recent change on your system? I would download chkrootkit (http://www.chkrootkit.org/) and scan your system for known rootkits.
-SN
ghaefb
2004-08-29, 10:41 AM CDT
SuperNu is right...
.bash_history is not linked to null by deafault in any Linux distribution I think.
This is something "fishy" :)
Xeno
2004-08-29, 02:36 PM CDT
Your both right, and when i noticed it yesterday the thought i had been cracked was what jumped out at me too. However it was by my own doing.
After grepping /etc/passwd for extra root accounts and running rkhunter and chkrootkit 5000 times did i remember what i had done. I had run a tool i acquired from Packetstormsecurity.nl named nixfo as to get a better idea of how much usefull info a cracker might get if an intrusion did eventuate. And as you guessed this tool links .bash_history -> /dev/null (Phew indeed)
So sorry to alarm everyone with my paranoia.
In future i will should take a less hands on approach to my security maybe :P.
/Xeno
vBulletin® v3.8.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.