[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] RaQ4r: chkrootkit odd report: bash_history file size is 0



"Michelle A. Hoyle" wrote:

> >Searching for anomalies in shell history files... Warning:
> >`//root/.bash_history' file size is zero
> 
> And, if I check the .bash_history file, it is indeed 0 and doesn't
> seem to be writing anything into it.  If I do a "history", it starts
> off with item 0, with something from this session (but the
> .bash_history file is still empty).  Did this file get rotated out of
> existence because it finally got too big or where did it go?
> 
> Do I need to worry about this?

Perhaps.  On my RaQ4, with the latest upgrades, the .bash_history file
is NOT zero, and does not get zeroed-out on ssh login either to admin
(with or without su to root) or ssh login directly to root.

Jeff
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
Linux and Cobalt/Sun/RaQ Consulting
nobaloney.net
P. O. Box 52672, Riverside, CA  92517
voice: (909) 778-9980  *  fax: (702) 548-9484