Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Env variables are exposed via the /proc filesystem.

I’d just unset histsize and histfile cars for the duration of doing sensitive stuff.



> Env variables are exposed via the /proc filesystem.

Sure, but only your user can read it. How bad is the exposure, really?


If your account gets compromised attackers can use the details from the history to move laterally in the network, because if you have passwords etc in the history then the attackers have access to it as well.

This is especially true for bridge / bastion systems that control access to internal servers. If the passwords/secrets to access the internal servers are in the history they get compromised as well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: