Operating System - HP-UX
1833994 Members
2694 Online
110063 Solutions
New Discussion

Re: HIDS 4.0 Template Failure

 
Derek Whigham_1
Trusted Contributor

HIDS 4.0 Template Failure

I have modified the HIDS 4.0 "Creation of World Writable Files" Template "Ignore Files in these Paths" Parameter.

Currently it is set to

^/dev/null$
^/dev/console$
^/dev/tty
^/dev/pty
^/dev/pts

I have added

^/var/X11/Xserver/logs$


But these creation of the X11 logs is still happening.

Anybody have any idea's why.
Divide and Conquer
7 REPLIES 7
rariasn
Honored Contributor

Re: HIDS 4.0 Template Failure

Hi Dereck,

^/var/X11/Xserver/logs/

rgs,

ran
Derek Whigham_1
Trusted Contributor

Re: HIDS 4.0 Template Failure

I have added the line suggested but am still seeing this output.

Type: Aggregated Alert (contains 2 individual alerts) Date: Fri Aug 4 13:10:49 2006 Severity: 3
Code: 11 Version: 40 Target Subsystem: file=/var/X11/Xserver/logs/X0.log(type=1,mode=33206,uid=0,gid=5,inode=94468,device=1073741827)
Attacker: uid=1,gid=5,pid=22450,ppid=1613 Attacked: ***** (**.***.**.**)
Details: Process with pid,ppid=22450,1613 executing /usr/bin/X11/Xhp (/usr/bin/X11/X :0 -auth /var/dt/ws01:AAAa01613) performed the following: created the world writable file /var/X11/Xserver/logs/X0.log (severity 3)
Divide and Conquer
rariasn
Honored Contributor

Re: HIDS 4.0 Template Failure

He Dereck,

Do you activate the template modify to node?

rgs,

ran
Derek Whigham_1
Trusted Contributor

Re: HIDS 4.0 Template Failure

Yes I have activated the new template , But still this alarm is being raised
Divide and Conquer
rariasn
Honored Contributor

Re: HIDS 4.0 Template Failure

Hi Dereck,

Delete /var directory from "Watch these pathnames for modificacion/creation" property.

rgs,


ran
Derek Whigham_1
Trusted Contributor

Re: HIDS 4.0 Template Failure

/var does not seem to monitor in this parameter. I am starting to think this is an issue with HIDS itself
Divide and Conquer
Pierre Pasturel
Respected Contributor

Re: HIDS 4.0 Template Failure

Hi Derek -

Login to your agent system where the error is occurring and send me everything in between
TEMPLATE world_writable
....
ENDTEMPLATE
that is in the agent's local /var/opt/ids/schedule file. This file will only exist when the agent is running your schedule.

Please also send me the alert that appears in the agent's /var/opt/ids/alert.log file.

Pierre