From owner-freebsd-security Fri Aug 28 22:07:08 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id WAA10955 for freebsd-security-outgoing; Fri, 28 Aug 1998 22:07:08 -0700 (PDT) (envelope-from owner-freebsd-security@FreeBSD.ORG) Received: from peak.mountin.net (peak.mountin.net [207.227.119.2]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id WAA10950 for ; Fri, 28 Aug 1998 22:07:04 -0700 (PDT) (envelope-from jeff-ml@mountin.net) Received: (from daemon@localhost) by peak.mountin.net (8.9.1/8.9.1) id AAA02294; Sat, 29 Aug 1998 00:05:41 -0500 (CDT) Received: from aridius-108.isdn.mke.execpc.com(169.207.66.235) by peak.mountin.net via smap (V1.3) id sma002292; Sat Aug 29 00:05:19 1998 Message-Id: <3.0.3.32.19980828235925.00b1b5ec@207.227.119.2> X-Sender: jeff-ml@207.227.119.2 X-Mailer: QUALCOMM Windows Eudora Pro Version 3.0.3 (32) Date: Fri, 28 Aug 1998 23:59:25 -0500 To: "Jan B. Koum " From: "Jeffrey J. Mountin" Subject: Re: Shell history Cc: security@FreeBSD.ORG In-Reply-To: References: <199808280519.PAA04932@henry.cs.adfa.oz.au> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org At 11:05 PM 8/27/98 -0700, Jan B. Koum wrote: >On Fri, 28 Aug 1998, Warren Toomey wrote: > >>In article by Jan B. Koum: >>> What if the user would be to switch shell or to install their own? >>> I do not think one should depend on shell history to log all what >>> user does. How would YOU monitor what your users are >>> doing if you had to? >> >> accton(8), lastcomm(1) >> >> Warren >> > > Once can just "cp" the executable. But in order to 'cp' you must be able to read. Why have more permissions than needed? Jeff Mountin - Unix Systems TCP/IP networking jeff@mountin.net To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message