Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- type=SYSCALL msg=audit(1531967958.869:178): arch=c000003e syscall=59 success=yes exit=0 a0=1ec77e8 a1=1ec6448 a2=1ec4e08 a3=7fff08963850 items=2 ppid=2444 pid=2449 auid=1000 uid=1000 gid=1001 euid=0 suid=0 fsuid=0 egid=1001 sgid=1001 fsgid=1001 tty=pts1 ses=3 comm="sudo" exe="/usr/bin/sudo" key=(null)
- type=BPRM_FCAPS msg=audit(1531967958.869:178): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=0000000000000000 old_pi=0000000000000000 old_pe=0000000000000000 new_pp=0000003fffffffff new_pi=0000000000000000 new_pe=0000003fffffffff
- type=EXECVE msg=audit(1531967958.869:178): argc=3 a0="sudo" a1="vi" a2="/etc/hosts"
- type=CWD msg=audit(1531967958.869:178): cwd="/home/srashid"
- type=PATH msg=audit(1531967958.869:178): item=0 name="/usr/bin/sudo" inode=146140 dev=08:01 mode=0104755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
- type=PATH msg=audit(1531967958.869:178): item=1 name=(null) inode=393295 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
- type=PROCTITLE msg=audit(1531967958.869:178): proctitle=7375646F007669002F6574632F686F737473
- type=USER_CMD msg=audit(1531967958.909:179): pid=2449 uid=1000 auid=1000 ses=3 msg='cwd="/home/srashid" cmd=7669202F6574632F686F737473 terminal=pts/1 res=success'
- type=CRED_REFR msg=audit(1531967958.913:180): pid=2449 uid=0 auid=1000 ses=3 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/1 res=success'
- type=USER_START msg=audit(1531967958.913:181): pid=2449 uid=0 auid=1000 ses=3 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/1 res=success'
- type=SYSCALL msg=audit(1531967958.913:182): arch=c000003e syscall=59 success=yes exit=0 a0=55d99adb1478 a1=55d99adab388 a2=55d99adb0de0 a3=0 items=2 ppid=2449 pid=2450 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=3 comm="vi" exe="/usr/bin/vim.basic" key=(null)
- type=EXECVE msg=audit(1531967958.913:182): argc=2 a0="vi" a1="/etc/hosts"
- type=CWD msg=audit(1531967958.913:182): cwd="/home/srashid"
- type=PATH msg=audit(1531967958.913:182): item=0 name="/usr/bin/vi" inode=146177 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
- type=PATH msg=audit(1531967958.913:182): item=1 name=(null) inode=393295 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
- type=PROCTITLE msg=audit(1531967958.913:182): proctitle=7669002F6574632F686F737473
Add Comment
Please, Sign In to add comment