Skip to content

Comment on /bin/sh: the biggest Unix security loophole (1984) [pdf]parent

Comments

> What do you need to do and what do the (even audit) logs say about who performed an activity whenever administrative activity happens? By activity you mean who run some process? doesn't enabling audit on all execve, execveat and looking at AUID besides EUID and UID fields tell you that? Or am I missing something? you may want to configure ENHANCED format in auditd for convenience.

No, you are right. On Linux you can look at AUID. To be fair, I have no idea about others than Linux.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.