Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #257281 > unrolled thread

Am I infected with a rootkit?

Started byJesper Dybdal <jd-debian-user@dybdal.dk>
First post2023-04-16 14:30 +0200
Last post2023-04-18 17:00 +0200
Articles 20 on this page of 44 — 20 participants

Back to article view | Back to linux.debian.user


Contents

  Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 14:30 +0200
    Re: Am I infected with a rootkit? Eduardo M KALINOWSKI <eduardo@kalinowski.com.br> - 2023-04-16 14:50 +0200
      Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 15:20 +0200
        Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 16:00 +0200
          Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 17:20 +0200
      Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:10 +0200
      Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-18 15:50 +0200
        Re: Am I infected with a rootkit? David Christensen <dpchrist@holgerdanske.com> - 2023-04-18 21:40 +0200
          Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-19 16:00 +0200
    Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 15:00 +0200
      Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:10 +0200
        Re: Am I infected with a rootkit? Jeffrey Walton <noloader@gmail.com> - 2023-04-16 16:50 +0200
        Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 17:20 +0200
    Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 15:10 +0200
      Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:40 +0200
        Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 18:00 +0200
          Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 18:50 +0200
            Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 19:30 +0200
          Re: Am I infected with a rootkit? "Thomas Schmitt" <scdbackup@gmx.net> - 2023-04-16 19:40 +0200
            Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 20:50 +0200
            Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 22:20 +0200
        Re: Am I infected with a rootkit? Curt <curty@free.fr> - 2023-04-17 18:50 +0200
    Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:40 +0200
      Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-16 17:20 +0200
      Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-18 06:50 +0200
        Re: Am I infected with a rootkit? David <bouncingcats@gmail.com> - 2023-04-18 07:40 +0200
          Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 10:00 +0200
            Re: Am I infected with a rootkit? debian-user@howorth.org.uk - 2023-04-18 13:00 +0200
              Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 13:10 +0200
            Re: Am I infected with a rootkit? David <bouncingcats@gmail.com> - 2023-04-18 14:10 +0200
              Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 14:30 +0200
                Re: Am I infected with a rootkit? songbird <songbird@anthive.com> - 2023-04-18 18:00 +0200
                  Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-18 18:30 +0200
                    Re: Am I infected with a rootkit? Andy Smith <andy@strugglers.net> - 2023-04-18 20:40 +0200
          Re: Am I infected with a rootkit? Jesper Dybdal <jesper@dybdal.dk> - 2023-04-18 16:00 +0200
    Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 16:40 +0200
    Re: Am I infected with a rootkit? David Christensen <dpchrist@holgerdanske.com> - 2023-04-17 03:20 +0200
      Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-17 17:40 +0200
      Re: Am I infected with a rootkit? Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-17 19:00 +0200
        Re: Am I infected with a rootkit? Tim Woodall <debianuser@woodall.me.uk> - 2023-04-17 20:30 +0200
    Re: Am I infected with a rootkit? Richmond <dnomhcir@gmx.com> - 2023-04-18 10:40 +0200
      Re: Am I infected with a rootkit? Jesper Dybdal <jesper@dybdal.dk> - 2023-04-18 16:00 +0200
        Re: Am I infected with a rootkit? Jeremy Ardley <jeremy@ardley.org> - 2023-04-18 16:10 +0200
          Re: Am I infected with a rootkit? Charles Curley <charlescurley@charlescurley.com> - 2023-04-18 17:00 +0200

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#257313

FromJesper Dybdal <jd-debian-user@dybdal.dk>
Date2023-04-16 22:20 +0200
Message-ID<Glh0R-2ue5-1@gated-at.bofh.it>
In reply to#257309
On 2023-04-16 19:35, Thomas Schmitt wrote:
> Hi,
>
> to make this mail on-topic:
>
> Jesper Dybdal, do you see the riddling lines in file ~/.bash_history
> of the superuser ?

Yes.

> If so: Do you see other strange lines there ? (Do they give more clue ?)
No.  I stupidly did not save the rest of .bash_history - only the 4 
lines.  I did, however, take a quick look in the file, and saw nothing 
conspicuous  other than those 4 lines.

Thanks,
Jesper

-- 
Jesper Dybdal
https://www.dybdal.dk

[toc] | [prev] | [next] | [standalone]


#257329

FromCurt <curty@free.fr>
Date2023-04-17 18:50 +0200
Message-ID<GlAdb-2FF8-3@gated-at.bofh.it>
In reply to#257291
On 2023-04-16, Jesper Dybdal <jd-debian-user@dybdal.dk> wrote:
>
> On 2023-04-16 15:08, Greg Wooledge wrote:
>> On Sun, Apr 16, 2023 at 02:19:34PM +0200, Jesper Dybdal wrote:
>>> And there in the bash history were 4 lines that I had not written :-(
>> I would initially ask "who else lives with you"....
>
> So would I - if I didn't know that the few people with physical access 
> to my apartment, including my wife, haven't the faintest idea that there 
> is a thing called "md5".

Maybe it's some trivial corollary of the infinite monkey theorem, and
it's really the dog.

-- 

[toc] | [prev] | [next] | [standalone]


#257292

FromJesper Dybdal <jd-debian-user@dybdal.dk>
Date2023-04-16 16:40 +0200
Message-ID<GlbHP-2qZ1-15@gated-at.bofh.it>
In reply to#257281
On 2023-04-16 16:33, David Wright wrote:
> On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote:
>> The 4 lines were:
>>> md5users
>>> sp md5users
>>> sp /x/md5users
>>> ps /x/md5users
>>
> Just FTR and clarity's sake, are the "> " characters (which my MUA has
> unhelpfully doubled by quoting) part of what was typed in the putty
> session, or did you type them into the post to make them stand out?
They were not part of what was typed, and I did add them to make the 
lines stand out.  Sorry for the unclear text.

Here is a correct and clear, I hope, version:

---------------- The 4 lines were:
md5users
sp md5users
sp /x/md5users
ps /x/md5users
---------------- End of the 4 lines

-- 
Jesper Dybdal
https://www.dybdal.dk

[toc] | [prev] | [next] | [standalone]


#257301

From<tomas@tuxteam.de>
Date2023-04-16 17:20 +0200
Message-ID<Glckx-2rsC-3@gated-at.bofh.it>
In reply to#257292

[Multipart message — attachments visible in raw view] — view raw

On Sun, Apr 16, 2023 at 04:39:13PM +0200, Jesper Dybdal wrote:
> 
> On 2023-04-16 16:33, David Wright wrote:
> > On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote:
> > > The 4 lines were:
> > > > md5users
> > > > sp md5users
> > > > sp /x/md5users
> > > > ps /x/md5users
> > > 
> > Just FTR and clarity's sake, are the "> " characters (which my MUA has
> > unhelpfully doubled by quoting) part of what was typed in the putty
> > session, or did you type them into the post to make them stand out?
> They were not part of what was typed, and I did add them to make the lines
> stand out.  Sorry for the unclear text.
> 
> Here is a correct and clear, I hope, version:
> 
> ---------------- The 4 lines were:
> md5users
> sp md5users
> sp /x/md5users
> ps /x/md5users
> ---------------- End of the 4 lines

Sometimes, some tools rely on a shell at the "other side" to do
their job. Emacs's Tramp is known for leaving traces in the shell
history, quite possibly abominations like VSCode do their thing
in a similar way.

That said, the above commands look more like a human not quite
knowing what (s)he's doing. If that were an intruder, I'd not
worry too much ;-)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#257341

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2023-04-18 06:50 +0200
Message-ID<GlLrX-2Muy-5@gated-at.bofh.it>
In reply to#257292
On Sun 16 Apr 2023 at 16:39:13 (+0200), Jesper Dybdal wrote:
> On 2023-04-16 16:33, David Wright wrote:
> > On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote:
> > > The 4 lines were:
> > > > md5users
> > > > sp md5users
> > > > sp /x/md5users
> > > > ps /x/md5users
> > > 
> > Just FTR and clarity's sake, are the "> " characters (which my MUA has
> > unhelpfully doubled by quoting) part of what was typed in the putty
> > session, or did you type them into the post to make them stand out?
> They were not part of what was typed, and I did add them to make the
> lines stand out.  Sorry for the unclear text.
> 
> Here is a correct and clear, I hope, version:
> 
> ---------------- The 4 lines were:
> md5users
> sp md5users
> sp /x/md5users
> ps /x/md5users
> ---------------- End of the 4 lines

OK, you wrote that you "pressed up-arrow a few times. And there in the
bash history were 4 lines …". If those 4 lines were not the first
things to appear when you pressed up-arrow, then I would assume that
the commands you typed /just/ before you went out with the dog were
the first lines to appear, and then your 4 lines after more up-arrows.

