Skip to content
This repository has been archived by the owner on Apr 17, 2023. It is now read-only.

V-72095 Does not Check for Blanket auditd Rules #62

Open
Bialogs opened this issue Feb 11, 2019 · 1 comment
Open

V-72095 Does not Check for Blanket auditd Rules #62

Bialogs opened this issue Feb 11, 2019 · 1 comment

Comments

@Bialogs
Copy link
Member

Bialogs commented Feb 11, 2019

This check finds all setuid and setgid programs on the system and attempts to match them with an auditd rule. However, this does not account for blanket rules such as the ones SIMP creates with the auditd:: audit_suid_sgid parameter.

This check could be updated to describe.one either the blanket rule or the individual rules.

@trevor-vaughan
Copy link
Member

I think this is a good idea. Also, if you check for the blanket rule, you can prevent trolling the entire filesystem which would be great.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants