by daedalus » Sun Feb 12, 2012 2:57 pm
Hello, the default shutdown policy for RBAC seems to fail under some configurations (namely debian wheezy). Trying to reboot the machine will leave it unusable and it tries to ask root password for maintenance. By reading the kernel log it looks like the shutdown role is applied, somewhat, but is then dropped?
- Code: Select all
[ 74.263359] grsec: (root:U:/sbin/gradm) grsecurity 2.2.2 RBAC system loaded by /sbin/gradm[gradm:1501] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:1495] uid/euid:0/0 gid/egid:0/0
[ 82.103358] grsec: (root:U:/sbin/gradm) successful change to special role shutdown (id 1) by /sbin/gradm[gradm:1502] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:1495] uid/euid:0/0 gid/egid:0/0
[ 86.002689] grsec: (root:U:/sbin/init) denied connect() to the unix domain socket /dev/log by /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0, parent /[swapper/0:0] uid/euid:0/0 gid/egid:0/0
[ 86.003172] grsec: (root:U:/sbin/init) use of CAP_SYS_TTY_CONFIG denied for /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0, parent /[swapper/0:0] uid/euid:0/0 gid/egid:0/0
[ 86.003182] grsec: (root:U:/sbin/init) use of CAP_SYS_TTY_CONFIG denied for /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0, parent /[swapper/0:0] uid/euid:0/0 gid/egid:0/0
[ 86.003191] grsec: (root:U:/sbin/init) use of CAP_SYS_TTY_CONFIG denied for /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0, parent /[swapper/0:0] uid/euid:0/0 gid/egid:0/0
[ 86.003202] grsec: (root:U:/sbin/init) use of CAP_SYS_TTY_CONFIG denied for /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0, parent /[swapper/0:0] uid/euid:0/0 gid/egid:0/0
[ 86.003212] grsec: (root:U:/sbin/init) use of CAP_SYS_TTY_CONFIG denied for /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0, parent /[swapper/0:0] uid/euid:0/0 gid/egid:0/0
[ 86.005364] grsec: (shutdown:S:/) denied open of /root/.bash_history for appending by /bin/bash[bash:1495] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
[ 86.005624] grsec: (shutdown:S:/) denied open of /root/.bash_history for reading by /bin/bash[bash:1495] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
[ 87.008750] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/stty[stty:1516] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rc[rc:1515] uid/euid:0/0 gid/egid:0/0
[ 87.009007] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/stty[stty:1516] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rc[rc:1515] uid/euid:0/0 gid/egid:0/0
[ 87.009247] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/stty[stty:1516] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rc[rc:1515] uid/euid:0/0 gid/egid:0/0
[ 87.009488] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/stty[stty:1516] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rc[rc:1515] uid/euid:0/0 gid/egid:0/0
[ 87.009727] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/stty[stty:1516] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rc[rc:1515] uid/euid:0/0 gid/egid:0/0
[ 87.031561] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rc[rc:1515] uid/euid:0/0 gid/egid:0/0
[ 87.033949] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 87.042927] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/grep[grep:1521] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.043481] grsec: (root:U:/) use of CAP_NET_RAW denied for /sbin/ebtables[ebtables:1520] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.045063] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1522] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.074397] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 87.108149] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1525] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.138759] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1525] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.171171] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1526] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.202604] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1526] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.235994] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1527] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.268573] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1527] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.302537] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1528] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/ebtables[ebtables:1519] uid/euid:0/0 gid/egid:0/0
[ 87.355674] grsec: (root:U:/) denied create of /var/lib/libvirt/libvirt-guests for writing by /etc/init.d/libvirt-guests[libvirt-guests:1529] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 87.408459] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1533] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.446375] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1540] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.481178] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 87.518923] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1543] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.554020] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1543] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.590073] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1544] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.624818] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1544] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.660459] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1545] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.694851] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1545] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/libvirt-bin[libvirt-bin:1532] uid/euid:0/0 gid/egid:0/0
[ 87.777824] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1549] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.813271] grsec: (root:U:/) denied send of signal 19 to protected task /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.864130] grsec: (root:U:/) denied send of signal 19 to protected task /sbin/udevd[udevd:380] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.898126] grsec: (root:U:/) denied send of signal 19 to protected task /sbin/udevd[udevd:381] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.931991] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/rsyslogd[rsyslogd:1242] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932021] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/acpid[acpid:1256] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932044] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/cron[cron:1282] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932067] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932086] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/libvirtd[libvirtd:1307] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932107] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932126] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/sshd[sshd:1378] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932146] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.932162] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933391] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933401] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933413] grsec: (root:U:/) denied send of signal 15 to protected task /usr/sbin/sshd[sshd:1378] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933424] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933436] grsec: (root:U:/) denied send of signal 15 to protected task /usr/sbin/libvirtd[libvirtd:1307] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933446] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933458] grsec: (root:U:/) denied send of signal 15 to protected task /usr/sbin/cron[cron:1282] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933471] grsec: (root:U:/) denied send of signal 15 to protected task /usr/sbin/acpid[acpid:1256] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933484] grsec: (root:U:/) denied send of signal 15 to protected task /sbin/udevd[udevd:381] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933497] grsec: (root:U:/) denied send of signal 15 to protected task /sbin/udevd[udevd:380] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933509] grsec: (root:U:/) denied send of signal 15 to protected task /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933541] grsec: (root:U:/) denied send of signal 18 to protected task /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1550] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 87.933545] grsec: more alerts, logging disabled for 10 seconds
