linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* perhaps obvious question: auditd and setuid/setgid?
@ 2015-09-02 23:06 John Jasen
  2015-09-03  2:32 ` rshaw1
  0 siblings, 1 reply; 5+ messages in thread
From: John Jasen @ 2015-09-02 23:06 UTC (permalink / raw)
  To: linux-audit

I'm currently testing auditd with rules for setuid or setgid binaries on
the system.

I currently maintain the list via find, and pushing the results to a
audit.rules file.

I'm hoping there's a cleaner way, perhaps by triggering on the
appropriate syscall -- but have not discovered it.

Is there an easier method?

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2015-09-04 17:36 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-09-02 23:06 perhaps obvious question: auditd and setuid/setgid? John Jasen
2015-09-03  2:32 ` rshaw1
2015-09-04 14:54   ` John Jasen
2015-09-04 16:20     ` Steve Grubb
2015-09-04 17:36       ` John Jasen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).