All of lore.kernel.org
 help / color / mirror / Atom feed
* Auditing Attemtps to run Audit commands.
@ 2010-10-05 16:30 Boyce, Kevin P (AS)
  2010-10-05 16:48 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Boyce, Kevin P (AS) @ 2010-10-05 16:30 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 672 bytes --]

Here is a silly question ( I don't know if this has been resolved in
newer releases, I am using audit-1.7.13).

 

I have an execve rule for any attempt to execute auditd for example.  I
never get any audit records when mortal users attempt to run the command
(even though they will fail).  I only see success events when the
commands are executed as root.

 

I know all of the executables that ship with the audit packages check to
see if root is executing them, but I think there is value in knowing who
might be attempting to stop the audit daemon from a security
perspective. 

 

 

Anyone have any thoughts on this?

 

Thanks,

Kevin


[-- Attachment #1.2: Type: text/html, Size: 2676 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2010-10-05 16:48 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-10-05 16:30 Auditing Attemtps to run Audit commands Boyce, Kevin P (AS)
2010-10-05 16:48 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.