mailing.freebsd.audit
  Home FAQ Contact Sign in
mailing.freebsd.audit only
 
Advanced search
April 2008
motuwethfrsasuw
 123456 14
78910111213 15
14151617181920 16
21222324252627 17
282930     18
2008
 Jan   Feb   Mar   Apr 
 May   Jun   Jul   Aug 
 Sep   Oct   Nov   Dec 
2008 2007 2006  
total
mailing.freebsd.audit Profile…
RELATED GROUPS

POPULAR GROUPS

more...

 Up
  audit_class for segfaults?         


Author: Jon Passki
Date: Apr 24, 2008 06:32

Hey All,

I guess I'm being dense here, but would I audit against the "pc"
audit_class if I want to catch segfaults?

--
Cheers,

Jon Passki, Partner
The Hursk Group, LLC

"Obvia conspicimus, nubem pellente Mathesi."

e: jon.passki@hursk.com
ph: 651/222.3020
cal: http://www.google.com/calendar/hosted/hursk.com/embed?src=jon.passki%%40hursk.co...
pgp: 1BB0 A946 927B 93C3 ED6A 0466 6692 6C2C 84BE 4122
_______________________________________________
freebsd-audit@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-audit
To unsubscribe, send any mail to "freebsd-audit-unsubscribe@freebsd.org"
no comments
  ohio female vocalists female hotties stomach female play urethral         


Author: nikkiempg
Date: Mar 24, 2008 11:08

Show full article (23.10Kb)
no comments
  more auditpipe devices         


Author: sam
Date: Mar 21, 2008 01:20

Hello,

please, the following is noteworthy:

-----------------------------------------------------------------
# ls /dev
acpi auditpipe171 auditpipe248 auditpipe4 devctl
apm auditpipe172 auditpipe249 auditpipe40...
Show full article (6.32Kb)
no comments
  Re: audit (OpenBSM) & cat         


Author: Robert Watson
Date: Mar 6, 2008 08:22

On Fri, 8 Feb 2008, sam wrote:
> description of trouble situation on system FreeBSD 6.3-RELEASE i386:
>
> open 2 putty console on remote server
>
> console1: # cat /dev/auditpipe | praudit -l
>
> console2: # cat >> /var/log/audit_cat...
Show full article (3.00Kb)
no comments
  Me doing my sister         


Author: yenc
Date: Mar 1, 2008 11:18

PORNOLATION RELEASE
no comments
  Re: OpenBSM & Jails         


Author: Robert Watson
Date: Feb 27, 2008 11:37

On Thu, 21 Feb 2008, sam wrote:
> i am using OpenBSM on System with jails
>
> part of praudit output / action write file in jail
>
> --------------------------------------------------
> header,176,10,open(2) - write,creat,trunc,0,Thu Feb 21 13:45:06 2008, + 501
> msec,argument,3,0x81ed,mode,argument,2,0x601,flags,path,//site/svn/dev.lineage2.dom/pamm/hooks/post-commit,attribute,755,www,www,88,800911,3234053,subject,lynx,root,wheel,root,wheel,44680,44668,56876,10.15.1.116,return,success,4,trailer,176,
> --------------------------------------------------
>
> please add jail-identification in output (cat /dev/auditpipe | praudit -lp)

Vladimir,

I believe Christian has plans to use the Solaris "zone" BSM token to this end,
as well as plans to enhance our support for hostid header fields so that when
audit trails are aggregated from many sources, they can be processed with
awareness of which source they came from. I've added him to the CC line, and
he may be able to expand on this.
Show full article (1.28Kb)
no comments
  OpenBSM & Jails         


Author: sam
Date: Feb 21, 2008 04:50

hello

i am using OpenBSM on System with jails

part of praudit output / action write file in jail

--------------------------------------------------
header,176,10,open(2) - write,creat,trunc,0,Thu Feb 21 13:45:06 2008, +
501
msec,argument,3,0x81ed,mode,argument,2,0x601,flags,path,//site/svn/dev.lineage2.dom/pamm/hooks/post-commit,attribute,755,www,www,88,800911,3234053,subject,lynx,root,wheel,root,wheel,44680,44668,56876,10.15.1.116,return,success,4,trailer,176,
--------------------------------------------------

please add jail-identification in output (cat /dev/auditpipe | praudit -lp)

/Vladimir Ermakov

_______________________________________________
freebsd-audit@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-audit
To unsubscribe, send any mail to "freebsd-audit-unsubscribe@freebsd.org"
no comments
  While thousands complain,         


Author: hribekt
Date: Feb 18, 2008 20:45

Stay man even when drunk! http://mouitz.quickwant.com

_______________________________________________
freebsd-audit@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-audit
To unsubscribe, send any mail to "freebsd-audit-unsubscribe@freebsd.org"
no comments
  Re: audit (OpenBSM) & cat         


Author: sam
Date: Feb 8, 2008 04:09

sam wrote:
>
> description of trouble situation on system FreeBSD 6.3-RELEASE i386
>
>
my /etc/security/audit_control

dir:/var/audit
flags:^all
minfree:20
naflags:^all
policy:cnt
filesz:0

/Vladimir Ermakov

_______________________________________________
freebsd-audit@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-audit
To unsubscribe, send any mail to "freebsd-audit-unsubscribe@freebsd.org"
no comments
  audit (OpenBSM) & cat         


Author: sam
Date: Feb 8, 2008 02:50

hi all

description of trouble situation on system FreeBSD 6.3-RELEASE i386:

open 2 putty console on remote server

console1:
# cat /dev/auditpipe | praudit -l

console2:
# cat >> /var/log/audit_cat.data

console1 (output message):
# cat /dev/auditpipe | praudit -l
header,168,10,open(2) - write,creat,0,Fri Feb 8 12:59:34 2008, + 309
msec,argument,3,0x1b6,mode,argument,2,0x209,flags,path,/var/log/audit_cat.data,attribute,644,root,admin,72,2732063,10952279,subject,venom,root,wheel,root,wheel,44255,41955,1647,192.168.1.26,return,success,4,trailer,168,

after 30 seconds

console2 (cat waiting user input & user typing message & pusshing
'Ctrl+d' for deattach ):
# cat >> /var/log/audit_cat.data
abracadabra_message
#
Show full article (1.54Kb)
no comments
 
1 2 3 4 5