[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Recent Hacks



On Tue, 13 Feb 2001, Carrie Bartkowiak wrote:

> > > > [root@www /root]# cat /.bash_history
> 
> I try this as admin or as root and I get "no such file or directory".
> locate .bash_history gets me some files in a couple of user's directories -
> ones that are my directories and one other user on the machine whom I trust
> (and who's on this list)... but nothing else.
> 
> Sound right?
> Carrie B

If yu look through cobalt's security info , one of the things they did was
to make a change to erase the history when root logs out so that people
can't peek at it and look for errant passwords....

(This is also a reason why it's a bad idea to have a users login directory
within the web tree, you could make the web server get this file ;)

gsh