From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: AUID question
Date: Fri, 14 Nov 2014 10:26:26 -0500 [thread overview]
Message-ID: <2358445.E63IALoBCF@x2> (raw)
In-Reply-To: <OFB969D3C1.F3862AC5-ON85257D90.005352C1-85257D90.0053E147@us.ibm.com>
On Friday, November 14, 2014 10:16:12 AM David Flatley wrote:
> While checking audit logs for failed logins, It was noticed that the
> AUID was one name and there was a UID of the user that failed login. The
> only thing we can figure is that the AUID user rebooted the system
> by logging in as himself and then using sudo to reboot the system prior to
> the fails. Are we correct in this assumption?
Maybe. If the auid was someone with admin powers, they might have restarted a
daemon which would insert their auid into the daemon and then cause other
user's logins to be wrong. But generally when auid!=uid, then they have used
sudo or su.
-Steve
next prev parent reply other threads:[~2014-11-14 15:26 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-01 21:49 Remote logging with autitd Wouter van Verre
2014-11-02 18:12 ` Steve Grubb
2014-11-02 21:16 ` Wouter van Verre
2014-11-02 21:25 ` LC Bruzenak
2014-11-02 22:09 ` Wouter van Verre
2014-11-13 22:23 ` Wouter van Verre
2014-11-14 2:44 ` Steve Grubb
2014-11-14 15:16 ` AUID question David Flatley
2014-11-14 15:26 ` Steve Grubb [this message]
2014-11-18 12:21 ` Remote logging with autitd Wouter van Verre
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2358445.E63IALoBCF@x2 \
--to=sgrubb@redhat.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.