Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Tech and Talk » OS and Software » All Things Unix » Securing .bash_history
Search Topic:
Uniqs:
386
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
iptables help... »
« shell scripting  
AuthorAll Replies


evilghost
Premium
join:2003-11-22
Springville, AL
·Windstream

Securing .bash_history

The SSH honeypot detected an actual human user, the first command they ran was "unset HISTFILE" which will unset the environment variable for the location of the bash history file. While this is a quite old technique evidently this is the first time I had seen it.

In an effort to educate others I'm creating this topic and providing methods to mitigate this.

To prevent this you can edit /etc/profile and set these variables as read-only. If you're using an ext filesystem you can also chattr .bash_history so it can only be opened in append mode; preventing users from erasing/clobbering the file.




bky
Premium
join:2002-07-05
Austin, TX
Excellent hardening tip, thanks. Also keeps the user from exporting a different value for histfile, such as /dev/null.


BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000

reply to evilghost
Excellent post.

It's important to note that this only stops the intruder from remapping the history file and doesn't stop the filesystem based vectors to achieve the same goal. Linking ~/.bash_history to /dev/null is still possible, etc.

Not trying to dissuade anyone from following the profile hardening method, just trying to encourage people to view the attack from all vantage points.

Thanks!
--
Overpower, overcome.


evilghost
Premium
join:2003-11-22
Springville, AL
·Windstream


edit:
April 11th, @12:53PM

said by BeesTea See Profile :

Excellent post.

It's important to note that this only stops the intruder from remapping the history file and doesn't stop the filesystem based vectors to achieve the same goal. Linking ~/.bash_history to /dev/null is still possible, etc.

Not trying to dissuade anyone from following the profile hardening method, just trying to encourage people to view the attack from all vantage points.

Thanks!
Can you expand on that? I was under the impression the chattr +a would cover that (or are you speaking with regard to the readonly export settings)? Thanks for your input



bky
Premium
join:2002-07-05
Austin, TX
·AT&T U-Verse

reply to BeesTea
said by BeesTea See Profile :

It's important to note that this only stops the intruder from remapping the history file and doesn't stop the filesystem based vectors to achieve the same goal. Linking ~/.bash_history to /dev/null is still possible, etc.
Actually, an append-only attribute would prevent the user from doing this.


BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000
reply to evilghost
Sorry, skimmed the chattr sentence and went to the first code block. Not enough coffee this morning I guess.

Again, great post.
--
Overpower, overcome.


evilghost
Premium
join:2003-11-22
Springville, AL
·Windstream

said by BeesTea See Profile :

Sorry, skimmed the chattr sentence and went to the first code block. Not enough coffee this morning I guess.

Again, great post.
Thanks again, glad I understood chattr to be what it is. Obviously chattr is only going to be applicable to an ext filesystem. I would assume ReiserFS and XFS have similar fs attribute settings...


bky
Premium
join:2002-07-05
Austin, TX
Yep. ext(all versions), jfs, xfs, and reiser all support extended attributes.
Forums » Tech and Talk » OS and Software » All Things Unixiptables help... »
« shell scripting  


Saturday, 11-Oct 04:27:33 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [140] It's Cable TV Rate Hike Season
· [96] Wholesale Bandwidth Prices Still Dropping
· [95] Is Comcast Cooking Up a 22Mbps/5Mbps Tier?
· [95] Symmetrical FiOS No Longer Qualifies For Bundle Discounts
· [84] Time Warner's Ugly Feud With LIN TV
· [77] Half Of New iPhone Owners Came From Verizon
· [70] Supreme Court TiVo/Echostar Ruling
· [70] Microsoft: U.S. Broadband Policy 'Total Failure'
· [66] Verizon Unveils Blackberry Storm
· [64] XOHM Online In Additional Launch Markets
Most people now reading
· Where did the money go? [General Questions]
· Extreme HD and Essentials [Verizon FIOS TV]
· Homeowner Says Cable Mistake Filled Kitchen With Raw Sewage [Comcast Cable TV]
· [Connectivity] Neighbor using MY router to connect to Internet? [Comcast HSI]
· Heads up; Usenet, "Rarpassgen.exe" virus [TekSavvy]
· [Rant] People who say Not voting for Barack because he's Black. [Rants, Raves, & Praise]
· Safty Question about K & T wiring. Very worried... [Home Repair & Improvement]
· IMG 1.6 Build 06.89 Released [Verizon FIOS TV]
· Tomato/MLPPP v2 FINAL released! [TekSavvy]