Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- type=USER_CMD msg=audit(1431686250.766:1612): user pid=22404 uid=508 auid=508 ses=95 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='cwd="/home/xxx" cmd=646F636B65722072756E202D7520706F737467726573202D69742031302E3138382E31332E3133363A383038302F616970612D73657276696365732D64617461626173653A312E312E323134202F62696E2F62617368 terminal=pts/2 res=success'
- type=CRED_ACQ msg=audit(1431686250.766:1613): user pid=22404 uid=0 auid=508 ses=95 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/2 res=success'
- type=USER_START msg=audit(1431686250.766:1614): user pid=22404 uid=0 auid=508 ses=95 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/2 res=success'
- type=NETFILTER_CFG msg=audit(1431686251.396:1615): table=nat family=2 entries=0
- type=NETFILTER_CFG msg=audit(1431686251.396:1615): table=filter family=2 entries=0
- type=SYSCALL msg=audit(1431686251.396:1615): arch=c000003e syscall=56 success=yes exit=22445 a0=6c020011 a1=0 a2=0 a3=0 items=0 ppid=1 pid=22280 auid=508 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=72 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:initrc_t:s0 key=(null)
- type=SYSCALL msg=audit(1431686251.396:1616): arch=c000003e syscall=56 success=yes exit=0 a0=6c020011 a1=0 a2=0 a3=0 items=0 ppid=22280 pid=22445 auid=508 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=72 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:initrc_t:s0 key=(null)
- type=FD_PAIR msg=audit(1431686251.396:1616): fd0=0 fd1=0
- type=ANOM_PROMISCUOUS msg=audit(1431686251.475:1617): dev=veth4ee3e6e prom=256 old_prom=0 auid=508 uid=0 gid=0 ses=72
- type=SYSCALL msg=audit(1431686251.475:1617): arch=c000003e syscall=16 success=yes exit=0 a0=26 a1=89a2 a2=c20871339c a3=0 items=0 ppid=1 pid=22280 auid=508 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=72 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:initrc_t:s0 key=(null)
- type=ANOM_PROMISCUOUS msg=audit(1431686251.545:1618): dev=veth4ee3e6e prom=0 old_prom=256 auid=4294967295 uid=0 gid=0 ses=4294967295
- type=USER_END msg=audit(1431686251.598:1619): user pid=22404 uid=0 auid=508 ses=95 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/2 res=success'
- type=CRED_DISP msg=audit(1431686251.598:1620): user pid=22404 uid=0 auid=508 ses=95 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/2 res=success'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement