31:系统命令审计脚本

 

[root@localhost_001 ~]# mkdir -p /usr/local/domob/records/
[root@localhost_001 ~]# chmod 777 /usr/local/domob/records/
[root@localhost_001 ~]# chmod o+t /usr/local/domob/records/
[root@localhost_001 ~]# vim /etc/profile
if [ ! -d  /usr/local/domob/records/${LOGNAME} ]
then
mkdir -p /usr/local/domob/records/${LOGNAME}
chmod 300 /usr/local/domob/records/${LOGNAME}
fi
export HISTORY_FILE="/usr/local/domob/records/${LOGNAME}/bash_history"
export PROMPT_COMMAND='{ date "+%Y-%m-%d %T ##### $(who am i |awk "{print \$1\" \"\$2\" \"\$5}") #### $(history 1 | { read x cmd; echo "$cmd"; })"; } >>$HISTORY_FILE'

[root@localhost_001 ~]# source /etc/profile

2、会在 /usr/local/recoreds/ 目录下,基于用户来生成文件;

[root@fenye2019 ~]# head !$
head /usr/local/records/root/bash_history
2019-03-12 18:09:57 ##### root pts/0 (111.196.244.117) #### source /etc/profile
2019-03-12 18:09:57 ##### root pts/0 (111.196.244.117) #### source /etc/profile
2019-03-12 18:09:58 ##### root pts/0 (111.196.244.117) #### ksdfj;
2019-03-12 18:10:03 ##### root pts/0 (111.196.244.117) #### cata /usr/local/records/root/bash_history
2019-03-12 18:10:08 ##### root pts/0 (111.196.244.117) #### cat /usr/local/records/root/bash_history
2019-03-12 18:10:36 ##### root pts/1 (111.196.244.117) #### 2019-03-12  18:05:27  exit
2019-03-12 18:10:45 ##### root pts/1 (111.196.244.117) #### 2019-03-12  18:05:27  exit
2019-03-12 18:10:45 ##### root pts/1 (111.196.244.117) #### 2019-03-12  18:05:27  exit
2019-03-12 18:10:46 ##### root pts/1 (111.196.244.117) #### 2019-03-12  18:10:46  ls
2019-03-12 18:13:28 ##### root pts/0 (111.196.244.117) #### cat /etc/profile

 

转载于:https://my.oschina.net/yuanhaohao/blog/3033578

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值