[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] Recent Hacks
- Subject: Re: [cobalt-users] Recent Hacks
- From: flash22@xxxxxxx
- Date: Tue Feb 13 15:27:02 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
On Tue, 13 Feb 2001, Carrie Bartkowiak wrote:
> > > > [root@www /root]# cat /.bash_history
>
> I try this as admin or as root and I get "no such file or directory".
> locate .bash_history gets me some files in a couple of user's directories -
> ones that are my directories and one other user on the machine whom I trust
> (and who's on this list)... but nothing else.
>
> Sound right?
> Carrie B
If yu look through cobalt's security info , one of the things they did was
to make a change to erase the history when root logs out so that people
can't peek at it and look for errant passwords....
(This is also a reason why it's a bad idea to have a users login directory
within the web tree, you could make the web server get this file ;)
gsh