<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to make a file write-able but not modifiable through editor in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336301#M342854</link>
    <description>Hi, &lt;BR /&gt;&lt;BR /&gt;Good Day!&lt;BR /&gt;&lt;BR /&gt;i wanna make .sh_history secure, like the user can't modify this file by means of any text editor or through other ways like echo output redirection commands, the purpose behind the scene is to maintain the integrity of user's command history file.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any idea?&lt;BR /&gt;&lt;BR /&gt;-Br&lt;BR /&gt;-Muhammad Ahmad</description>
    <pubDate>Tue, 13 Jan 2009 07:46:19 GMT</pubDate>
    <dc:creator>Muhammad Ahmad</dc:creator>
    <dc:date>2009-01-13T07:46:19Z</dc:date>
    <item>
      <title>how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336301#M342854</link>
      <description>Hi, &lt;BR /&gt;&lt;BR /&gt;Good Day!&lt;BR /&gt;&lt;BR /&gt;i wanna make .sh_history secure, like the user can't modify this file by means of any text editor or through other ways like echo output redirection commands, the purpose behind the scene is to maintain the integrity of user's command history file.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any idea?&lt;BR /&gt;&lt;BR /&gt;-Br&lt;BR /&gt;-Muhammad Ahmad</description>
      <pubDate>Tue, 13 Jan 2009 07:46:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336301#M342854</guid>
      <dc:creator>Muhammad Ahmad</dc:creator>
      <dc:date>2009-01-13T07:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336302#M342855</link>
      <description>you can use chatr command to change the internal attribute&lt;BR /&gt;&lt;BR /&gt;#man chatr</description>
      <pubDate>Tue, 13 Jan 2009 07:58:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336302#M342855</guid>
      <dc:creator>Jeeshan</dc:creator>
      <dc:date>2009-01-13T07:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336303#M342856</link>
      <description>chatr is for programs/libraries. &lt;BR /&gt;&lt;BR /&gt;On Linux you can do it with chatr, but i don't know something similar under HP-UX.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;ivan</description>
      <pubDate>Tue, 13 Jan 2009 08:25:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336303#M342856</guid>
      <dc:creator>Ivan Krastev</dc:creator>
      <dc:date>2009-01-13T08:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336304#M342857</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Did you try setacl (similar to setfacl for&lt;BR /&gt;Linux and Solaris)?&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;VK2COT</description>
      <pubDate>Tue, 13 Jan 2009 08:52:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336304#M342857</guid>
      <dc:creator>VK2COT</dc:creator>
      <dc:date>2009-01-13T08:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336305#M342858</link>
      <description>You can't do this.  If the shell can write to the file so can the user.&lt;BR /&gt;&lt;BR /&gt;If you want to monitor what users do, you'll have to use a different tool.</description>
      <pubDate>Tue, 13 Jan 2009 10:58:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336305#M342858</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-01-13T10:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336306#M342859</link>
      <description>I guess there is a way: after the shell is started, move the history file to a directory that is not accessible by the user... Since the shell has the file already open, it will keep on writing, but the user cannot access the file.&lt;BR /&gt;&lt;BR /&gt;I haven't tried, but it should work... It's like removing the syslog.log file without triggering the syslogd to re-create the file... It will keep on writing to the deleted file.</description>
      <pubDate>Tue, 13 Jan 2009 13:12:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336306#M342859</guid>
      <dc:creator>Elmar P. Kolkman</dc:creator>
      <dc:date>2009-01-13T13:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336307#M342860</link>
      <description>&amp;gt;Elmar: Since the shell has the file already open, it will keep on writing, but the user cannot access the file.&lt;BR /&gt;&lt;BR /&gt;I'm not sure this will work if you create a new shell by invoking a script.  It is going to want to use $HISTFILE, which isn't there.&lt;BR /&gt;</description>
      <pubDate>Wed, 14 Jan 2009 04:20:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336307#M342860</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-01-14T04:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336308#M342861</link>
      <description>No problem... It will just create a new one ;-)</description>
      <pubDate>Wed, 14 Jan 2009 05:51:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336308#M342861</guid>
      <dc:creator>Elmar P. Kolkman</dc:creator>
      <dc:date>2009-01-14T05:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336309#M342862</link>
      <description>You can always install the B1 version of Unix and all your file level security problems will go away !~)&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 14 Jan 2009 18:37:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336309#M342862</guid>
      <dc:creator>PW HP-UX Support Team</dc:creator>
      <dc:date>2009-01-14T18:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: how to make a file write-able but not modifiable through editor</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336310#M342863</link>
      <description>The .sh_history (or whatever $HISTFILE is set to) is NOT a command security tool, it is just that a "command history" for the user. The shell that writes to it IS running as the same user so in order to move it to a nonaccissible area, you have to have an SUID script/command doit as part of the login profile. And this will only make a copy of it each time the user logs in and a new one will be started in the default location. &lt;BR /&gt;To complicate the scenario think on what would happen if a user logged in on several different concurrent or overlapping sessions.&lt;BR /&gt;In any case a smart user can purge or delete the history file during the shell and as they log out so there is nothing left to look at. Or they can unset the HISTFILE as soon as they login.&lt;BR /&gt;Bottom line is don't rely on the history file for investigative work on your users. &lt;BR /&gt;Look into trusted system and user accounting setups for user command tracking.</description>
      <pubDate>Wed, 14 Jan 2009 18:54:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-make-a-file-write-able-but-not-modifiable-through-editor/m-p/4336310#M342863</guid>
      <dc:creator>TTr</dc:creator>
      <dc:date>2009-01-14T18:54:03Z</dc:date>
    </item>
  </channel>
</rss>

