LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-09-2010, 02:16 PM   #1
boblikeslinux
LQ Newbie
 
Registered: Feb 2010
Posts: 10

Rep: Reputation: 1
Root's .bash_history has been truncated to 0


I have a recently installed Ubuntu Karmic with standard packages. I enabled automatic security updates and manually updated every package once. I have the root account enabled. At ~1am GMT my .bash_history file for the root account has been truncated to zero. I think the PC may have crashed (no keyboard, mouse, etc, but still some HD activity) at around this time. The disk isn't full, but this is a fresh install, I do not have direct net access (NAT) and I have only visited a limited number of web sites.

Can anyone think of innocuous reasons this would happen?

Last edited by boblikeslinux; 02-09-2010 at 02:17 PM.
 
Old 02-09-2010, 03:15 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
No, searched your syslogs and auth records for any anomalies? Are there any ~/.bash* configuration files (say the ~/.bash_log* ones) that include a "cleanup" line?
 
Old 02-09-2010, 03:38 PM   #3
boblikeslinux
LQ Newbie
 
Registered: Feb 2010
Posts: 10

Original Poster
Rep: Reputation: 1
There are no cleanup lines, and it doesn't seem like something they would make updating packages do.

Yet, it's so unlikely to have been hacked with such limited exposure to the net. And for someone who hacked it with that limited exposure to be clumsy enough to truncate the .bash_history instead of just disabling their session history? That also seems weird...
 
Old 02-09-2010, 04:24 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by boblikeslinux View Post
There are no cleanup lines
OK...

Quote:
Originally Posted by boblikeslinux View Post
Yet, it's so unlikely to have been hacked with such limited exposure to the net. And for someone who hacked it with that limited exposure to be clumsy enough to truncate the .bash_history instead of just disabling their session history? That also seems weird...
I'd rather deal with facts than the chance of something being "likely" or "unlikely". Does "env | grep HIST" show any HISTFILESIZE, HISTSIZE and HISTIGNORE environment variables perhaps?

Last edited by unSpawn; 02-09-2010 at 04:26 PM.
 
Old 02-09-2010, 05:58 PM   #5
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
Can you check /var/log/messages, dmesg to see if your system did in fact crash/reboot?
 
Old 02-09-2010, 06:34 PM   #6
boblikeslinux
LQ Newbie
 
Registered: Feb 2010
Posts: 10

Original Poster
Rep: Reputation: 1
Quote:
Originally Posted by unSpawn View Post
I'd rather deal with facts than the chance of something being "likely" or "unlikely". Does "env | grep HIST" show any HISTFILESIZE, HISTSIZE and HISTIGNORE environment variables perhaps?
No history stuff. My bash history is once again collecting normally, it didn't stay a zero size file.

Quote:
Originally Posted by chrism01 View Post
Can you check /var/log/messages, dmesg to see if your system did in fact crash/reboot?
The only activity around that time is:

Feb 9 01:05:45 box kernel: Kernel logging (proc) stopped.
Feb 9 01:05:45 box rsyslogd: [origin software="rsyslogd" swVersion="4.2.0" x-pid="513" x-info="http://www.rsyslog.com"] exiting on signal 15.

It's about the time I stopped using the system. The history file was truncated at 1:05 am too. I can't remember if the system crashed or I shut it down (yesterday the OS was in a different box which is prone to crashing) but it does closely match the time I went to bed.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
root's .bash_history is zero size Reasa Linux - Security 7 02-21-2009 05:46 AM
.bash_history t3gah Linux - Software 2 05-05-2005 03:45 AM
Truncated IP??? What? slaken Linux - Networking 5 05-12-2004 03:51 AM
bash_history linj Linux - Software 6 08-08-2003 10:13 AM
.bash_history gone togeno Linux - Security 3 06-30-2003 07:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration