[prev in list] [next in list] [prev in thread] [next in thread] 

List:       linux-audit
Subject:    RE: AUDIT Rules
From:       "Mike Nixon" <mnixxon () gmail ! com>
Date:       2007-05-24 23:31:08
Message-ID: 005101c79e5b$9bb8f1b0$3301a8c0 () Rascal
[Download RAW message or body]

Change the word possible to always and restart your auditd daemon.

	i.e.
		-a exit,always -S chmod -F success=0 -F success!=0
		-a exit,always -S fchmod -F success=0 -F success!=0

Mike Nixon, CISSP
LTC Engineering Assoc.
nixon@ltceng.com

-----Original Message-----
From: linux-audit-bounces@redhat.com [mailto:linux-audit-bounces@redhat.com]
On Behalf Of Paul Whitney
Sent: Wednesday, May 23, 2007 3:05 PM
To: linux-audit@redhat.com
Subject: AUDIT Rules

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Can someone tell me what is the correct syntax for successfully or failing
to modify a file using the chmod command?  I have :

- -a exit,possible -S chmod -F success=0 -F success!=0
- -a exit,possible -S fchmod -F success=0 -F success!=0

But I am not able to audit the event. As a regular user I try to change the
permissions of /etc/shadow. The action fails (as expected) but does not get
audited.

Any suggestions is greatly appreciated.


Paul Whitney
Information Systems Solutions
paul.whitney@mac.com

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.0.6 (Build 6060)

iQEVAwUBRlSQSbdVg+viRqgEAQjJTAf8CHUY4lQMv7tJrdseTqe/l2n1oFwu8GNr
xrIPab5+iQtRWk4OwwOnmifz1yZRyA+tO+W0hXc7UFn5c1J8YKFooAYEiTK/DvBI
oE4Aeme5QDIW4MN/quq8qOeKieMUDr2oPt3ZqVW6F9u/pF/dlUaQ5OvdSchtdfLw
iYMsd2rS5xtUVa0fDYEsQqz6AAaKbpuBCa6+ksxWTnPOCjYec0jpVpT3unFLA7G3
FK34zc5nfzuGimEtPb3wGvZv32wPyDDV8aD/ghw9kBYT3Fobd4LF6ZT89MbWSlja
I5HW38q8elNn6an3FjWo+UV9r47tuMteIuFUatwed47yR/58xizoEg==
=yBwv
-----END PGP SIGNATURE-----


--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit

No virus found in this incoming message.
Checked by AVG Free Edition. 
Version: 7.5.467 / Virus Database: 269.8.0/817 - Release Date: 5/24/2007
4:01 PM
 

No virus found in this outgoing message.
Checked by AVG Free Edition. 
Version: 7.5.467 / Virus Database: 269.8.0/817 - Release Date: 5/24/2007
4:01 PM
 

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic