Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Bypassing audit's file watches
@ 2006-07-07 14:58 Steve
  2006-07-07 15:59 ` Timothy R. Chavez
  2006-07-08  2:00 ` Amy Griffis
  0 siblings, 2 replies; 9+ messages in thread
From: Steve @ 2006-07-07 14:58 UTC (permalink / raw)
  To: linux-audit

I have found that I can modify files that are being watched and audit 
not catch it (ie. no events are dispatched).  When monitoring a file for 
all system calls, I can:

echo "" > /file/to/watch

or

cat some_file > /file/to/watch

without generating audit events.  I assume this has to do with how the 
kernel handles re-direction.  Is it possible to catch these modifications?

Thanks,
Steve

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2006-07-11 15:07 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-07-07 14:58 Bypassing audit's file watches Steve
2006-07-07 15:59 ` Timothy R. Chavez
2006-07-07 16:08   ` Michael C Thompson
2006-07-07 16:20     ` Michael C Thompson
2006-07-08  2:00 ` Amy Griffis
2006-07-10 11:32   ` Steve
2006-07-10 22:31     ` Amy Griffis
2006-07-11 15:07       ` Michael C Thompson
2006-07-10 15:16   ` Timothy R. Chavez

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox