HP-UX Host Intrusion Detection System Version 4.3 administrator guide

Table Of Contents
Table A-4 Unusual Argument Length Alert Properties (continued)
DescriptionAlert Value/FormatAlert Field
Type
Alert FieldResponse Program
Argument
The user ID, group ID,
process ID, and parent
process ID of the process that
executed a privileged setuid
program with an unusually
long argument length
uid=<uid>, gid=<gid>, pid=<pid>,
ppid=<ppid>
StringAttackerargv[5]
The full path name of the
setuid program the attacker
executed with an unusually
long argument length and
the program’s type, mode,
uid, gid, inode, and device
number
file=<full pathname>,
type=<type>,
mode=<mode>, uid=<uid>,
gid=<gid>, inode=<inode>,
device=<device>
StringTarget of Attackargv[6]
Alert summaryPotential Buffer overflow
detected
StringSummaryargv[7]
Detailed alert descriptionPotential buffer overflow attack
by process with pid <pid> and
ppid <ppid> when
executing<program>
(type=<type>, inode=<inode>,
device=<device), invoked as
follows: <argv[0> <argv[1].
Length of the longest argument
is <value>, which surpasses the
longest expected argument
length of <unusual_arg_len>.
Total length of argument is
<value>.
StringDetailsargv[8]
The event that triggered the
alert
nullStringEventargv[9]
NOTE: See Table B-1 (page 161) for the definition of additional arguments that can be used to
access specific alert information (for example, pid and ppid) without parsing the string alert
fields.
Argument with Nonprintable Character
Table A-5 lists the alert properties the Buffer Overflow template generates, and forwards to a
response program when a privileged setuid program was invoked with an argument that
contains a nonprintable character.
Table A-5 Argument with Nonprintable Character Alert Properties
DescriptionAlert Value/FormatAlert Field
Type
Alert FieldResponse Program
Argument
Unique code assigned to
template
0IntegerTemplate codeargv[1]
Template Version<version>IntegerVersionargv[2]
Alert severity1IntegerSeverityargv[3]
UTC time in number of seconds
since the epoch when a
privileged setuid program was
run with an argument that
contains a nonprintable character
<secs>IntegerUTC timeargv[4]
124 Templates and Alerts