LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-21-2012, 07:18 PM   #1
khizra
LQ Newbie
 
Registered: Mar 2012
Posts: 1

Rep: Reputation: Disabled
Question automated scripts - .bash history


Hello Everyone,

I have a couple of questions:

1) How do I find traces/signs of automated scripts? I think bash history contains info about the manually typed commands by keyboards, but automated scripts wont be found there in bash history.. Am I right??

2)Also where would i find the info that who logins using which shell?
i think one place is to etc/log/secure...

Please help!

Thanks in advance
 
Old 03-22-2012, 02:28 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by khizra View Post
automated scripts wont be found there in bash history..
No they won't be.


Quote:
Originally Posted by khizra View Post
Also where would i find the info that who logins using which shell?
i think one place is to etc/log/secure...
Login records are stored in /var/log/wtmp and /var/log/btmp and /var/log/secure is where among others PAM logs PAM login stack messages.


Quote:
Originally Posted by khizra View Post
How do I find traces/signs of automated scripts?
You should always provide distribution, user, service and other relevant details as apart from the above things depend on your setup (for instance both SELinux and Grsecurity can log say exec syscalls but you have to run and have configured one of those beforehand and both the 'at' and 'crond' services can use {at,cron}.deny files), who has access to the machine (IDS or Netfilter logging network scans and other traffic, the system recording any violations) and to some extent when you first got the hunch something could be wrong (sometimes you would be able to copy out deleted files on open file descriptors or "undelete" them). You see providing details first is vital.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Urgent : Automated scripts require to check device file in hpux manish_meet_in Linux - Newbie 4 01-26-2007 01:45 PM
automated tasks scripts Texas_student Linux - Software 2 04-23-2006 11:07 AM
FileServer w/ automated scripts for a small-sized enterprise tyiooo Linux - Enterprise 3 08-27-2005 12:26 PM
Any automated scripts to run DVD Backups? bweiss Linux - Newbie 3 04-28-2005 09:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration