Re: bash_history set to zero length



Kevin Bailey wrote:

And are there any reasons for the bash_history file to get set to zero -
say for a broken ssh session - caused by a backup script logging in from
a backup server over ssh using a key etc?

I've had chkrootkit report the zero size file - but can find absolutely
no other sign of a compromise.

There would not seem to be any valid reason for the various /.bash_history
files [all] to be zeroed. To be more thorough you could check them all -

# ll /root/.bash_history

# ll /home/[any_user_0]/.bash_history

.... - etc.

If you have set an IDS baseline (as [i.e.] tripwire or aide ...), (and
stored on read-only media) you can check to see if your executable system
files have been altered. If you have not done this, you have little or no
reason to expect anything innocent. Please don't shoot the messenger, and
sorry to say, but if you do not have an explanation immediately at hand,
disconnect and rebuild from scratch or backup, as in last known secure
backup. We all dread this, and I am sorry that this misfortune has come
into your life.

Good luck and best wishes. But please do disconnect. Thank you.
.



Relevant Pages

  • Re: bash_history set to zero length
    ... say for a broken ssh session - caused by a backup script logging in from ... There would not seem to be any valid reason for the various /.bash_history ... But please do disconnect. ...
    (comp.os.linux.security)
  • Re: External HDD on a Mac
    ... I'd like to disconnect the drive from the system unless I'm actually using it for backup. ... Should this be done with the system up and running using the normal unmount procedure, then turn off the drive and disconnect it from the system, or is it ok to disconnect the drive and turn it off BEFORE booting up the computer? ... You can start the Mac and later start the external, watch the external mount, do the business of backup and then unmount the external and turn it off while the Mac stays on. ...
    (comp.sys.mac.apps)
  • Re: External HDD on a Mac
    ... actually using it for backup. ... In shutting down the drive to disconnect it from the computer, ... have to unmount it first. ... You can start the Mac and later start the external, ...
    (comp.sys.mac.apps)
  • Re: KB ARTICLE 278875
    ... upgrading a W2K domain to accept 2003 domain controllers. ... but does not have the "backup the Schema Master and disconnect" step. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Virtualized a child DC - need to recover due to USN rollback
    ... Then do the tests to guarantee that everything was OK. ... correct methods (disconnect from network, do the system state backup, ... IM There's no point to recover a system state from a disconnected DC ... If it does and it's replicating, etc, make a good backup of the System State and flat file backup of the hard drives. ...
    (microsoft.public.windows.server.active_directory)