清除Centos系统用户登录记录和命令记录

1
2
echo>/var/log/wtmp#清除用户登录记录和命令记录
[root @localhost root]# last //此时即查不到用户登录信息
1
2
echo>/var/log/btmp
[root @localhost root]# lastb //查不到登陆失败信息
1
echo>/var/log/secure #如果没有这个文件,重启syslog进程service syslog restart

清除历史命令

1
2
cd/root/
echo> .bash_history

或者

1
history-c #清除命令记录

也可以写个shell脚本,一键清除所有的日志

1
2
3
4
5
6
7
8
9
10
11
12
13
#!/bin/sh
cat/dev/null>/var/log/syslog
cat/dev/null>/var/adm/sylog
cat/dev/null>/var/log/wtmp
cat/dev/null>/var/log/maillog
cat/dev/null>/var/log/messages
cat/dev/null>/var/log/openwebmail.log
cat/dev/null>/var/log/maillog
cat/dev/null>/var/log/secure
cat/dev/null>/var/log/httpd/error_log
cat/dev/null>/var/log/httpd/ssl_error_log
cat/dev/null>/var/log/httpd/ssl_request_log
cat/dev/null>/var/log/httpd/ssl_access_log

你可能感兴趣的:(清除Centos系统用户登录记录和命令记录)