If that's the case, then your 4 lines could have been typed
in a previous login as root, and that could have been some time
ago. They would have been languishing at the end of the file
/root/.bash_history before you logged in as root this time.

There is an option to timestamp entries in the history file. I've
never used it, nor heard of its being used. That might disambiguate
things if you ever suspect it might happen again.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#257343

FromDavid <bouncingcats@gmail.com>
Date2023-04-18 07:40 +0200
Message-ID<GlMel-2N10-9@gated-at.bofh.it>
In reply to#257341
On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote:

> There is an option to timestamp entries in the history file. I've
> never used it, nor heard of its being used. That might disambiguate
> things if you ever suspect it might happen again.

Hi, on my machines I use Bash as interactive
shell, with:
HISTTIMEFORMAT=: %Y%m%d_%H%M%S ;

That provides a couple of benefits:

1) it writes a commented Unix timestamp with
each addition to the ~/.bash_history file, so that
the history file not only logs what commands were
run interactively, but also when.

2) when I run the 'history' command, the outpt
is formatted like this:
501  : 20230418_151124 ; help history
502  : 20230418_151406 ; env
503  : 20230418_151749 ; history
The colon and semicolon allow the timestamp
to function as a no-operation command.
That means that history expansion
can still function, for example entering !502
interactively will run line number 502, but
only the 'env' that comes after the semicolon
will have any effect.

[toc] | [prev] | [next] | [standalone]


#257344

From<tomas@tuxteam.de>
Date2023-04-18 10:00 +0200
Message-ID<GlOpP-2Oi2-1@gated-at.bofh.it>
In reply to#257343

[Multipart message — attachments visible in raw view] — view raw

On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote:
> On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote:
> 
> > There is an option to timestamp entries in the history file. I've
> > never used it, nor heard of its being used. That might disambiguate
> > things if you ever suspect it might happen again.
> 
> Hi, on my machines I use Bash as interactive
> shell, with:
> HISTTIMEFORMAT=: %Y%m%d_%H%M%S ;
> 
> That provides a couple of benefits:
> 
> 1) it writes a commented Unix timestamp with
> each addition to the ~/.bash_history file, so that
> the history file not only logs what commands were
> run interactively, but also when.
> 
> 2) when I run the 'history' command, the outpt
> is formatted like this:
> 501  : 20230418_151124 ; help history
> 502  : 20230418_151406 ; env
> 503  : 20230418_151749 ; history
> The colon and semicolon allow the timestamp
> to function as a no-operation command.

At least in bash, this doesn't seem necessary, as you are
only seeing an external representation: internally, bash
keeps the timestamp separate (as happens to the seq number,
too).

In the external file, the timestamps are kept as #-comments
in separate lines (with the UNIX timestamps in them).

> That means that history expansion
> can still function, for example entering !502
> interactively will run line number 502, but
> only the 'env' that comes after the semicolon
> will have any effect.

I tried it out, and this also works with a "naked" timestamp,
without the : ... ; wrapping.

Caveat: I only tried with bash.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#257347

Fromdebian-user@howorth.org.uk
Date2023-04-18 13:00 +0200
Message-ID<GlRe1-2Q1C-3@gated-at.bofh.it>
In reply to#257344
<tomas@tuxteam.de> wrote:
> On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote:
> > On Tue, 18 Apr 2023 at 04:42, David Wright
> > <deblis@lionunicorn.co.uk> wrote: 
> > > There is an option to timestamp entries in the history file. I've
> > > never used it, nor heard of its being used. That might
> > > disambiguate things if you ever suspect it might happen again.  
> > 
> > Hi, on my machines I use Bash as interactive
> > shell, with:
> > HISTTIMEFORMAT=: %Y%m%d_%H%M%S ;
> > 
> > That provides a couple of benefits:
> > 
> > 1) it writes a commented Unix timestamp with
> > each addition to the ~/.bash_history file, so that
> > the history file not only logs what commands were
> > run interactively, but also when.
> > 
> > 2) when I run the 'history' command, the outpt
> > is formatted like this:
> > 501  : 20230418_151124 ; help history
> > 502  : 20230418_151406 ; env
> > 503  : 20230418_151749 ; history
> > The colon and semicolon allow the timestamp
> > to function as a no-operation command.  
> 
> At least in bash, this doesn't seem necessary, as you are
> only seeing an external representation: internally, bash
> keeps the timestamp separate (as happens to the seq number,
> too).
> 
> In the external file, the timestamps are kept as #-comments
> in separate lines (with the UNIX timestamps in them).

bash seems to treat root and a normal user differently.

> > That means that history expansion
> > can still function, for example entering !502
> > interactively will run line number 502, but
> > only the 'env' that comes after the semicolon
> > will have any effect.  
> 
> I tried it out, and this also works with a "naked" timestamp,
> without the : ... ; wrapping.
> 
> Caveat: I only tried with bash.
> 
> Cheers

[toc] | [prev] | [next] | [standalone]


#257348

From<tomas@tuxteam.de>
Date2023-04-18 13:10 +0200
Message-ID<GlRnI-2Qlc-5@gated-at.bofh.it>
In reply to#257347

[Multipart message — attachments visible in raw view] — view raw

On Tue, Apr 18, 2023 at 11:51:42AM +0100, debian-user@howorth.org.uk wrote:
> <tomas@tuxteam.de> wrote:

[...]

> > At least in bash, this doesn't seem necessary, as you are
> > only seeing an external representation: internally, bash
> > keeps the timestamp separate (as happens to the seq number,
> > too).
> > 
> > In the external file, the timestamps are kept as #-comments
> > in separate lines (with the UNIX timestamps in them).
> 
> bash seems to treat root and a normal user differently.

On my box, history, .bash_history and HISTTIMEFORMAT behave as
I described both for root and for a regular user.

Just to be sure:
# tomas@trotzki:~$ bash --version
# GNU bash, version 5.1.4(1)-release (x86_64-pc-linux-gnu)
# Copyright (C) 2020 Free Software Foundation, Inc.
# License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
# 
# This is free software; you are free to change and redistribute it.
# There is NO WARRANTY, to the extent permitted by law.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#257349

FromDavid <bouncingcats@gmail.com>
Date2023-04-18 14:10 +0200
Message-ID<GlSjL-2QWe-3@gated-at.bofh.it>
In reply to#257344
On Tue, 18 Apr 2023 at 07:51, <tomas@tuxteam.de> wrote:
> On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote:
> > On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote:

> > > There is an option to timestamp entries in the history file. I've
> > > never used it, nor heard of its being used. That might disambiguate
> > > things if you ever suspect it might happen again.
> >
> > Hi, on my machines I use Bash as interactive
> > shell, with:
> > HISTTIMEFORMAT=: %Y%m%d_%H%M%S ;
> >
> > That provides a couple of benefits:
> >
> > 1) it writes a commented Unix timestamp with
> > each addition to the ~/.bash_history file, so that
> > the history file not only logs what commands were
> > run interactively, but also when.
> >
> > 2) when I run the 'history' command, the outpt
> > is formatted like this:
> > 501  : 20230418_151124 ; help history
> > 502  : 20230418_151406 ; env
> > 503  : 20230418_151749 ; history
> > The colon and semicolon allow the timestamp
> > to function as a no-operation command.
>
> At least in bash, this doesn't seem necessary, as you are
> only seeing an external representation: internally, bash
> keeps the timestamp separate (as happens to the seq number,
> too).

Hi, it could well be unnecessary, I haven't played with it
for a long time.

I'm sure that there would have been some reason at the
time why I chose to configure it that way, but it is so many years
ago that I can't recall the reason.

Guessing, it could just have been that I was lazy and doing something
odd. Perhaps I wanted to dump the history output into a file, preserve
the timestamps for some long-forgotten reason, and also put a shebang
at the top of the file and run it again with minimal editing. Or maybe
I wanted a known delimiter that I could strip automatically from
the history output. I dunno.

It also would have been several Bash versions ago, Bash 2 or 3, so
perhaps the behaviour changed since I configured it.

Anyway, if it isn't necessary now, there's no reason for me to advocate
doing that, so I appreciate that you have let everyone know about that.

[toc] | [prev] | [next] | [standalone]


#257350

From<tomas@tuxteam.de>
Date2023-04-18 14:30 +0200
Message-ID<GlSD8-2R3b-1@gated-at.bofh.it>
In reply to#257349

[Multipart message — attachments visible in raw view] — view raw

On Tue, Apr 18, 2023 at 11:59:58AM +0000, David wrote:
> On Tue, 18 Apr 2023 at 07:51, <tomas@tuxteam.de> wrote:
> > On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote:

[...]

> > > The colon and semicolon allow the timestamp
> > > to function as a no-operation command.
> >
> > At least in bash, this doesn't seem necessary, as you are
> > only seeing an external representation: internally, bash
> > keeps the timestamp separate (as happens to the seq number,
> > too).
> 
> Hi, it could well be unnecessary, I haven't played with it
> for a long time.

[...]

> It also would have been several Bash versions ago, Bash 2 or 3, so
> perhaps the behaviour changed since I configured it.
> 
> Anyway, if it isn't necessary now, there's no reason for me to advocate
> doing that, so I appreciate that you have let everyone know about that.

Definitely. I just pointed that out as a request for discussion.
Perhaps this isn't portable across shells or even different
versions of bash. So caveat emptor :)

Cheers and thanks -- I didn't know about HISTTIMEFORMAT before!

-- 
t

[toc] | [prev] | [next] | [standalone]


#257362

Fromsongbird <songbird@anthive.com>
Date2023-04-18 18:00 +0200
Message-ID<GlVUl-2SWQ-3@gated-at.bofh.it>
In reply to#257350
<tomas@tuxteam.de> wrote:
...
> Definitely. I just pointed that out as a request for discussion.
> Perhaps this isn't portable across shells or even different
> versions of bash. So caveat emptor :)
>
> Cheers and thanks -- I didn't know about HISTTIMEFORMAT before!

  just as an aside for those who think about this sort of thing.  :)

  i like to start with a known state including the shell history
so upon starting up a terminal i determine what commands i want
in the history by detecting which directory i'm in (which tells
me which project i'm working on).  it's very easy then for me
to start things by using the !<number> or !<abbrv>.

  i also do not like history stuff hanging around so i may 
attempt to clear things out upon logging out or shutting down
but since some crashes can happen i do not rely upon that 
being 100%.  which is why when i do start up i set things up
how i like and do clear the history at that point (before
putting the commands in i want).


  songbird

[toc] | [prev] | [next] | [standalone]


#257363

FromMichel Verdier <mv524@free.fr>
Date2023-04-18 18:30 +0200
Message-ID<GlWno-2TlQ-3@gated-at.bofh.it>
In reply to#257362
Le 18 avril 2023 songbird a écrit :

>   i like to start with a known state including the shell history
> so upon starting up a terminal i determine what commands i want
> in the history by detecting which directory i'm in (which tells
> me which project i'm working on).  it's very easy then for me
> to start things by using the !<number> or !<abbrv>.

I recently learned the ctrl-r key which launch a regex search in
history. It's more powerful than !<abbrv> as it search the full
lines so not only commands but also parameters.

[toc] | [prev] | [next] | [standalone]


#257370

FromAndy Smith <andy@strugglers.net>
Date2023-04-18 20:40 +0200
Message-ID<GlYpb-2UCC-1@gated-at.bofh.it>
In reply to#257363
Hello,

On Tue, Apr 18, 2023 at 06:22:16PM +0200, Michel Verdier wrote:
> I recently learned the ctrl-r key which launch a regex search in
> history. It's more powerful than !<abbrv> as it search the full
> lines so not only commands but also parameters.

Now step in to the late 2010s and look into "fzf" 😀

(It is packaged in Debian)

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#257353

FromJesper Dybdal <jesper@dybdal.dk>
Date2023-04-18 16:00 +0200
Message-ID<GlU2d-2RNB-1@gated-at.bofh.it>
In reply to#257343
On 2023-04-18 07:29, David wrote:
> On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote:
>
>> There is an option to timestamp entries in the history file. I've
>> never used it, nor heard of its being used. That might disambiguate
>> things if you ever suspect it might happen again.
> Hi, on my machines I use Bash as interactive
> shell, with:
> HISTTIMEFORMAT=: %Y%m%d_%H%M%S ;
>
> That provides a couple of benefits:
...

Thanks to David, David, Tomas, and debian-user@howorth.org.uk for the 
suggestion of using time stamps on the history lines.  I intend to do 
that in the future.

-- 
Jesper Dybdal
https://www.dybdal.dk

[toc] | [prev] | [next] | [standalone]


#257296

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2023-04-16 16:40 +0200
Message-ID<GlbHP-2qZ1-7@gated-at.bofh.it>
In reply to#257281
On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote:
> And there in the bash history were 4 lines that I had not written :-(
> 
> I am certain that nobody had been in my apartment while I was gone.
> And even if they had, nobody with a key to my apartment would dream of
> writing things like the 4 lines that I found in the history file.
> 
> The 4 lines were:
> > md5users
> > sp md5users
> > sp /x/md5users
> > ps /x/md5users
> There is no file named "md5users" or directory named "/x" or command
> named "sp" on the Debian machine.

