LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-18-2010, 05:17 PM   #1
mccartjd
Member
 
Registered: Apr 2008
Posts: 108

Rep: Reputation: 15
Cool audit.rules statement entered from


I am new to linux so maybe I'm misunderstanding somthing. After copying from /usr/share/doc/audit-1.7.7/nispom.rules to /etc/audit/audit.rules I can perform a ausearch on items that have a
-w flag:

-w /etc/localtime -p wa -k TIME_CHANGE

ausearch –k TIME_CHANGE

however items that have a -a flag

-a exit,always -F arch=b64 -S rmdir -S unlink -F exit=-EACCES -k delete

I perform a ausearch -k delete after I provoked a rmdir that of course failed however the ausearch response is somthing like "no match found". Should it have reported an attempt to delte a folder was made and failed?

Am I missing somthing or is this somthing I misunderstood. I thought if I attempted to delete a folder or directory (and failed) it would find the event and report back after perform an ausearch.

Thanks
John
 
Old 02-18-2010, 05:32 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Add a '-a entry,always -S rmdir -S unlink -k delete' rule and test to see if that works?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I read the audit time stamp? msg=audit(1213186256.105:20663) abefroman Linux - Software 3 04-21-2011 06:37 PM
Confused about a statement in the rules csvan LQ Suggestions & Feedback 8 09-03-2009 05:26 PM
Problem with if statement in a find -exec statement romsieze Programming 2 10-02-2008 12:38 AM
cat: /etc/udev/rules.d/70-persistent-net.rules: No such file or directory rcg1984 Linux From Scratch 2 09-17-2008 07:02 AM
/etc/audit.rules - Error sending watch insert request Linux_Learner[LL] Linux - Security 2 07-16-2006 07:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration