- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Alert 29 in IDS-9000 on file /dev/diag/diag2
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2001 10:55 AM
07-05-2001 10:55 AM
I get an enormous amount of alerts (code 29) for a file /dev/diag/diag2.
Is is safe to exclude this file in the template?
Sincerely,
Richard Falt
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2003 04:47 AM
01-06-2003 04:47 AM
Re: Alert 29 in IDS-9000 on file /dev/diag/diag2
I am now seeing the same thing having just installed IDS. What did you find out about this?
Thanks,
Theresa
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2003 05:24 AM
01-06-2003 05:24 AM
Re: Alert 29 in IDS-9000 on file /dev/diag/diag2
I never received a "good" answer but I went ahead and excluded this file.
Richard
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-06-2003 05:32 AM
01-06-2003 05:32 AM
SolutionSee
http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x4d817d4cf554d611abdb0090277a778c,00.html
It points you to the good documentation.
The following list maps the Code values to the name of the detection
template that generates them.
Code Detection Template
5 Buffer overflow attacks
6 Race condition attacks
9 Creation of SetUID files
13 Creation of world-writable files
15 Repeated failed su commands
16 Repeated failed logins
27 Modification of files/directories
28 Changes to log files
29 Modification of another user???s files
30 Monitor start of interactive sessions
31 Monitor logins/logouts
As you can see an alert 29 comes when this file is accessed by a not owner so excluding is best
Steve Steel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2003 01:34 PM
01-09-2003 01:34 PM
Re: Alert 29 in IDS-9000 on file /dev/diag/diag2
Can you post the entire alert detail for one of these alerts?
Pierre
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-15-2003 12:14 PM
01-15-2003 12:14 PM
Re: Alert 29 in IDS-9000 on file /dev/diag/diag2
Instead of excluding /dev/diag/diag2 by putting it in the "Ignore changes to these files" property of the "Modificaton of another user's files" template, it would be better to add /dev/diag/diag2 to one of the "Files modified by Program X" template and add the full pathname of memlogd in the corresponding "Program List X," where X can equal 1, 2, or 3.
We will be updating the default template property values to reduce some of these alerts in our upcoming V2.2 available in late Spring/early Summer.
Pierre