nitter
Andrew Case
@attrc
9 Sep 2012
Month of
@volatility
plugins teaser: Recovering .bash_history from memory, even in the face of anti-forensics:
pastebin.com/Pj39TMrU
#dfir
3
13
7
Hal Pomeranz
@hal_pomeranz
9 Sep 2012
Replying to
@attrc
@attrc
Does it only work if history timestamps are enabled?
Sep 9, 2012 · 10:19 PM UTC
1
Andrew Case
@attrc
9 Sep 2012
Replying to
@hal_pomeranz
@hal_pomeranz
nope, that's the awesome part, bash keeps them anyway
1
Hal Pomeranz
@hal_pomeranz
9 Sep 2012
@attrc
Ah, I gotcha-- identifying the bash processes and sucking the history out?
2
more replies