Templates and Alerts

Creation of World-Writable File Template

Table A-16

 

World-writable File Created Alert Properties (Continued)

 

 

 

 

 

 

 

 

 

Response

 

Alert

Alert

 

 

 

 

Program

 

Field

 

Alert Value/Format

Description

 

 

Field

 

 

Argument

 

Type

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[8]

Details

String

 

“User with uid <uid> <performed action

Detailed alert

 

 

 

 

 

 

on the file> <full

description

 

 

 

 

 

 

pathname>(type=<type>,inode=<inode>,

 

 

 

 

 

 

 

device<device>) when executing

 

 

 

 

 

 

 

<program>(type=<type>,inode=<inode>,d

 

 

 

 

 

 

 

evice=<device>), invoked as follows:

 

 

 

 

 

 

 

<argv[0]> <argv[1]>..., as process with pid

 

 

 

 

 

 

 

<pid> and ppid <ppid> and running with

 

 

 

 

 

 

 

effective uid=<euid> and with effective

 

 

 

 

 

 

 

gid=<egid>.

 

 

 

 

 

 

 

where <performed action on the file> is

 

 

 

 

 

 

 

set to one of the following:

 

 

 

 

 

 

 

"created the world writable file"

 

 

 

 

 

 

 

"created the world writable directory"

 

 

 

 

 

 

 

"created the world-writable character

 

 

 

 

 

 

 

special file"

 

 

 

 

 

 

 

"created the world writable block special

 

 

 

 

 

 

 

file"

 

 

 

 

 

 

 

"created the world writable pipe (fifo) file"

 

 

 

 

 

 

 

"renamed the world-writable file"

 

 

 

 

 

 

 

"changed the owner of the world writable

 

 

 

 

 

 

 

file"

 

 

 

 

 

 

 

"enabled the world writable permission on

 

 

 

 

 

 

 

file"

 

 

 

 

 

 

 

"performed system call <number> on the

 

 

 

 

 

 

 

file"

 

 

 

 

 

 

 

 

 

argv[9]

Local Time

Integer

 

<secs>

Local time in

 

 

 

 

 

 

 

number of

 

 

 

 

 

 

 

seconds since

 

 

 

 

 

 

 

epoch when a

 

 

 

 

 

 

 

world writable

 

 

 

 

 

 

 

file is created

 

 

 

 

 

 

 

 

 

 

Refer to Table B-1 in Appendix B for the definition of argv[10] through argv[32] that can

NOTE

 

 

 

 

be used to access specific alert information (i.e., pid, ppid) without having to parse the

 

 

 

string alert fields above.

 

 

 

 

 

 

 

 

 

 

Appendix A

161

Page 173
Image 173
HP Host Intrusion Detection System (HIDS) manual Appendix a 161