<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"> <html> <head> <style type="text/css"> body { font-size: 82%; color:#000000; background-color:white; margin:0px; } h1.report_title { margin-top:0px; margin-bottom:5px; font-size:110%; padding-top:0px; padding-bottom:1px; padding-left:4px; color:#ffffff; text-align:left; background-color:#808080; } h2.standard_section_title { margin-top:0px; margin-bottom:5px; font-size:100%; padding-top:0px; padding-bottom:1px; padding-left:0px; color:black; background-color:transparent; } h2.custom_section_title { margin-top:0px; margin-bottom:5px; font-size:100%; padding-top:0px; padding-bottom:1px; padding-left:0px; color:black; background-color:transparent; } font.message_count_label { color: #000000; background-color:transparent; } b.message_count { color: #000000; background-color:transparent; } font.stats_label { color: #000000; background-color:transparent; } b.stats_count { color: #000000; background-color:transparent; } b.report_date { color: #000000; background-color:transparent; } font.message_date { color: black; background-color:transparent; position:relative } font.host_name { color: #000000; background-color:transparent; } font.syscall_timestamp { color: #000000; background-color:transparent; } font.avc_deny { color:red; background-color:transparent; } font.avc_grant { color:green; background-color:transparent; } font.exe { color: #000000; background-color:transparent; } font.path { color: blue; background-color:transparent; } font.src_context { color:black; background-color:transparent; font-weight: bold } font.tgt_context { color:black; background-color:transparent; font-weight: bold } font.obj_class { color: #000000; background-color:transparent; } </style> <title>seaudit-report</title> </head> <body> <b class="report_date"># Report generated by seaudit-report on Sat Oct 30 10:54:17 2004 </b><br> <h1 class="report_title">Title: SEAudit Log Report</h1> <h2 class="standard_section_title"><u>Log Statistics</h2></u> <font class="stats_label">Number of total messages:</font> <b class="stats_count">42</b><br> <font class="stats_label">Number of policy load messages:</font> <b class="stats_count">8</b><br> <font class="stats_label">Number of policy boolean messages:</font> <b class="stats_count">5</b><br> <font class="stats_label">Number of allow messages:</font> <b class="stats_count">11</b><br> <font class="stats_label">Number of denied messages:</font> <b class="stats_count">22</b><br> <br> <h2 class="standard_section_title"><u>Policy Loads</h2></u> <font class="message_count_label">Number of messages:</font> <b class="message_count">8</b><br> <br> <font class="message_date">Oct 25 09:24:43 </font><font class="host_name">xavier </font>kernel: security: 3 users, 4 roles, 280 types, 16 bools<br> <font class="message_date">Oct 25 09:24:43 </font><font class="host_name">xavier </font>kernel: security: 53 classes, 5345 rules<br> <font class="message_date">Oct 25 10:23:52 </font><font class="host_name">xavier </font>kernel: security: 3 users, 4 roles, 280 types, 16 bools<br> <font class="message_date">Oct 25 10:23:52 </font><font class="host_name">xavier </font>kernel: security: 53 classes, 5345 rules<br> <font class="message_date">Oct 25 10:41:58 </font><font class="host_name">xavier </font>kernel: security: 3 users, 4 roles, 280 types, 16 bools<br> <font class="message_date">Oct 25 10:41:58 </font><font class="host_name">xavier </font>kernel: security: 53 classes, 5345 rules<br> <font class="message_date">Oct 26 16:02:30 </font><font class="host_name">xavier </font>kernel: security: 3 users, 4 roles, 280 types, 16 bools<br> <font class="message_date">Oct 26 16:02:30 </font><font class="host_name">xavier </font>kernel: security: 53 classes, 5345 rules<br> <br> <h2 class="standard_section_title"><u>Enforcement mode toggles</h2></u> <font class="message_count_label">Number of messages:</font> <b class="message_count">0</b><br> <br> <br> <h2 class="standard_section_title"><u>Policy boolean changes</h2></u> <font class="message_count_label">Number of messages:</font> <b class="message_count">5</b><br> <br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: security: committed booleans: { httpd_unified:1, httpd_enable_cgi:1, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_disable_trans:0, dhcpd_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nscd_disable_trans:0, ntpd_disable_trans:0, portmap_disable_trans:0, snmpd_disable_trans:0, squid_disable_trans:0, syslogd_disable_trans:0, ypbind_disable_trans:0, allow_ypbind:1 }<br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: security: committed booleans: { httpd_unified:1, httpd_enable_cgi:1, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_disable_trans:0, dhcpd_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nscd_disable_trans:0, ntpd_disable_trans:0, portmap_disable_trans:0, snmpd_disable_trans:0, squid_disable_trans:0, syslogd_disable_trans:0, ypbind_disable_trans:0, allow_ypbind:1 }<br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: security: committed booleans: { httpd_unified:1, httpd_enable_cgi:1, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_disable_trans:0, dhcpd_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nscd_disable_trans:0, ntpd_disable_trans:0, portmap_disable_trans:0, snmpd_disable_trans:0, squid_disable_trans:0, syslogd_disable_trans:0, ypbind_disable_trans:0, allow_ypbind:1 }<br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: security: committed booleans: { httpd_unified:1, httpd_enable_cgi:1, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_disable_trans:0, dhcpd_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nscd_disable_trans:0, ntpd_disable_trans:0, portmap_disable_trans:0, snmpd_disable_trans:0, squid_disable_trans:0, syslogd_disable_trans:0, ypbind_disable_trans:0, allow_ypbind:1 }<br> <font class="message_date">Oct 26 17:37:38 </font><font class="host_name">xavier </font>kernel: security: committed booleans: { httpd_unified:1, httpd_enable_cgi:0, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_disable_trans:0, dhcpd_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nscd_disable_trans:0, ntpd_disable_trans:0, portmap_disable_trans:0, snmpd_disable_trans:0, squid_disable_trans:0, syslogd_disable_trans:0, ypbind_disable_trans:0, allow_ypbind:1 }<br> <br> <h2 class="standard_section_title"><u>Allow Listing</h2></u> <font class="message_count_label">Number of messages:</font> <b class="message_count">11</b><br> <br> <font