Templates and Alerts
Buffer Overflow Template
Table |
| Argument with | ||||
|
|
|
|
|
|
|
| Response | Alert | Alert |
|
| |
| Program | Alert Value/Format | Description | |||
| Field | Field Type | ||||
| Argument |
|
| |||
|
|
|
|
|
| |
|
|
|
|
|
| |
| argv[9] | Local Time | Integer | <secs> | Local time in | |
|
|
|
|
|
| number of seconds |
|
|
|
|
|
| since epoch when |
|
|
|
|
|
| a privileged setuid |
|
|
|
|
|
| program was run |
|
|
|
|
|
| with an argument |
|
|
|
|
|
| that contains a |
|
|
|
|
|
| |
|
|
|
|
|
| character. |
|
|
|
|
|
|
|
|
|
| Refer to Table | |||
NOTE |
| |||||
|
|
| be used to access specific alert information (i.e., pid, ppid) without having to parse the | |||
|
|
| string alert fields above. |
| ||
|
|
| • The template does not detect that an actual buffer overflow attack was successful, | |||
Limitations |
| |||||
|
|
| and only detects that one might have been attempted. |
|
• The template only reports
140 | Appendix A |