EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard

An ethical hacker is performing a post-exploitation phase on a Linux server. They have achieved root access and need to remove all traces of their activity. Which of the following actions would be most effective for clearing command history and log entries related to their session, while minimizing the chance of detection by a seasoned forensic analyst?

  1. ARebooting the system into a live CD and then deleting the entire '/var/log' directory.
  2. BEditing '/var/log/auth.log' and '/var/log/syslog' directly to remove specific entries, and setting 'HISTFILE=/dev/null' for the current session.
  3. CUsing 'history -c' and then 'rm ~/.bash_history'
  4. DUsing 'shred -u /var/log/auth.log' and 'shred -u /var/log/syslog'
Show answer & explanation

Correct answer: B. Editing '/var/log/auth.log' and '/var/log/syslog' directly to remove specific entries, and setting 'HISTFILE=/dev/null' for the current session.

Directly editing log files to remove specific entries and setting HISTFILE=/dev/null (or unsetting HISTFILE) is a stealthier approach than mass deletion. 'shred' might leave a trace of its execution, and deleting entire log files or directories can be a major red flag for forensic analysts, as it creates large gaps in logs or missing files, indicating tampering.

Why the other options are wrong

  • A. Deleting the entire /var/log directory is a very obvious sign of tampering and would immediately alert a forensic analyst to malicious activity.
  • C. While it clears history, 'rm' leaves an inode record of the deletion, and doesn't address system logs.
  • D. Using 'shred' on logs is noisy; it explicitly shows an attempt to securely delete, which is a strong indicator of tampering. It also leaves the shred command in memory/history.

Clearing Linux Logs (Stealth)

Techniques used by attackers to remove or modify evidence of their presence from Linux system logs and command histories while attempting to minimize detection by forensic analysis.

  • Involves direct manipulation of log files to remove specific entries.
  • Disabling or redirecting command history logging.
  • Aims to avoid obvious signs of tampering like mass deletion of files.

Memory trick: Anti-forensics: Logs edit, History null, Timestamps touch, Rootkits hide.

More System Hacking Phases and Attack Techniques questions