<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auditing broken? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602262#M755635</link>
    <description>There's nothing special I can in his userid...&lt;BR /&gt;&lt;BR /&gt;# id ouellemi&lt;BR /&gt;uid=334(ouellemi) gid=126(cdb_dba) groups=20(users),25(sybase),30(cdb_dev),37(dl_admin),40(trfas400),124(cdb_dev2),127(cdb_sqr),128(cdb_ext),140(das),170(db_batch),29(oper)&lt;BR /&gt;&lt;BR /&gt;... and there was nothing special made after running wtmpfix.</description>
    <pubDate>Wed, 31 Oct 2001 17:49:52 GMT</pubDate>
    <dc:creator>Jacques Larouche</dc:creator>
    <dc:date>2001-10-31T17:49:52Z</dc:date>
    <item>
      <title>Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602256#M755629</link>
      <description>Because of a problem with lost files, I activated the Events Auditing on one of our server, especially for the "delete" event type.  The result is totally wrong gives me such output:&lt;BR /&gt;fbsql011:/.secure/etc# sam &amp;amp;&lt;BR /&gt;[1]     16478&lt;BR /&gt;fbsql011:/.secure/etc# audisp -e delete audfile1&lt;BR /&gt;All users are selected.&lt;BR /&gt;Selected the following events:&lt;BR /&gt;delete&lt;BR /&gt;2048 &lt;BR /&gt;All ttys are selected.&lt;BR /&gt;Selecting successful &amp;amp; failed events.&lt;BR /&gt;TIME              PID E  EVENT   PPID    AID       RUID       RGID       EUID       EGID TTY&lt;BR /&gt;&lt;BR /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;BR /&gt;011026 11:17:33 14785 S    137  12764     16          0          3          0          3 ttyp2&lt;BR /&gt;[ Event=rmdir; User=ouellemi; Real Grp=sys; Eff.Grp=sys;  ]&lt;BR /&gt;&lt;BR /&gt;     RETURN_VALUE 1 = 0; &lt;BR /&gt;     PARAM #1 (file path) = 0 (cnode);&lt;BR /&gt;                            0x40000008 (dev);&lt;BR /&gt;                            3824 (inode);&lt;BR /&gt;              (path) = /var/sam/core&lt;BR /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;BR /&gt;&lt;BR /&gt;The User mentionned is a valid user, but wasn't logged on the system at that time. ttyp2 is my own tty and i'm not 'ouellemi'!&lt;BR /&gt;Deleting myself a file doesn't update that event log.&lt;BR /&gt;&lt;BR /&gt;Strange...</description>
      <pubDate>Fri, 26 Oct 2001 14:56:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602256#M755629</guid>
      <dc:creator>Jacques Larouche</dc:creator>
      <dc:date>2001-10-26T14:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602257#M755630</link>
      <description>Are you sure that that user doesn't have a cronjob running to clean up core files?&lt;BR /&gt;&lt;BR /&gt;And have you checked that your uid is not that same as that user?&lt;BR /&gt;&lt;BR /&gt;Finally, you should check that root isn't automatically excluded from auditing...&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;James</description>
      <pubDate>Tue, 30 Oct 2001 16:23:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602257#M755630</guid>
      <dc:creator>James Beamish-White</dc:creator>
      <dc:date>2001-10-30T16:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602258#M755631</link>
      <description>Yes James, i've checked all that!</description>
      <pubDate>Tue, 30 Oct 2001 21:35:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602258#M755631</guid>
      <dc:creator>Jacques Larouche</dc:creator>
      <dc:date>2001-10-30T21:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602259#M755632</link>
      <description>What groups does the user ouellemi belong to? What is their UID? Do they have AT jobs running? Are there any scripts that they have ownership of that are being executed by cron? Or maybe they have a setuid bit set on a script under their name?&lt;BR /&gt;&lt;BR /&gt;You could also have corrupt tmp files. What does "last" show for that user?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Wed, 31 Oct 2001 03:24:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602259#M755632</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-10-31T03:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602260#M755633</link>
      <description>I checked the wtmp file with the "last" command and as I tought, that user never logged on.  And he had nothing running under cron or at too.  I decided to get rid of that account, so I got him off the passwd file.  Now the same audit result shows me root as the uid, instead of ouellemi.  I know that that doesn't explain too much, but at least it works better now (until that user asks me for an account one day!)&lt;BR /&gt;&lt;BR /&gt;Jacques</description>
      <pubDate>Wed, 31 Oct 2001 17:14:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602260#M755633</guid>
      <dc:creator>Jacques Larouche</dc:creator>
      <dc:date>2001-10-31T17:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602261#M755634</link>
      <description>What was their UID and GID?&lt;BR /&gt;&lt;BR /&gt;I'm thinking maybe you have corrupt wtmp, utmp, or btmp files. Which one, I have no clue, but I'm sure someone can tell us. Look into the wtmpfix command.  It just might have screwed up records.&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Wed, 31 Oct 2001 17:35:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602261#M755634</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-10-31T17:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing broken?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602262#M755635</link>
      <description>There's nothing special I can in his userid...&lt;BR /&gt;&lt;BR /&gt;# id ouellemi&lt;BR /&gt;uid=334(ouellemi) gid=126(cdb_dba) groups=20(users),25(sybase),30(cdb_dev),37(dl_admin),40(trfas400),124(cdb_dev2),127(cdb_sqr),128(cdb_ext),140(das),170(db_batch),29(oper)&lt;BR /&gt;&lt;BR /&gt;... and there was nothing special made after running wtmpfix.</description>
      <pubDate>Wed, 31 Oct 2001 17:49:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-broken/m-p/2602262#M755635</guid>
      <dc:creator>Jacques Larouche</dc:creator>
      <dc:date>2001-10-31T17:49:52Z</dc:date>
    </item>
  </channel>
</rss>

