Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 6 Jan 2013 23:25:16 +0100
From:      Patrick Proniewski <patpro@patpro.net>
To:        Mike Tancsa <mike@sentex.net>
Cc:        "freebsd-security@freebsd.org" <freebsd-security@freebsd.org>
Subject:   Re: audit events confusion
Message-ID:  <27758D4F-14E0-4BEB-AF89-E78D75FD89D7@patpro.net>
In-Reply-To: <50E9F6A8.5050502@sentex.net>
References:  <50E9F6A8.5050502@sentex.net>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
On 06 janv. 2013, at 23:11, Mike Tancsa wrote:

> But if I make a simple php script to try and connect out, again, pflog0
> blocks it and logs it, but it does not show up in the audit logs
> 
> 17:07:46.518501 rule 433/0(match): block out on em0: 64.7.xx.xx.36528 >
> 8.8.8.8.25: Flags [S], seq 1724105073, win 65535, options [mss
> 1460,nop,wscale 3,sackOK,TS val 177324430 ecr 0], length 0
> 
> Any idea what I am missing ?

I think auditd can catch events only for users that have logged in at least once. To audit Apache, I've had to install setaudit and launch httpd process by using setaudit with proper flags.
I've modified my /usr/local/etc/rc.d/apache22 file, mainly changing the start command to start_cmd="apache22_auditstart" and adding the proper command definition:

apache22_auditstart() {
        echo "Starting apache22 with audit"
        eval /usr/local/sbin/setaudit ${apache22_auditflags} ${command} ${apache22_flags} -k start 
}

In /etc/rc.conf, I've added:

apache22_auditflags="-a www -m ex,lo,ad,-pc,fd,-fc,-fm,-fw"

I'm then able to log audit events for Apache, according to flags I've set in apache22_auditflags.

hope this helps,
patpro
[-- Attachment #2 --]
0	*H
010	+0	*H

M0400
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
071024210155Z
171024210155Z010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0"0
	*H
0
	-).2AUGo#G
B|NDRpM-B=o-we5JQpa>O.#._<V
[~**pz~3WG.ᘟMlr[<Ce6fqO"uxfWN#uicgkv$Lb%y`_{`xK'GN00U00U0USr풜\|~5NԸQ0U#0N@[i04hCA0f+Z0X0'+0http://ocsp.startssl.com/ca0-+0!http://www.startssl.com/sfsca.crt0[UT0R0'%#!http://www.startssl.com/sfsca.crl0'%#!http://crl.startssl.com/sfsca.crl0U y0w0u+70f0.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0
	*H

}x,\c^#wMq}>UK/^yX֏y	frMIŲB61ymQ󸟆ҨݬZ0&;@#13qۑ&	̢o	6r_;GO>*I(	74XS1r3)!LJy6Kotˆ#
_wSr
;B
ADp(fs䰷6%.W0J3:bC<8t X1<Cn=t==wST~\wkBf|15zUP)(IjVB!OfI=bb\4-*em/нSJm7N[]'@ڽD9Kr>R7/|o^I@ټ'Pa$ z9a'L)(
I}vcH]۸D*W}
m>Q|C.(,lQ00
D0
	*H
010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0
121004043928Z
131004184306Z0Y10U
zm88vYvifJz4tIj910Upatpro@patpro.net1 0	*H
	patpro@patpro.net0"0
	*H
0
Ϟ4*7.'4$iZ
z/'O^;x}1aXH'1D2CT)+dIjHs2rwx||6xlS?$vu!+P
4<ę6@FAaF:X:F0Xf|}
U?6N,)7NΗ<Kp3}`jk(-7pg62ޤ00	U00U0U%0++0U(50.h
;J0U#0Sr풜\|~5NԸQ0U0patpro@patpro.net0!U 00+700.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.0+00' StartCom Certification Authority0dLiability and warranties are limited! See section "Legal and Limitations" of the StartCom CA policy.06U/0-0+)'%http://crl.startssl.com/crtu1-crl.crl0+009+0-http://ocsp.startssl.com/sub/class1/client/ca0B+06http://aia.startssl.com/certs/sub.class1.client.ca.crt0#U0http://www.startssl.com/0
	*H
3aCY0~
V$W:¾B#5K5au=iIQ.jKvb`x=.E%UzO/A4ţ}gP+>[)=ꯊ&w@Urd)֜s߫@ec
 M$v7~_*6%޹m>T^?`3|sg/q/4<(~^*_'PfR=k/[,dk+
,]vm1o0k0010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA
D0	+0	*H
	1	*H
0	*H
	1
130106222517Z0#	*H
	1*L~$ae80	+710010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA
D0*H
	1010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA
D0
	*H
w9xjhޒ;3٣2ĐI	'N7pC_R</DCڜTqF1`\l-0?]ɿ6HIU_]",z"Ԉ`
y"NaQV0cR_rںҜuj0ESr֍xWtlzlih<s9ˢS`ݞkp0C-˨%QGd
help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?27758D4F-14E0-4BEB-AF89-E78D75FD89D7>