[ 98.990429] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1575] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.017457] grsec: (root:U:/) denied send of signal 19 to protected task /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.056079] grsec: (root:U:/) denied send of signal 19 to protected task /sbin/udevd[udevd:380] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.082259] grsec: (root:U:/) denied send of signal 19 to protected task /sbin/udevd[udevd:381] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.108476] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/rsyslogd[rsyslogd:1242] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.134640] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/acpid[acpid:1256] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.160703] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/cron[cron:1282] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.186743] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.212540] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/libvirtd[libvirtd:1307] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.238524] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.264349] grsec: (root:U:/) denied send of signal 19 to protected task /usr/sbin/sshd[sshd:1378] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.290276] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.316042] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.342876] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.368693] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.394501] grsec: (root:U:/) denied send of signal 9 to protected task /usr/sbin/sshd[sshd:1378] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.420553] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.446491] grsec: (root:U:/) denied send of signal 9 to protected task /usr/sbin/libvirtd[libvirtd:1307] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.472661] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.498633] grsec: (root:U:/) denied send of signal 9 to protected task /usr/sbin/cron[cron:1282] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.524919] grsec: (root:U:/) denied send of signal 9 to protected task /usr/sbin/acpid[acpid:1256] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.551298] grsec: (root:U:/) denied send of signal 9 to protected task /sbin/udevd[udevd:381] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.578129] grsec: (root:U:/) denied send of signal 9 to protected task /sbin/udevd[udevd:380] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.605572] grsec: (root:U:/) denied send of signal 9 to protected task /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.633770] grsec: (root:U:/) denied send of signal 18 to protected task /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.662840] grsec: (root:U:/) denied send of signal 18 to protected task /sbin/udevd[udevd:380] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.692759] grsec: (root:U:/) denied send of signal 18 to protected task /sbin/udevd[udevd:381] uid/euid:0/0 gid/egid:0/0, parent /sbin/udevd[udevd:277] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.723552] grsec: (root:U:/) denied send of signal 18 to protected task /usr/sbin/rsyslogd[rsyslogd:1242] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.755174] grsec: (root:U:/) denied send of signal 18 to protected task /usr/sbin/acpid[acpid:1256] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.787100] grsec: (root:U:/) denied send of signal 18 to protected task /usr/sbin/cron[cron:1282] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.819515] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.852381] grsec: (root:U:/) denied send of signal 18 to protected task /usr/sbin/libvirtd[libvirtd:1307] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.885604] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.885626] grsec: (root:U:/) denied send of signal 18 to protected task /usr/sbin/sshd[sshd:1378] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.885637] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.885646] grsec: (root:U:/) use of CAP_KILL denied for /sbin/killall5[killall5:1576] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.920122] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 99.923361] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1579] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.923381] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1579] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.924478] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1580] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.924496] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1580] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 99.925237] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1581] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/sendsigs[sendsigs:1546] uid/euid:0/0 gid/egid:0/0
[ 100.237095] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1583] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.271014] grsec: (root:U:/) denied send of signal 15 to protected task /usr/sbin/rsyslogd[rsyslogd:1242] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /sbin/start-stop-daemon[start-stop-daem:1584] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.337650] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1585] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.370448] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 100.406215] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1588] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.439040] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1588] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.472941] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1589] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.505801] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1589] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.539579] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1590] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.572548] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /usr/bin/tput[tput:1590] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/rsyslog[rsyslog:1582] uid/euid:0/0 gid/egid:0/0
[ 100.623886] grsec: (root:U:/) denied access of /etc/adjtime for writing by /etc/init.d/hwclock.sh[hwclock.sh:1591] uid/euid:0/0 gid/egid:0/0, parent /sbin/startpar[startpar:1518] uid/euid:0/0 gid/egid:0/0
[ 100.674424] grsec: (root:U:/) denied open of /dev/rtc0 for reading by /sbin/hwclock[hwclock:1592] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/hwclock.sh[hwclock.sh:1591] uid/euid:0/0 gid/egid:0/0
[ 100.744627] grsec: (root:U:/) denied access of /var/log/wtmp for writing by /sbin/halt[halt:1597] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/umountnfs.sh[umountnfs.sh:1593] uid/euid:0/0 gid/egid:0/0
[ 100.777639] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/rm[rm:1598] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/umountnfs.sh[umountnfs.sh:1593] uid/euid:0/0 gid/egid:0/0
[ 100.829207] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /bin/echo[echo:1600] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/networking[networking:1599] uid/euid:0/0 gid/egid:0/0
[ 100.866911] grsec: (root:U:/lib) denied access to hidden file /bin/dash by /lib/bridge-utils/ifupdown.sh[run-parts:1606] uid/euid:0/0 gid/egid:0/0, parent /bin/run-parts[run-parts:1605] uid/euid:0/0 gid/egid:0/0
[ 100.937035] grsec: (root:U:/) use of CAP_NET_ADMIN denied for /sbin/route[route:1611] uid/euid:0/0 gid/egid:0/0, parent /bin/dash[sh:1610] uid/euid:0/0 gid/egid:0/0
[ 100.969385] grsec: (root:U:/) use of CAP_SYS_TTY_CONFIG denied for /sbin/route[route:1611] uid/euid:0/0 gid/egid:0/0, parent /bin/dash[sh:1610] uid/euid:0/0 gid/egid:0/0
[ 101.038748] grsec: (root:U:/) denied open of /var/lib/urandom/random-seed for writing by /bin/dd[dd:1615] uid/euid:0/0 gid/egid:0/0, parent /etc/init.d/urandom[urandom:1612] uid/euid:0/0 gid/egid:0/0
[ 101.076220] grsec: more alerts, logging disabled for 10 seconds
Last edited by
daedalus on Tue Feb 14, 2012 4:30 pm, edited 1 time in total.