Guest User

Untitled

a guest
Jul 19th, 2018
71
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.33 KB | None | 0 0
  1. type=SYSCALL msg=audit(1531967958.869:178): arch=c000003e syscall=59 success=yes exit=0 a0=1ec77e8 a1=1ec6448 a2=1ec4e08 a3=7fff08963850 items=2 ppid=2444 pid=2449 auid=1000 uid=1000 gid=1001 euid=0 suid=0 fsuid=0 egid=1001 sgid=1001 fsgid=1001 tty=pts1 ses=3 comm="sudo" exe="/usr/bin/sudo" key=(null)
  2. type=BPRM_FCAPS msg=audit(1531967958.869:178): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=0000000000000000 old_pi=0000000000000000 old_pe=0000000000000000 new_pp=0000003fffffffff new_pi=0000000000000000 new_pe=0000003fffffffff
  3. type=EXECVE msg=audit(1531967958.869:178): argc=3 a0="sudo" a1="vi" a2="/etc/hosts"
  4. type=CWD msg=audit(1531967958.869:178): cwd="/home/srashid"
  5. type=PATH msg=audit(1531967958.869:178): item=0 name="/usr/bin/sudo" inode=146140 dev=08:01 mode=0104755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
  6. type=PATH msg=audit(1531967958.869:178): item=1 name=(null) inode=393295 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
  7. type=PROCTITLE msg=audit(1531967958.869:178): proctitle=7375646F007669002F6574632F686F737473
  8. type=USER_CMD msg=audit(1531967958.909:179): pid=2449 uid=1000 auid=1000 ses=3 msg='cwd="/home/srashid" cmd=7669202F6574632F686F737473 terminal=pts/1 res=success'
  9. type=CRED_REFR msg=audit(1531967958.913:180): pid=2449 uid=0 auid=1000 ses=3 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/1 res=success'
  10. type=USER_START msg=audit(1531967958.913:181): pid=2449 uid=0 auid=1000 ses=3 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/1 res=success'
  11. type=SYSCALL msg=audit(1531967958.913:182): arch=c000003e syscall=59 success=yes exit=0 a0=55d99adb1478 a1=55d99adab388 a2=55d99adb0de0 a3=0 items=2 ppid=2449 pid=2450 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=3 comm="vi" exe="/usr/bin/vim.basic" key=(null)
  12. type=EXECVE msg=audit(1531967958.913:182): argc=2 a0="vi" a1="/etc/hosts"
  13. type=CWD msg=audit(1531967958.913:182): cwd="/home/srashid"
  14. type=PATH msg=audit(1531967958.913:182): item=0 name="/usr/bin/vi" inode=146177 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
  15. type=PATH msg=audit(1531967958.913:182): item=1 name=(null) inode=393295 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
  16. type=PROCTITLE msg=audit(1531967958.913:182): proctitle=7669002F6574632F686F737473
Add Comment
Please, Sign In to add comment