[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] RaQ4r: chkrootkit odd report: bash_history file size is 0



Date: Wed, 19 Dec 2001 11:18:02 -0800
From: Jeff Lasman <jblists@xxxxxxxxxxxxx>

"Michelle A. Hoyle" wrote:

 >Searching for anomalies in shell history files... Warning:
 >`//root/.bash_history' file size is zero

 And, if I check the .bash_history file, it is indeed 0 and doesn't
 seem to be writing anything into it.  If I do a "history", it starts
 off with item 0, with something from this session (but the
 .bash_history file is still empty).  Did this file get rotated out of
 > existence because it finally got too big or where did it go?

 Do I need to worry about this?

Perhaps.  On my RaQ4, with the latest upgrades, the .bash_history file
is NOT zero, and does not get zeroed-out on ssh login either to admin
(with or without su to root) or ssh login directly to root.


I use ssh all the time. The last time I happened to look at the history file (which was quite some time ago), it had thousands of entries in it. That's why I was wondering if it maybe hit some size and rotated. I did a cursory look through etc/cron-daily, but I didn't see anything for that.

M