public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* NISPOM Auditing
@ 2008-05-21 16:01 Mathis, Jim
  2008-05-21 17:14 ` Steve Grubb
  0 siblings, 1 reply; 6+ messages in thread
From: Mathis, Jim @ 2008-05-21 16:01 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 265 bytes --]

Hello,
 
Is there a way to setup a watch log to report if a user attempted to
"cd" to a directory that they didn't have permission to access. I have
watch logs in place but it doesn't seem to report when a "cd" is
attempted and permission is denied. Thanks.
 
-Jim

[-- Attachment #1.2: Type: text/html, Size: 916 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 6+ messages in thread
* NISPOM Auditing
@ 2008-05-22 20:28 Mathis, Jim
  2008-05-22 21:19 ` Steve Grubb
  0 siblings, 1 reply; 6+ messages in thread
From: Mathis, Jim @ 2008-05-22 20:28 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1164 bytes --]

Hello,
 
I need to log file edit attempts when a user doesn't have permission to
edit a specific file. For example, a non-root user attempts to edit
"/var/log/audit/audit'log" which has a permission setting of 640.
Although the user won't be able to edit the file (permission denied) -
I'd still like to log the attempt. Here's a snippet of my audit.rules
file:
 
## unsuccessful creation

-a exit,always -S creat -S mkdir -S mknod -S link -S symlink -F exit=-13
-k creation

-a exit,always -S mkdirat -S mknodat -S linkat -S symlinkat -F exit=-13
-k creation

## unsuccessful open

-a exit,always -S open -F exit=-13 -k open

## unsuccessful close

-a exit,always -S close -F exit=-13 -k close

## unsuccessful modifications

-a exit,always -S rename -S truncate -S ftruncate -F exit=-13 -k mods

-a exit,always -S renameat -F exit=-13 -k mods

## unsuccessful deletion

-a exit,always -S rmdir -S unlink -F exit=-13 -k delete 

-a exit,always -S unlinkat -F exit=-13 -k delete

## unauthorized change directory (cd)

-a exit,always -S chdir -F path=/var/log/audit -k evil2-cd

## Watch Files

-w /var/log/audit/audit.log -p rwxa -k audit-log2

 

Thanks 

-Jim


[-- Attachment #1.2: Type: text/html, Size: 2782 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2008-05-27 14:19 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-21 16:01 NISPOM Auditing Mathis, Jim
2008-05-21 17:14 ` Steve Grubb
  -- strict thread matches above, loose matches on Subject: below --
2008-05-22 20:28 Mathis, Jim
2008-05-22 21:19 ` Steve Grubb
2008-05-27 14:00   ` corbin
2008-05-27 14:19     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox