LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 04-28-2003, 04:36 PM   #1
farhan
Member
 
Registered: Feb 2003
Distribution: xNIX
Posts: 121

Rep: Reputation: 15
where can i find history


hi
is ther any other place where i can find the bash history other than /.bash_history
i want to know wt the user had been doing on the shell......also want to know wt the use had ben doing in the gui (kde)??
 
Old 04-28-2003, 04:38 PM   #2
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Rep: Reputation: 45
You can't really log everything the user is doing in the GUI without patching KDE afaik! And if you do so it will be a HUGE performance decrease. Is it really worth the trouble ?

What are you trying to archive ?
 
Old 04-28-2003, 04:46 PM   #3
farhan
Member
 
Registered: Feb 2003
Distribution: xNIX
Posts: 121

Original Poster
Rep: Reputation: 15
wana see history of shell

if the used delets the commands from the bahs history file then how can i find out wt had benn he doing there... i mean the user is the member of the same root group and have all the rights
then if he delets the command from the .bash-history file then is there any other place where can i find out the logs
 
Old 04-28-2003, 05:12 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
If a privileged user deletes commands or you expect it to happen, that means you've got a trust problem. If you can't trust this user to do a job w/o the need for you constantly checking, then deny the user access to privileged accounts. If that is not an option you can get some initial coverage (not everything and not for long), but since the user is in the root group circumvention is easy anyway once he/she finds out you've been logging.

So, maybe it would be good if you explained why you need this before we try to offer more detailed suggestions. Depending on decay (for instance disk I/O and time) you may be able to undelete snippets of .bash_history when not shredded or linked to /dev/null or something like that, but it's more like forensics stuff (slow, tedious and no guarantee of result).
 
Old 04-29-2003, 09:06 AM   #5
farhan
Member
 
Registered: Feb 2003
Distribution: xNIX
Posts: 121

Original Poster
Rep: Reputation: 15
i wana do is as we were confiruring the firwell at home we all were the amember of root group ..as i was root there. it was mis configured no trafic was comming and out.. and i tried to find out it in the .bash-history but commands there were not causing the problem..then i thought that may be some one had deleted the command as we will blame him that he had created problem ot us
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
history junaid18183 Linux - General 14 11-07-2009 07:01 AM
history saipraveen Linux - Newbie 5 06-10-2005 07:04 PM
about history jackandking Programming 1 12-18-2004 02:10 PM
How to find back "history" database after "history -c" ? san_lss Linux - Newbie 1 01-07-2004 11:53 AM
History neohybrid1 Linux - General 1 12-03-2002 04:53 AM


All times are GMT -5. The time now is 12:08 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration