HP Host Intrusion Detection System (HIDS) manual Argument with Non-printable Character, 138

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 150
Image 150

Templates and Alerts

Buffer Overflow Template

Table A-4

Unusual Argument Length Alert Properties (Continued)

 

 

 

 

 

 

 

 

Response

 

 

Alert

 

 

 

Program

 

Alert Field

Field

Alert Value/Format

Description

 

Argument

 

 

Type

 

 

 

 

 

 

 

 

 

 

argv[8]

 

Details

String

“Potential buffer overflow attack

Detailed alert

 

 

 

 

 

by process with pid <pid> and

description

 

 

 

 

 

ppid <ppid> when

 

 

 

 

 

 

executing<program>(type=<type

 

 

 

 

 

 

>, inode=<inode>,

 

 

 

 

 

 

device=<device), invoked as

 

 

 

 

 

 

follows: "<argv[0><argv[1]..."

 

 

 

 

 

 

Length of the longest argument

 

 

 

 

 

 

is <value> which surpasses the

 

 

 

 

 

 

longest expected argument

 

 

 

 

 

 

length of <unusual_arg_len>.

 

 

 

 

 

 

Total length of argument is

 

 

 

 

 

 

<value>.”

 

 

 

 

 

 

 

 

 

argv[9]

 

Local Time

Integer

<secs>

Local time in number

 

 

 

 

 

 

of seconds since

 

 

 

 

 

 

epoch when a

 

 

 

 

 

 

privileged setuid

 

 

 

 

 

 

program was run

 

 

 

 

 

 

with an unusually

 

 

 

 

 

 

long program length

 

 

 

 

 

 

 

 

 

 

Refer to Table B-1 in Appendix B for the definition of argv[10] through argv[32] that can

NOTE

 

 

 

be used to access specific alert information (i.e., pid, ppid) without having to parse the

 

 

 

string alert fields above.

 

 

 

 

 

 

 

 

 

Argument with Non-printable Character

This template generates and forwards the following alert to a response program when a privileged setuid program was invoked with an argument that contains a non-printable character:

Table A-5

Argument with Non-printable Character Alert Properties

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Alert Value/Format

Description

 

Field

Field Type

 

Argument

 

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[1]

Template

Integer

0

Unique code

 

 

code

 

 

assigned to

 

 

 

 

 

template

 

 

 

 

 

 

 

argv[2]

Version

Integer

2

Version of the

 

 

 

 

 

template

 

 

 

 

 

 

138

Appendix A

Page 150
Image 150
HP Host Intrusion Detection System (HIDS) manual Argument with Non-printable Character, 138