From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Mike Nixon" Subject: RE: AUDIT Rules Date: Thu, 24 May 2007 19:31:08 -0400 Message-ID: <005101c79e5b$9bb8f1b0$3301a8c0@Rascal> References: Mime-Version: 1.0 Content-Type: text/plain; charset="windows-1250" Content-Transfer-Encoding: 7bit Return-path: Received: from mx2.redhat.com (mx2.redhat.com [10.255.15.25]) by int-mx2.corp.redhat.com (8.13.1/8.13.1) with ESMTP id l4ONVNUv015127 for ; Thu, 24 May 2007 19:31:23 -0400 Received: from an-out-0708.google.com (an-out-0708.google.com [209.85.132.244]) by mx2.redhat.com (8.13.1/8.13.1) with ESMTP id l4ONVIkN003346 for ; Thu, 24 May 2007 19:31:19 -0400 Received: by an-out-0708.google.com with SMTP id c31so174430ana for ; Thu, 24 May 2007 16:31:18 -0700 (PDT) In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: 'Paul Whitney' , linux-audit@redhat.com List-Id: linux-audit@redhat.com Change the word possible to always and restart your auditd daemon. i.e. -a exit,always -S chmod -F success=0 -F success!=0 -a exit,always -S fchmod -F success=0 -F success!=0 Mike Nixon, CISSP LTC Engineering Assoc. nixon@ltceng.com -----Original Message----- From: linux-audit-bounces@redhat.com [mailto:linux-audit-bounces@redhat.com] On Behalf Of Paul Whitney Sent: Wednesday, May 23, 2007 3:05 PM To: linux-audit@redhat.com Subject: AUDIT Rules -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Can someone tell me what is the correct syntax for successfully or failing to modify a file using the chmod command? I have : - -a exit,possible -S chmod -F success=0 -F success!=0 - -a exit,possible -S fchmod -F success=0 -F success!=0 But I am not able to audit the event. As a regular user I try to change the permissions of /etc/shadow. The action fails (as expected) but does not get audited. Any suggestions is greatly appreciated. Paul Whitney Information Systems Solutions paul.whitney@mac.com -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.6 (Build 6060) iQEVAwUBRlSQSbdVg+viRqgEAQjJTAf8CHUY4lQMv7tJrdseTqe/l2n1oFwu8GNr xrIPab5+iQtRWk4OwwOnmifz1yZRyA+tO+W0hXc7UFn5c1J8YKFooAYEiTK/DvBI oE4Aeme5QDIW4MN/quq8qOeKieMUDr2oPt3ZqVW6F9u/pF/dlUaQ5OvdSchtdfLw iYMsd2rS5xtUVa0fDYEsQqz6AAaKbpuBCa6+ksxWTnPOCjYec0jpVpT3unFLA7G3 FK34zc5nfzuGimEtPb3wGvZv32wPyDDV8aD/ghw9kBYT3Fobd4LF6ZT89MbWSlja I5HW38q8elNn6an3FjWo+UV9r47tuMteIuFUatwed47yR/58xizoEg== =yBwv -----END PGP SIGNATURE----- -- Linux-audit mailing list Linux-audit@redhat.com https://www.redhat.com/mailman/listinfo/linux-audit No virus found in this incoming message. Checked by AVG Free Edition. Version: 7.5.467 / Virus Database: 269.8.0/817 - Release Date: 5/24/2007 4:01 PM No virus found in this outgoing message. Checked by AVG Free Edition. Version: 7.5.467 / Virus Database: 269.8.0/817 - Release Date: 5/24/2007 4:01 PM