All of lore.kernel.org
 help / color / mirror / Atom feed
* is it a newbie'sh question?: where is the log for violated access ?
@ 2006-05-22 17:10 Tetsuji Maverick Rai
  2006-05-22 17:36 ` Stephen Smalley
  0 siblings, 1 reply; 3+ messages in thread
From: Tetsuji Maverick Rai @ 2006-05-22 17:10 UTC (permalink / raw)
  To: selinux

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi all,

I thought when an access violation occurs, it's logged in
/var/log/audit.log or messages, but it doesn't look so.

For example, If I invoke "su apache -c "cat /etc/passwd" as root which
will cause access error because apache user isn't allowed to use cat,
but I cannot find any violation log in any of the log files above.

Actually it's prohibited by selinux: ie.
as a root "su apache -c 'cat /etc/passwd'" will say nothing, while
"su maverick -c 'cat /etc/passwd'" (maverick is a normal user) displays
contents of /etc/passwd.  I think it's a form of access violation but
this isn't logged anywhere.   Will anyone tell me why or where it's logged?

Thanks in advance.

- -Tetsuji
- --
Tetsuji 'Maverick' Rai
Main http://maverick6664.bravehost.com/
Profile:
http://setiweb.ssl.berkeley.edu/beta/view_profile.php?userid=123
pubkey http://mav.atspace.com/tmr_at_gmail.txt
PGP Key ID: 82335CD9
Key fingerprint = 41CA 94B4 2A89 3FF1 5B11  BC37 D597 E667 8233 5CD9

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFEcfB51ZfmZ4IzXNkRAvHFAKDHHpesYfMN3s09kE7fjVmrcDPwtQCeOIH/
lO4DvEl/aJi7jcjqMD4BhRs=
=KWSB
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2006-05-22 18:03 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-22 17:10 is it a newbie'sh question?: where is the log for violated access ? Tetsuji Maverick Rai
2006-05-22 17:36 ` Stephen Smalley
2006-05-22 18:02   ` Tetsuji Maverick Rai

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.