- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: IDS 9000 alert for buffer overflow
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-28-2004 11:33 AM
04-28-2004 11:33 AM
Example :
=========================================
Unexpected change in privilege levels with UID:2164(GID:0) EUID:2164(EGID:20) executing /usr/lbin/ftpd(1,14697,"40000007") with arguments["ftpd", "-l", "-a"] and system call kern_unlink as PID:25701
=====================================
Also, I receive one alert for every command executed by that particular ftp session
This is being caused by the "buffer overflow" template. The template does'nt have any modification options. Is there some safe way to supress these messages ? (May be in the idsconf file or elsewhere ?)
Thanks
-Krishnan
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-29-2004 10:10 AM
04-29-2004 10:10 AM
SolutionNo, HIDS (IDS/9000) does not currently have a way to suppress these alerts.
I believe the alert you are getting is caused by a defect in the BO template for HIDS v1.0 and v2.x. HIDS v3.0, which is coming out in the 2nd half of 2004, will have a completely revamped BO template which should perform MUCH better and have better heuristics and filtering capabilities. I would not use the BO template that comes with HIDS v2.x.
If your system is HP-UX 11i (11.11) or later, I would recommend using the kernel exec-on-stack buffer overflow protection (see the chatr(2) man page for details).
Pierre
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-03-2004 07:54 AM
05-03-2004 07:54 AM
			
				
					
						
							Re: IDS 9000 alert for buffer overflow
						
					
					
				
			
		
	
			
	
	
	
	
	
Thank you for the clarification. I am hoping to see some filtering abilites in the HIDS 3.0 for the BO template.
I have few more questions for you :
a) Does the lab have a beta version of HIDS 3.0?
b) Whenever certain applications are executed (for example "glance" ), the cpu utilisation for "idscor" and "idssysdsp" spikes upto 20 % for a period of about 1-2 minutes. Is there a way to tell IDS to ignore certain binaries/applications from checks altogether?
c) Is HP even remotely considering releasing a version of HIDS for RedHat Linux/SUN and other OS ? I am aware that IDS is pretty much kernel/host specific but our management was just looking into the possibility of one common HOST intrusion detection product for various platforms. Any suggestions?
Thanks
-Krishnan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-04-2004 07:15 AM
05-04-2004 07:15 AM
			
				
					
						
							Re: IDS 9000 alert for buffer overflow
						
					
					
				
			
		
	
			
	
	
	
	
	
a) Does the lab have a beta version of HIDS 3.0?
We will have a beta version sometime this summer. Let me know if you are interested in participating. If you give me permission, I can ask the ITRC forum manager to pass along your email address so I can contact you directly.
b) Whenever certain applications are executed (for example "glance" ), the cpu utilisation for "idscor" and "idssysdsp" spikes upto 20 % for a period of about 1-2 minutes. Is there a way to tell IDS to ignore certain binaries/applications from checks altogether?
There is not. Actually, we hope that the next version of IDS will address the CPU utilization, although we are primarily concentrating on improving event throughput. The next version of the BO template will provide the ability to filter out alerts based on a program's pathname, in addition to being less CPU intensive.
c) Is HP even remotely considering releasing a version of HIDS for RedHat Linux/SUN and other OS ? I am aware that IDS is pretty much kernel/host specific but our management was just looking into the possibility of one common HOST intrusion detection product for various platforms. Any suggestions?
We are not considering Solaris or Windows at this time, although we might reconsider Solaris if we have a supported public interface to their kernel auditing system. We have looked into Linux, but we will not be doing a port in the near future.
Pierre
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-04-2004 08:11 AM
05-04-2004 08:11 AM
