From mboxrd@z Thu Jan 1 00:00:00 1970 From: John Jasen Subject: Re: perhaps obvious question: auditd and setuid/setgid? Date: Fri, 4 Sep 2015 10:54:47 -0400 Message-ID: <55E9B0B7.9040607@gmail.com> References: <55E780DE.80400@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Received: from mx1.redhat.com (ext-mx05.extmail.prod.ext.phx2.redhat.com [10.5.110.29]) by int-mx10.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id t84Espu6027039 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for ; Fri, 4 Sep 2015 10:54:51 -0400 Received: from mail-io0-f169.google.com (mail-io0-f169.google.com [209.85.223.169]) by mx1.redhat.com (Postfix) with ESMTPS id D74E0550D0 for ; Fri, 4 Sep 2015 14:54:49 +0000 (UTC) Received: by ioii196 with SMTP id i196so26404370ioi.3 for ; Fri, 04 Sep 2015 07:54:49 -0700 (PDT) Received: from [10.1.28.93] ([198.119.59.10]) by smtp.googlemail.com with ESMTPSA id y100sm1549366ioi.29.2015.09.04.07.54.48 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 04 Sep 2015 07:54:48 -0700 (PDT) In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com I was specifically wondering if I was missing the appropriate syscall for the use of setuid or setgid. >>From a brief examination and test, this appears to not be the case? On 09/02/2015 10:32 PM, rshaw1@umbc.edu wrote: >> I'm currently testing auditd with rules for setuid or setgid binaries on >> the system. >> >> I currently maintain the list via find, and pushing the results to a >> audit.rules file. >> >> I'm hoping there's a cleaner way, perhaps by triggering on the >> appropriate syscall -- but have not discovered it. >> >> Is there an easier method? > The find method is what I use (though I push it to a file in rules.d and > then run augenrules, which for RHEL5/6 I just stole from RHEL7). Using > find to generate these rules is actually in the text of, IIRC, at least > one of the RHEL STIGs (6, draft of 7, possibly both), though not quite as > automated as the way I do it. > > --Ray >