From mboxrd@z Thu Jan 1 00:00:00 1970 From: John Jasen Subject: perhaps obvious question: auditd and setuid/setgid? Date: Wed, 2 Sep 2015 19:06:06 -0400 Message-ID: <55E780DE.80400@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Received: from mx1.redhat.com (ext-mx07.extmail.prod.ext.phx2.redhat.com [10.5.110.31]) by int-mx13.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id t82N69E6027611 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for ; Wed, 2 Sep 2015 19:06:09 -0400 Received: from mail-qg0-f44.google.com (mail-qg0-f44.google.com [209.85.192.44]) by mx1.redhat.com (Postfix) with ESMTPS id 54D1EC0A15EB for ; Wed, 2 Sep 2015 23:06:08 +0000 (UTC) Received: by qgt47 with SMTP id 47so16305683qgt.2 for ; Wed, 02 Sep 2015 16:06:07 -0700 (PDT) Received: from [10.0.0.230] (pool-71-244-242-131.bltmmd.fios.verizon.net. [71.244.242.131]) by smtp.googlemail.com with ESMTPSA id b50sm13743046qgb.9.2015.09.02.16.06.06 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Sep 2015 16:06:07 -0700 (PDT) List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com I'm currently testing auditd with rules for setuid or setgid binaries on the system. I currently maintain the list via find, and pushing the results to a audit.rules file. I'm hoping there's a cleaner way, perhaps by triggering on the appropriate syscall -- but have not discovered it. Is there an easier method?