3 ms·
$> some_command --username myusername --password mypassword $> history ... 12345 some_command --username myusername --password mypassword This comes up fair
by nmrm 12y ago
$> some_command --username myusername --password mypassword
$> history
...
12345 some_command --username myusername --password mypassword
This comes up fairly often with poorly designed CLI's. Wiping your bash history after running the command isn't an unreasaonble hack.
Edit/Addendum: Although there are other (perhaps better) ways to achieve the same effect, the main point is that doing a "history -c" should be considered no more suspicious than e.g. closing a document to clear your "undo" history.
- zx2c4 12y agoFair enough. Though, read -p "Password: " -s password; some_command --username myusername --password "$password"
- 0x0 12y agoAlthough this avoid a .bash_history entry, this will still make the password visible to "ps ax" on most multi-user systems.
- NoodleIncident 12y agoA space before the command stops it from going in your history, though.
- ewams 12y agois that only for certain distro's because that isnt true on debian: 115 history 116 history (1 space) 117 history (2 spaces) 118 man passwd 119 passwd -a (1 space) 120 history 121 passwd -a (2 spaces) 122 history
- paxswill 12y agoIt's controlled by the HISTCONTROL variable in bash. If it contains 'ignorespace' (or 'ignoreboth' to ignore duplicates as well). Check the man page for more details.
- judk 12y agoAnyone know why this incredible hack was introduced in hr first place? In my entire career this "feature" had only caused annoyance after copy-pasting a command. Why not have a shell command called 'nohist' to wrap a command line?
- puls 12y agoYou can control this with the HISTCONTROL and HISTIGNORE environment variables: http://askubuntu.com/questions/15926/how-to-avoid-duplicate-entries-in-bash-history http://askubuntu.com/questions/15926/how-to-avoid-duplicate-...
- judk 12y agoThank you for providing something of technical value in this conversation.
- dfc 12y agoMuch to my dismay this is not true. By default debian is configured to `ignoreboth` ie dupes and spaces. Like you I also change the debian default for HISTCONTROL. Lines 11-13 of /etc/skel/.bashrc:[^1] # don't put duplicate lines or lines starting with space in the history. # See bash(1) for more options HISTCONTROL=ignoreboth [^1]: https://bazaar.launchpad.net/~doko/+junk/pkg-bash-debian/view/head:/skel.bashrc#L11 https://bazaar.launchpad.net/~doko/+junk/pkg-bash-debian/vie... Provenance for /etc/skel/.bashrc: dfc@ronin:~$ dlocate /etc/skel/ bash: /etc/skel/.bash_logout bash: /etc/skel/.bashrc bash: /etc/skel/.profile dfc@ronin:~$ apt-cache showsrc bash |grep ^Vcs- Vcs-Browser: https://code.launchpad.net/~doko/+junk/pkg-bash-debian Vcs-Bzr: http://bazaar.launchpad.net/~doko/+junk/pkg-bash-debian