LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-01-2010, 04:29 PM   #1
jholp
LQ Newbie
 
Registered: Jan 2010
Posts: 13

Rep: Reputation: 0
Need to audit created files and deleted files


I have a request for auditing on passive "listening" machines. The customer wants to audit file creation and deletion.

-a exit, always -S mkdir -S rmdir

Should work for directories

But how would one gracefully audit the creation and deletion of files ?
I asume it would be system call when one does a touch, vi, etc. for creating.

I assume they would want the UID of the person that did the creating and deleting, along with year, month, date, hour, minute, second.

Any ideas?

Thanks,

John
 
Old 09-01-2010, 05:41 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by jholp View Post
I have a request for auditing on passive "listening" machines.
Sounds intriguing but I wonder if it has anything to do with /etc/audit/audit.rules?..


Quote:
Originally Posted by jholp View Post
But how would one gracefully audit the creation and deletion of files ?
From readlink -f /lib/modules/$(uname -r)/build)/include/asm-i386/unistd.h see creat, open, unlink?


Quote:
Originally Posted by jholp View Post
I assume they would want the UID of the person that did the creating and deleting, along with year, month, date, hour, minute, second.
Are you sure you want to assume things? Y'know.. ;-p Anyway, 'auditctl' your rules adding an appropriate key (making it easier to do 'ausearch --interpret --key') then watch your /var/log/audit/audit.log. UNIX Epoch, UID fields, they're all there. Also see 'aureport'.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Deleted files on a SMB-share - Files gone, space still allocated - Fedora 10 Zwentendorf Linux - Server 4 03-01-2009 05:04 AM
LXer: Linux audit files to see who made changes to a file LXer Syndicated Linux News 0 03-21-2007 12:33 AM
Mepis, copy files to thumb drive, files deleted? vremenno Linux - Newbie 6 09-15-2006 11:21 PM
removing last created files Prasun1 Linux - General 7 09-25-2005 07:31 PM
How to delete the destination files while the source files deleted in cp -u ? myunicom Linux - General 4 09-26-2003 01:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration