Post a Comment
Pretty great feature to be sure, and long overdue. However it's not exactly a watertight solution. It's better than nothing, but I think it would not be difficult to get around this logging, starting with firing up a different shell, or masking your commands by running them in a script.
At one time a truly excellent solution for shell auditing was the OSS project Enterprise Audit Shell, but unfortunately that project was quickly shut down when the source code was bought by some company that turned it into a commercial product.
I've always thought that taking up the last version of the source that was released and running w/it would be a great OSS project to get involved with, but I have no time for it.
I can imagine the first command that anyone who wants to get actual work done would issue would be "bash" or "zsh"
Granted the auditing is probably INTENDED as soimething to run on a server to try and catch hackers, but the potentials for abuse are, to put it mildly, immense.






