public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* AUDIT Rules
@ 2007-05-23 19:04 Paul Whitney
  2007-05-23 19:10 ` Steve Grubb
  2007-05-24 23:31 ` Mike Nixon
  0 siblings, 2 replies; 4+ messages in thread
From: Paul Whitney @ 2007-05-23 19:04 UTC (permalink / raw)
  To: linux-audit

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Can someone tell me what is the correct syntax for successfully or failing
to modify a file using the chmod command?  I have :

- -a exit,possible -S chmod -F success=0 -F success!=0
- -a exit,possible -S fchmod -F success=0 -F success!=0

But I am not able to audit the event. As a regular user I try to change the
permissions of /etc/shadow. The action fails (as expected) but does not get
audited.

Any suggestions is greatly appreciated.


Paul Whitney
Information Systems Solutions
paul.whitney@mac.com

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.0.6 (Build 6060)

iQEVAwUBRlSQSbdVg+viRqgEAQjJTAf8CHUY4lQMv7tJrdseTqe/l2n1oFwu8GNr
xrIPab5+iQtRWk4OwwOnmifz1yZRyA+tO+W0hXc7UFn5c1J8YKFooAYEiTK/DvBI
oE4Aeme5QDIW4MN/quq8qOeKieMUDr2oPt3ZqVW6F9u/pF/dlUaQ5OvdSchtdfLw
iYMsd2rS5xtUVa0fDYEsQqz6AAaKbpuBCa6+ksxWTnPOCjYec0jpVpT3unFLA7G3
FK34zc5nfzuGimEtPb3wGvZv32wPyDDV8aD/ghw9kBYT3Fobd4LF6ZT89MbWSlja
I5HW38q8elNn6an3FjWo+UV9r47tuMteIuFUatwed47yR/58xizoEg==
=yBwv
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2007-05-24 23:31 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-05-23 19:04 AUDIT Rules Paul Whitney
2007-05-23 19:10 ` Steve Grubb
2007-05-24 13:03   ` Curtis, TS Troy @ IS
2007-05-24 23:31 ` Mike Nixon

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox