All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: AUID question
Date: Fri, 14 Nov 2014 10:26:26 -0500	[thread overview]
Message-ID: <2358445.E63IALoBCF@x2> (raw)
In-Reply-To: <OFB969D3C1.F3862AC5-ON85257D90.005352C1-85257D90.0053E147@us.ibm.com>

On Friday, November 14, 2014 10:16:12 AM David Flatley wrote:
>    While checking audit logs for failed logins, It was noticed that the
> AUID was one name and there was a UID of the user that failed login. The
> only thing we can figure is that the AUID user rebooted the system
> by logging in as himself and then using sudo to reboot the system prior to
> the fails. Are we correct in this assumption?

Maybe. If the auid was someone with admin powers, they might have restarted a 
daemon which would insert their auid into the daemon and then cause other 
user's logins to be wrong. But generally when auid!=uid, then they have used 
sudo or su.

-Steve

  reply	other threads:[~2014-11-14 15:26 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-01 21:49 Remote logging with autitd Wouter van Verre
2014-11-02 18:12 ` Steve Grubb
2014-11-02 21:16   ` Wouter van Verre
2014-11-02 21:25     ` LC Bruzenak
2014-11-02 22:09       ` Wouter van Verre
2014-11-13 22:23     ` Wouter van Verre
2014-11-14  2:44       ` Steve Grubb
2014-11-14 15:16         ` AUID question David Flatley
2014-11-14 15:26           ` Steve Grubb [this message]
2014-11-18 12:21         ` Remote logging with autitd Wouter van Verre

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2358445.E63IALoBCF@x2 \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.