Notes
Values
Section
level
time
user_name
Executable
Solaris 10 or later.
Name of the zone to which the
signature applies
zone
Prevents SIGKILL signal to be sent to the client.
unixmisc:killagent
directives
Solaris class UNIX_bo
The following table lists the possible sections and values for the Solaris class_bo (Buffer
Overflow):
Notes
Values
Section
UNIX_bo
Class
See
Common sections.
Id
level
time
user_name
Executable
Program to look for.
Program name
program
Solaris 10 or later. See note 1.
Name of the zone to which the
signature applies
zone
Binary arguments.
unixbo:binargs
directives
Illegal address, such as running a program from
the stack.
unixbo:illegal_address
Program execution.
unixbo:exec
Program environment.
unixbo:environment
Binary environment.
unixbo:binenv
Used when the return address for a function is
not in the proper stack frame.
unixbo:libc
Note 1
By default, all zones are protected by the signature. To restrict protection to a particular zone,
add a zone section in the signature and include the name of the zone.
For example, if you have a zone named "app_zone" whose root is /zones/app, then the rule:
Rule {
...
file { Include "/tmp/test.log" }
zone { Include "app_zone" }
Appendix A — Writing Custom Signatures and Exceptions
Non-Windows custom signatures
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
132