#!/bin/bash
for i in `lsblk --output MOUNTPOINT | grep /`
do
for i in `lsblk --output MOUNTPOINT | grep /`
do
for j in `find ${i} -xdev -type f \( -perm -4000 -o -perm -2000 \)`
do
if [ "$(grep -c ${j} /etc/audit/audit.rules)" -ge 1 ]; then
# If there is a rule...do nothing?
do
if [ "$(grep -c ${j} /etc/audit/audit.rules)" -ge 1 ]; then
# If there is a rule...do nothing?
echo "" > /dev/null
else
echo "suid/sgid program ${j} - NO audit rule!"
fi
done
done
else
echo "suid/sgid program ${j} - NO audit rule!"
fi
done
done