#include #include #include #include #include #include #include int main() { int rc=0; int mode; /* stop auditd */ system("/etc/rc.d/init.d/auditd stop"); /* set mode for temp file */ mode = 0777; /* touch temp file */ system("touch /tmp/pers64_check"); /* start auditd */ system("/etc/rc.d/init.d/auditd start"); /* setup filtering rule */ system("auditctl -a exit,always -S chmod -F pers=0x0000"); /* execute chmod syscall */ syscall(__NR_chmod, "/tmp/pers64_check", mode); /* stop auditd */ system("/etc/rc.d/init.d/auditd stop"); }