HP Host Intrusion Detection System (HIDS) manual World-Writable File Created

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 171
Image 171

 

 

 

 

Templates and Alerts

 

 

 

 

Creation of World-Writable File Template

Table A-15

Template Properties (Continued)

 

 

 

 

 

 

 

 

 

Name

 

Type

Default Value

 

 

 

 

 

 

 

 

programs_1

 

II

^/usr/lbin/rlogind$ ^/usr/lbin/swagent$

 

 

 

 

 

& ^/usr/sbin/swagentd & ^/usr/sam/lb

 

 

 

 

 

in/samd$ & ^/opt/perf/bin/ &

 

 

 

 

 

^/opt/OV/bin/

 

 

 

 

 

^/opt/openssl/prngd/prngd$

 

 

 

 

 

^/usr/sbin/getty$ ^/usr/sam/lbin/samd$

 

 

 

 

 

^/opt/VRTSob/bin/vxsvc$

 

 

 

 

 

^/opt/perf/bin/

 

 

 

 

 

^/opt/OV/httpd/bin/httpd$ ^/opt/OV/bin/

 

 

 

 

 

^/usr/sbin/useradd$ &

 

 

 

 

 

^/usr/sbin/userdel$ &

 

 

 

 

 

^/usr/sbin/usermod$ ^/usr

 

 

 

 

 

/sbin/groupadd$ & ^/usr/sbin/groupdel$ &

 

 

 

 

 

^/usr/sbin/groupmod$

 

 

 

 

 

^/usr/sbin/kmtune$

 

 

 

 

 

 

 

 

pathnames_X

 

II

<empty>

 

 

 

 

 

 

 

 

programs_X

 

II

<empty>

 

 

 

 

 

 

 

Properties

Property: priv_uid_list

 

 

 

A list of system-level user IDs.

This list should contain those users that are considered to have elevated access to the system. Removing any of these means that the creation of a world writable file owned by one of those users will not be detected by this template.

Property: pathnames_to_not_watch

Pathnames of files that can be safely ignored if they are made world writable.

Properties: pathnames_X, programs_X

These properties can be used to filter out alerts generated when a particular program creates a particular world writable file. See “Type II: Pathnames/Programs Pairs” on page 130 for a detailed description of these property pairs.

Alerts generated

“World-Writable File Created” on page 159

 

by this template

 

 

 

 

 

 

 

World-Writable File Created

 

Table A-16

World-writable File Created Alert Properties

 

 

 

 

 

 

 

 

 

Response

 

Alert

Alert

 

 

 

Program

 

Field

Alert Value/Format

Description

 

 

Field

 

Argument

 

Type

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[1]

 

Template

Integer

5

Unique code

 

 

 

code

 

 

assigned to

 

 

 

 

 

 

template

 

 

 

 

 

 

 

Appendix A

159

Page 171
Image 171
HP Host Intrusion Detection System (HIDS) manual World-Writable File Created