class="message_date">Oct 25 09:24:43 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098710683.835:0): </font>avc: <font class="avc_grant">granted </font>{ load_policy } for pid=11970 <font class="exe">exe=/usr/sbin/load_policy </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.944:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6486 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.944:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6486 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.976:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6488 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.976:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6488 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.984:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6490 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.984:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6490 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.993:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6492 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:37 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826657.993:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6492 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:38 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826658.001:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6494 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <font class="message_date">Oct 26 17:37:38 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098826658.001:0): </font>avc: <font class="avc_grant">granted </font>{ setbool } for pid=6494 <font class="exe">exe=/usr/bin/setsebool </font><font class="src_context">scontext=root:system_r:unconfined_t </font><font class="tgt_context">tcontext=system_u:object_r:security_t </font><font class="obj_class">tclass=security </font><br> <br> <h2 class="standard_section_title"><u>Deny Listing</h2></u> <font class="message_count_label">Number of messages:</font> <b class="message_count">22</b><br> <br> <font class="message_date">Oct 25 11:52:15 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719535.427:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6762 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:52:15 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719535.427:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6762 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:52:16 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719536.545:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6763 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:52:16 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719536.545:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6763 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:52:48 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719568.028:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6764 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:52:48 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719568.028:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6764 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:01 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719581.775:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6760 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:01 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719581.775:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6760 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:03 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719583.534:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6761 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:03 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719583.534:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6761 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:28 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719608.033:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6762 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:28 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719608.033:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6762 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:32 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719612.460:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6763 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:32 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719612.460:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6763 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:39 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719619.374:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6764 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:53:39 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719619.374:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6764 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:55:48 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719748.465:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6965 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:55:48 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719748.465:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6965 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:56:07 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719767.643:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6969 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:56:07 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719767.643:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6969 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:56:09 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719769.510:0): </font>avc: <font class="avc_deny">denied </font>{ search } for pid=6972 <font class="exe">exe=/usr/sbin/httpd </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <font class="message_date">Oct 25 11:56:09 </font><font class="host_name">xavier </font>kernel: <font class="syscall_timestamp">audit(1098719769.510:0): </font>avc: <font class="avc_deny">denied </font>{ getattr } for pid=6972 <font class="exe">exe=/usr/sbin/httpd </font><font class="path">path=/home/kmacmillan/public_html </font>dev=dm-0 ino=11897405 <font class="src_context">scontext=root:system_r:httpd_t </font><font class="tgt_context">tcontext=user_u:object_r:user_home_t </font><font class="obj_class">tclass=dir </font><br> <br> <b><u>Malformed messages</b></u> <br> <br> </body> </html>