Just FTR and clarity's sake, are the "> " characters (which my MUA has
unhelpfully doubled by quoting) part of what was typed in the putty
session, or did you type them into the post to make them stand out?

The reason I ask is that most people have their PS2 set to "> ",
suggesting that these might have been some sort of continuation—
of what, we don't know.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#257315

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2023-04-17 03:20 +0200
Message-ID<GllHb-2x2t-1@gated-at.bofh.it>
In reply to#257281
On 4/16/23 05:19, Jesper Dybdal wrote:
> I have a Debian pc functioning as router, firewall, file server, name 
> server, webserver, ...
> It has very recently been upgraded to Bullseye.
> 
> On the internal network I have a Windows 10 pc.

> And there in the bash history were 4 lines that I had not written :-(

>> md5users
>> sp md5users
>> sp /x/md5users
>> ps /x/md5users


On 4/16/23 07:30, Jesper Dybdal wrote:

 > ... I really need to be able to run ssh [on Windows to] administer
 > [the Debian] machine (which normally has neither keyboard nor
 > monitor).


What about installing a KVM switch and administering the Debian computer 
from the console?


If the two computers are separated, you could use a KVM extender and put 
the KVM switch near the Windows computer.  Or, you could get networked 
KVM equipment.


That said, using one computer as router, firewall, file server, name 
server, web server, and more represents "all of your eggs in one 
basket".  I suggest using dedicated hardware for networking, network 
segmentation (e.g. DMZ), and kernel or hypervisor compartmentalization 
of services.  Qubes looks very appealing:

         https://www.qubes-os.org/


David

[toc] | [prev] | [next] | [standalone]


#257327

FromMichel Verdier <mv524@free.fr>
Date2023-04-17 17:40 +0200
Message-ID<Glz7r-2F3t-1@gated-at.bofh.it>
In reply to#257315
Le 17 avril 2023 David Christensen a écrit :

> That said, using one computer as router, firewall, file server, name server,
> web server, and more represents "all of your eggs in one basket".  I suggest
> using dedicated hardware for networking, network segmentation (e.g. DMZ), and
> kernel or hypervisor compartmentalization of services.  Qubes looks very
> appealing:

What are its advantages vs debian ? Debian can chroot most services. Some
are chrooted by default (postfix, etc). And you can use Xen and tor on
debian.

[toc] | [prev] | [next] | [standalone]


#257330

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2023-04-17 19:00 +0200
Message-ID<GlAmR-2FId-9@gated-at.bofh.it>
In reply to#257315
> That said, using one computer as router, firewall, file server, name server,
> web server, and more represents "all of your eggs in one basket".  I suggest
> using dedicated hardware for networking, network segmentation (e.g. DMZ),
> and kernel or hypervisor compartmentalization of services.

Dedicated hardware has its upsides, indeed, but it also
has its downsides (e.g. in terms of impact to the planet).


        Stefan

[toc] | [prev] | [next] | [standalone]


#257331

FromTim Woodall <debianuser@woodall.me.uk>
Date2023-04-17 20:30 +0200
Message-ID<GlBLX-2GF4-5@gated-at.bofh.it>
In reply to#257330
On Mon, 17 Apr 2023, Stefan Monnier wrote:

>> That said, using one computer as router, firewall, file server, name server,
>> web server, and more represents "all of your eggs in one basket".  I suggest
>> using dedicated hardware for networking, network segmentation (e.g. DMZ),
>> and kernel or hypervisor compartmentalization of services.
>
> Dedicated hardware has its upsides, indeed, but it also
> has its downsides (e.g. in terms of impact to the planet).
>

This is very true.

I switched to using one of these:
https://www.asrockrack.com/general/productdetail.asp?Model=J1900D2Y
in a xen configuration, from multiple hardware - but multiple services
on one hardware instance.

it's low power and fanless and has built in IPMI.

For me that ticks all the boxes I need. Having each of nameserver, dhcp
server, web server, firewall, "file server"[1] etc, running on separate
guests makes upgrading so much simpler too. I used to dread upgrades,
now they're relatively painless.

[1] I don't really run a fileserver but I do run iscsi targets.

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web